Use of insufficiently random values in NetBSD - #VU51432

 

Use of insufficiently random values in NetBSD - #VU51432

Published: March 12, 2021


Vulnerability identifier: #VU51432
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-330
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a spoofing attack.

The vulnerability exists due to IP ID randomization is not enabled by default for IPv4 and IPv6 fragments and TCP ISS random generation has an information leak. A remote attacker can analyze packets received from the system and use the obtained information to spoof packets.


Affected software

NetBSD

Remediation

Install updates from vendor's website.


External References

Related Security Bulletins