Use of insufficiently random values in ZUKEN ELMIC products - CVE-2022-43501

 

Use of insufficiently random values in ZUKEN ELMIC products - CVE-2022-43501

Published: February 10, 2023


Vulnerability identifier: #VU72105
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-43501
CWE-ID: CWE-330
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise communication between parties and perform spoofing attack.

The vulnerability exists due to usage of its own weak random number generator function when generating TCP initial sequence numbers. A remote attacker can guess the output produced by such generator and hijack future TCP sessions or perform spoofing attack.


Affected software

KASAGO IPv4
KASAGO IPv4 Light
KASAGO mobile IPv6
KASAGO IPv6/v4 Dual

How to mitigate CVE-2022-43501

Install updates from vendor's website.

KASAGO IPv4 - update to 6.0.1.34
KASAGO IPv4 Light - update to 6.0.1.34
KASAGO mobile IPv6 - update to 6.0.1.34
KASAGO IPv6/v4 Dual - update to 6.0.1.34

External References

Related Security Bulletins