#VU97753 Predictable Seed in Pseudo-Random Number Generator (PRNG) in aws - CVE-2024-41708

 

#VU97753 Predictable Seed in Pseudo-Random Number Generator (PRNG) in aws - CVE-2024-41708

Published: September 27, 2024


Vulnerability identifier: #VU97753
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2024-41708
CWE-ID: CWE-337
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
aws
Software vendor:
AdaCore

Description

The vulnerability allows a remote attacker to compromise the affected application.

The vulnerability exists due to usage of a weak random number generator within the Random_String() function in the src/core/aws-utils.adb module. A remote attacker can guess session identifiers of other users and gain unauthorized access to the application.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links