CVE Vulnerabilities

CVE-2024-25407

Insufficient Entropy

Published: Feb 13, 2024 | Modified: Oct 16, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

SteVe v3.6.0 was discovered to use predictable transaction IDs when receiving a StartTransaction request. This vulnerability can allow attackers to cause a Denial of Service (DoS) by using the predicted transaction IDs to terminate other transactions.

Weakness

The product uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.

Affected Software

Name Vendor Start Version End Version
Steve Steve_project 3.6.0 (including) 3.6.0 (including)

Potential Mitigations

References