CVE Vulnerabilities

CVE-2024-25407

Insufficient Entropy

Published: Feb 13, 2024 | Modified: May 08, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

SteVe v3.6.0 was discovered to use predictable transaction IDs when receiving a StartTransaction request. This vulnerability can allow attackers to cause a Denial of Service (DoS) by using the predicted transaction IDs to terminate other transactions.

Weakness

The product uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.

Affected Software

NameVendorStart VersionEnd Version
SteveSteve-community3.6.0 (including)3.6.0 (including)

Potential Mitigations

References