CVE-2021-45487: High severity netbsd current vulnerability
In NetBSD through 9.2, the IPv4 ID generation algorithm does not use appropriate cryptographic measures.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-45487?
CVE-2021-45487 is a vulnerability in NetBSD through version 9.2 that allows an attacker to generate predictable IPv4 ID values, which could be exploited for cryptographic attacks.
What is the severity of CVE-2021-45487?
CVE-2021-45487 has a severity rating of 7.5 out of 10, indicating a high severity.
How does CVE-2021-45487 affect NetBSD?
CVE-2021-45487 affects NetBSD through version 9.2 by using an insecure IPv4 ID generation algorithm that does not employ appropriate cryptographic measures.
How can an attacker exploit CVE-2021-45487?
An attacker can exploit CVE-2021-45487 by leveraging the predictable IPv4 ID values to carry out cryptographic attacks and potentially compromise the security of affected systems.
Is there a fix available for CVE-2021-45487?
Yes, NetBSD has released a fix for CVE-2021-45487. It is recommended to update to version 9.2 or later to address this vulnerability.