First published: Sat Dec 25 2021(Updated: )
In NetBSD through 9.2, the IPv4 ID generation algorithm does not use appropriate cryptographic measures.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
NetBSD NetBSD | <=9.2 | |
<=9.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-45487 is a vulnerability in NetBSD through version 9.2 that allows an attacker to generate predictable IPv4 ID values, which could be exploited for cryptographic attacks.
CVE-2021-45487 has a severity rating of 7.5 out of 10, indicating a high severity.
CVE-2021-45487 affects NetBSD through version 9.2 by using an insecure IPv4 ID generation algorithm that does not employ appropriate cryptographic measures.
An attacker can exploit CVE-2021-45487 by leveraging the predictable IPv4 ID values to carry out cryptographic attacks and potentially compromise the security of affected systems.
Yes, NetBSD has released a fix for CVE-2021-45487. It is recommended to update to version 9.2 or later to address this vulnerability.