CVE-2021-45488: High severity netbsd current vulnerability
Published Dec 25, 2021
·Updated
In NetBSD through 9.2, there is an information leak in the TCP ISN (ISS) generation algorithm.
Affected Software
1 affected component
NetBSD NetBSD<=9.2
Remediation
Event History
Dec 25, 2021
CVE Published
via MITRE·01:03 AM
Data Sourced
via MITRE·01:03 AM
Description
Data Sourced
via NVD·02:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this information leak in the TCP ISN generation algorithm in NetBSD?
The vulnerability ID for this information leak is CVE-2021-45488.
2
What is the severity of CVE-2021-45488?
CVE-2021-45488 has a severity rating of 7.5 (High).
3
How does the information leak occur in NetBSD through version 9.2?
The information leak occurs in the TCP ISN (ISS) generation algorithm in NetBSD through version 9.2.
4
Which software versions are affected by CVE-2021-45488?
NetBSD versions up to and including 9.2 are affected by CVE-2021-45488.
5
Is there a fix available for this vulnerability?
It is recommended to update NetBSD to version 9.3 or apply the relevant security patch provided by the vendor.