First published: Tue Feb 13 2024(Updated: )
SteVe v3.6.0 was discovered to use predictable transaction ID's when receiving a StartTransaction request. This vulnerability can allow attackers to cause a Denial of Service (DoS) by using the predicted transaction ID's to terminate other transactions.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Odoo Community | =3.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-25407 has been classified as a medium severity vulnerability due to its potential to cause Denial of Service (DoS).
To fix CVE-2024-25407, upgrade SteVe to version 3.6.1 or later, which addresses the predictable transaction ID issue.
Exploiting CVE-2024-25407 can lead to a Denial of Service (DoS) by terminating ongoing transactions using predicted transaction IDs.
Yes, CVE-2024-25407 specifically affects SteVe version 3.6.0; earlier versions may not be impacted.
To determine if your system is vulnerable to CVE-2024-25407, check if you are running SteVe version 3.6.0.