CVE-2024-25407: High severity Steve-community Steve vulnerability
SteVe v3.6.0 was discovered to use predictable transaction ID's when receiving a StartTransaction request. This vulnerability can allow attackers to cause a Denial of Service (DoS) by using the predicted transaction ID's to terminate other transactions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25407?
CVE-2024-25407 has been classified as a medium severity vulnerability due to its potential to cause Denial of Service (DoS).
How do I fix CVE-2024-25407?
To fix CVE-2024-25407, upgrade SteVe to version 3.6.1 or later, which addresses the predictable transaction ID issue.
What is the impact of exploiting CVE-2024-25407?
Exploiting CVE-2024-25407 can lead to a Denial of Service (DoS) by terminating ongoing transactions using predicted transaction IDs.
Is CVE-2024-25407 present in earlier versions of SteVe?
Yes, CVE-2024-25407 specifically affects SteVe version 3.6.0; earlier versions may not be impacted.
How can I determine if my system is vulnerable to CVE-2024-25407?
To determine if your system is vulnerable to CVE-2024-25407, check if you are running SteVe version 3.6.0.