CVE-2024-38270: Medium severity zyxel gs1900-48hpv2 vulnerability
An insufficient entropy vulnerability caused by the improper use of a randomness function with low entropy for web authentication tokens generation exists in the Zyxel GS1900-10HP firmware version V2.80(AAZI.0)C0. This vulnerability could allow a LAN-based attacker a slight chance to gain a valid session token if multiple authenticated sessions are alive.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-38270?
CVE-2024-38270 is considered a vulnerability with a slight risk of exploitation due to insufficient entropy in web authentication token generation.
How do I fix CVE-2024-38270?
To mitigate CVE-2024-38270, update the firmware of the affected Zyxel GS1900 series switches to the latest version provided by Zyxel.
Which devices are affected by CVE-2024-38270?
CVE-2024-38270 affects several Zyxel GS1900 series switches, including models GS1900-10HP, GS1900-24E, and GS1900-48HPV2 with specific firmware versions.
What type of attack can exploit CVE-2024-38270?
CVE-2024-38270 can allow a LAN-based attacker to potentially gain unauthorized access to web authentication tokens.
Who is responsible for fixing CVE-2024-38270?
The responsibility for fixing CVE-2024-38270 lies with Zyxel, which will provide patches through firmware updates as necessary.