CVE-2024-41594: Weak Encryption
An issue in DrayTek Vigor310 devices through 4.3.2.6 allows an attacker to obtain sensitive information because the httpd server of the Vigor management UI uses a static string for seeding the PRNG of OpenSSL.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-41594?
CVE-2024-41594 has been assessed as a moderate severity vulnerability due to its potential to expose sensitive information.
How do I fix CVE-2024-41594?
To fix CVE-2024-41594, users should update the firmware of DrayTek Vigor310 devices to the latest available version that addresses this vulnerability.
What are the potential impacts of CVE-2024-41594?
The potential impacts of CVE-2024-41594 include the risk of unauthorized access to sensitive information facilitated by weaknesses in OpenSSL's PRNG.
Which DrayTek devices are affected by CVE-2024-41594?
CVE-2024-41594 specifically affects DrayTek Vigor310 devices running firmware versions up to 4.3.2.6.
Can CVE-2024-41594 be exploited remotely?
Yes, CVE-2024-41594 can potentially be exploited remotely, allowing attackers to gain access to sensitive information.