| [Japanese] | |
JVNDB-2023-001215 | |
Zuken Elmic KASAGO uses insufficient random values for TCP Initial Sequence Numbers | |
| Overview | |
Zuken Elmic KASAGO, TCP/IP protocol stack for embedded systems, uses its own random number generator function when generating TCP initial sequence numbers, which leads to use insufficient random values (CWE-330). | |
| CVSS Severity (What is CVSS?) | |
|
CVSS V3 Severity:
Base Metrics 5.9 (Medium) [Other]
| |
| Affected Products | |
|
| |
ZUKEN ELMIC,INC | |
|
| |
| Impact | |
TCP initial sequence numbers may be derived; and ongoing TCP sessions may be hijacked or future TCP sessions may be spoofed. | |
| Solution | |
[Update The Software] | |
| Vendor Information | |
Panasonic Corporation | |
| CWE (What is CWE?) | |
|
| |
| CVE (What is CVE?) | |
|
| |
| References | |
| |
| Revision History | |
|
| Date Public | 2023/02/10 |
| Date First Published | 2023/02/13 |
| Date Last Updated | 2024/06/14 |


