[Japanese] | |
JVNDB-2023-001215 | |
Zuken Elmic KASAGO uses insufficient random values for TCP Initial Sequence Numbers | |
Overview | |
Zuken Elmic KASAGO, TCP/IP protocol stack for embedded systems, uses its own random number generator function when generating TCP initial sequence numbers, which leads to use insufficient random values (CWE-330). | |
CVSS Severity (What is CVSS?) | |
CVSS V3 Severity:
Base Metrics 5.9 (Medium) [Other]
| |
Affected Products | |
| |
ZUKEN ELMIC,INC | |
| |
Impact | |
TCP initial sequence numbers may be derived; and ongoing TCP sessions may be hijacked or future TCP sessions may be spoofed. | |
Solution | |
[Update The Software] | |
Vendor Information | |
Panasonic Corporation | |
CWE (What is CWE?) | |
| |
CVE (What is CVE?) | |
| |
References | |
| |
Revision History | |
|
Date Public | 2023/02/10 |
Date First Published | 2023/02/13 |
Date Last Updated | 2024/06/14 |