CVE-2002-20002
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Jan 2, 2025
CWE ID 338
Summary
CVE-2002-20002 is a vulnerability affecting the Net::EasyTCP package before version 0.15 used in Perl. Instead of utilizing a secure random number generator for cryptographic keys, this package relies on Perl's built-in rand() function, which is not strong enough for such purposes. An attacker can exploit this weakness to predict or generate valid cryptographic keys, potentially leading to unauthorized access or data manipulation. Users of this package are advised to upgrade to a secure version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.