CVE-2024-56370
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2024-56370 is a vulnerability affecting Net::Xero 0.044 and earlier versions for Perl. The issue lies in the use of the insecure rand() function as the default source of entropy for cryptographic functions. Net::Xero relies on the Data::Random library, which is not designed for cryptographic applications and utilizes the rand() function, making the encryption susceptible to predictable patterns and attacks. This weakness can potentially lead to unauthorized access, data breaches, or other malicious activities. Users of affected versions are urged to update to a secure and cryptographically sound alternative for their Perl applications.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.