CVE-2024-56370

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Apr 5, 2025
Updated: Apr 14, 2025
CWE ID 338

Summary

CVE-2024-56370 is a vulnerability affecting Net::Xero 0.044 and earlier versions for Perl. The issue lies in the use of the insecure rand() function as the default source of entropy for cryptographic functions. Net::Xero relies on the Data::Random library, which is not designed for cryptographic applications and utilizes the rand() function, making the encryption susceptible to predictable patterns and attacks. This weakness can potentially lead to unauthorized access, data breaches, or other malicious activities. Users of affected versions are urged to update to a secure and cryptographically sound alternative for their Perl applications.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share