CVE-2024-57835

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Apr 5, 2025
Updated: Apr 8, 2025
CWE ID 338

Summary

CVE-2024-57835 exposes a vulnerability in Amon2::Auth::Site::LINE, where nonce values are generated using the insecure Perl built-in random number generator, String::Random's default setting. This puts systems at risk as the rand() function is not cryptographically secure, potentially allowing predictable nonce values and enabling attacks such as replay attacks or session hijacking.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share