CVE-2024-57854

N

et::NSCA::Client versions through 0.009002 for Perl uses a poor random number generator. Version v0.003 switched to use Data::Rand::Obscure instead of Crypt::Random for generation of a random initialisation vectors. Data::Rand::Obscure uses Perl's built-in rand() function, which is not suitable for cryptographic functions.

Configurations

No configuration.

History

05 Mar 2026, 19:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1

05 Mar 2026, 12:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2026/03/05/1 -

05 Mar 2026, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-05 03:15

Updated : 2026-03-05 19:38


NVD link : CVE-2024-57854

Mitre link : CVE-2024-57854

CVE.ORG link : CVE-2024-57854


JSON object : View

Products Affected

No product.

CWE
CWE-338

Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)