VDB
CVE-2024-10604
CVE-2024-10604
PUBLISHED
CVSS 6.900000095367432 MEDIUM
Vulnerabilities in the algorithms used by Fuchsia to populate network protocol header fields, specifically the TCP ISN, TCP timestamp, TCP and UDP source ports, and IPv4/IPv6 fragment ID allow for these values to be guessed under circumstances
EPSS 0.23% · 14.3th percentile
Risk Scores
CVSS 4.0
6.900000095367432
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
EPSS Score
0.23%
14.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| fuchsia | 0, f17, 0 | |
| Fuchsia | Release F19, Release F19 |
Timeline
- Jan 30, 2025 CVE Published
- Jan 30, 2025 PoC Published
- Jan 30, 2025 PoC Published
- Jan 30, 2025 PoC Published
- Jan 31, 2025 EPSS Score
- Feb 15, 2025 EPSS Score
- Feb 24, 2025 PoC Published
- Feb 24, 2025 PoC Published
- Mar 2, 2025 EPSS Score
- Mar 18, 2025 EPSS Score
- Mar 24, 2025 Coalition ESS Score
- Apr 2, 2025 EPSS Score
References
- https://www.ndss-symposium.org/wp-content/uploads/2025-122-paper.pdf url
- https://nvd.nist.gov/vuln/detail/CVE-2024-10604 advisory
- https://fuchsia.googlesource.com/fuchsia/+/40e7fbcdcd013441daf4492f1ead349a9e5b80dc url
- https://fuchsia.googlesource.com/fuchsia/+/a3c17a4d6b3140f9175d6cf6ac4eb4e775f8dea8 url