CVE-2024-10604

Severity CVSS v4.0:
MEDIUM
Type:
CWE-330 Use of Insufficiently Random Value
Publication date:
30/01/2025
Last modified:
29/07/2025

Description

Vulnerabilities in the algorithms used by Fuchsia to populate network protocol header fields, specifically the TCP ISN, TCP timestamp, TCP and UDP source ports, and IPv4/IPv6 fragment ID allow for these values to be guessed under circumstances

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:google:fuchsia:*:*:*:*:*:*:*:* f16 (excluding)
cpe:2.3:o:google:fuchsia:*:*:*:*:*:*:*:* f17 (including) f20 (excluding)