CVE-2024-10604
Severity CVSS v4.0:
MEDIUM
Type:
CWE-330
Use of Insufficiently Random Value
Publication date:
30/01/2025
Last modified:
29/07/2025
Description
Vulnerabilities in the algorithms used by Fuchsia to populate network protocol header fields, specifically the TCP ISN, TCP timestamp, TCP and UDP source ports, and IPv4/IPv6 fragment ID allow for these values to be guessed under circumstances
Impact
Base Score 4.0
6.90
Severity 4.0
MEDIUM
Base Score 3.x
5.30
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:google:fuchsia:*:*:*:*:*:*:*:* | f16 (excluding) | |
| cpe:2.3:o:google:fuchsia:*:*:*:*:*:*:*:* | f17 (including) | f20 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



