Skip to main content

CVE-2024-25943

7.6
HIGHCVSS v3.1 Base Score
2.40%
LOW RiskEPSS (85th percentile)

iDRAC9, versions prior to 7.00.00.172 for 14th Generation and 7.10.50.00 for 15th and 16th Generations, contains a session hijacking vulnerability in IPMI. A remote attacker could potentially exploit this vulnerability, leading to arbitrary code execution on the vulnerable application.

Published: 6/29/2024
Modified: 2/3/2025
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

7.6HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L

EPSS Score (Exploitation Probability)

2.40%LOW Exploitation Risk
85th percentile

This vulnerability has a 2.40% probability of being exploited in the next 30 days, ranking higher than 85% of all scored CVEs.

CWE Classification

Related Vulnerabilities

Same Weakness Type(CWE-330)

CVE-2024-10082HIGH 8.7

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication method confusion allows logging in as the built-in root user from an external service. The built-in root user up until 6.24.1 is generated in a weak manner, cannot be disabled, and has universal access.This vulnerability allows an attacker who can create an account on an enabled external authentication service, to log in as the root user, and access and control everything that can be controlled via the web interface. The attacker needs to acquire the username of the root user to be successful. This issue affects CodeChecker: through 6.24.1.

11/6/2024
CVE-2024-36389CRITICAL 9.8

MileSight DeviceHub - CWE-330 Use of Insufficiently Random Values may allow Authentication Bypass

6/2/2024
CVE-2024-21495MEDIUM 6.5

Versions of the package github.com/greenpau/caddy-security before 1.0.42 are vulnerable to Insecure Randomness due to using an insecure random number generation library which could possibly be predicted via a brute-force search. Attackers could use the potentially predictable nonce value used for authentication purposes in the OAuth flow to conduct OAuth replay attacks. In addition, insecure randomness is used while generating multifactor authentication (MFA) secrets and creating API keys in the database package.

2/17/2024
CVE-2023-46740MEDIUM 6.5

CubeFS is an open-source cloud-native file storage system. Prior to version 3.3.1, CubeFS used an insecure random string generator to generate user-specific, sensitive keys used to authenticate users in a CubeFS deployment. This could allow an attacker to predict and/or guess the generated string and impersonate a user thereby obtaining higher privileges. When CubeFS creates new users, it creates a piece of sensitive information for the user called the “accessKey”. To create the "accesKey", CubeFS uses an insecure string generator which makes it easy to guess and thereby impersonate the created user. An attacker could leverage the predictable random string generator and guess a users access key and impersonate the user to obtain higher privileges. The issue has been fixed in v3.3.1. There is no other mitigation than to upgrade.

1/3/2024
CVE-2020-27636CRITICAL 9.1

In Microchip MPLAB Net 3.6.1, TCP ISNs are improperly random.

10/10/2023

Similar SeverityHIGH