Vulnerabilities > CVE-2024-25407 - Insufficient Entropy vulnerability in Steve Project Steve 3.6.0
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
NONE Availability impact
HIGH Summary
SteVe v3.6.0 was discovered to use predictable transaction ID's when receiving a StartTransaction request. This vulnerability can allow attackers to cause a Denial of Service (DoS) by using the predicted transaction ID's to terminate other transactions.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |