CVE-2017-9371
In BlackBerry QNX Software Development Platform (SDP) 6.6.0 and 6.5.0 SP1 and earlier, a loss of integrity vulnerability in the default configuration of the QNX SDP could allow an attacker being able to reduce the entropy of the PRNG, making other blended attacks more practical by gaining control over environmental factors that influence seed generation.
Scoring
- Severity
- LOW
- CVSS base score
- 2.6
- CVSS vector
- CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
- EPSS probability
- 0.24%
- CWE
- CWE-332
- Published
- 2017-11-14
- Last modified
- 2026-03-14
Affected products
- BlackBerry QNX Software Development Platform (QNX SDP)
- BlackBerry QNX Software Development Platform (QNX SDP)
Weakness type
Related vulnerabilities
- CVE-2026-3290 — Timing limitations of the HRNG in RS9116 when power save mode is enabled results in predictable values
- CVE-2023-20107 — Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Low-Entropy Keys Vulnerability
- CVE-2019-1715 — Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Low-Entropy Keys Vulnerability
- CVE-2016-9154 — Siemens Desigo PX Web modules PXA40-W0, PXA40-W1, PXA40-W2 for Desigo PX automation controllers...