CVE-2024-52616
A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementing them sequentially after that. This predictable behavior facilitates DNS spoofing attacks, allowing attackers to guess transaction IDs.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS probability
- 0.67%
- CWE
- CWE-334
- Published
- 2024-11-21
- Last modified
- 2026-06-29
Affected products
- Red Hat Red Hat Enterprise Linux 9
Weakness type
Related vulnerabilities
- CVE-2026-71851 — crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain
- CVE-2024-54017 — A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V11.0), SIPROTEC 5...
- CVE-2025-3895 — Low token entropy in MegaBIP
- CVE-2024-51720 — Vulnerabilities in SecuSUITE Server Components Impact SecuSUITE
- CVE-2024-6890 — Journyx Unauthenticated Password Reset Bruteforce
- CVE-2023-6951 — A Use of Weak Credentials vulnerability affecting the Wi-Fi network generated by a set of DJI...
- CVE-2022-24402 — Intentionally weakened effective strength in TETRA TEA1
- CVE-2023-39979 — MXsecurity Authentication Bypass