CWE-336Variant

Same Seed in Pseudo-Random Number Generator (PRNG)

Draft in the CWE catalog · 3 CVEs mapped

3
CVEs mapped
8.7
Median CVSS
What it is

A Pseudo-Random Number Generator (PRNG) uses the same seed each time the product is initialized.

Recent examples
8.7cvss
CVE-2026-6924

Weak entropy initialization in Silicon Labs Matter SiWx917 TinyCrypt path

A bug in the entropy initialization for SiWx917 causes the DRBG to use a predictable seed. As such, all random numbers generated in the Matter code use the same stream of numbers. This vulnerability was discovered after the impacted repository was already deprecated.

HIGHno explanation yet
0%
epss
9.2cvss
CVE-2026-24044

ESS Community Helm Chart has a weak server key generation method

Element Server Suite Community Edition (ESS Community) deploys a Matrix stack using the provided Helm charts and Kubernetes distribution. The ESS Community Helm Chart secrets initialization hook (using matrix-tools container before 0.5.7) is using an insecure Matrix server key generation method, allowing network attackers to potentially recreate the same key pair, allowing them to impersonate the victim server. The secret is generated by the secrets initialization hook, in the ESS Community Helm Chart values, if both initSecrets.enabled is not set to false and synapse.signingKey is not defined. Given a server key in Matrix authenticates both requests originating from and events constructed on a given server, this potentially impacts confidentiality, integrity and availability of rooms which have a vulnerable server present as a member. The confidentiality of past conversations in end-to-end encrypted rooms is not impacted. The key generation issue was fixed in matrix-tools 0.5.7, released as part of ESS Community Helm Chart 25.12.1.

CRITICALno explanation yet
0%
epss
7.8cvss
CVE-2021-42810

Safenet Authentication Service Remote Desktop Gateway prior to 2.0.3 may allow privilege escilation to authenticated users

A flaw in the previous versions of the product may allow an authenticated attacker the ability to execute code as a privileged user on a system where the agent is installed.

HIGHno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-336
Abstraction
Variant
Structure
Simple
Status
Draft
References (2)