Draft in the CWE catalog · 6 CVEs mapped
An exact value or random number can be precisely predicted by observing previous values.
Predictable Exact Value from Previous Values vulnerability in Mitsubishi Electric Corporation GOT2000 Series GT21 model versions 01.49.000 and prior and GOT SIMPLE Series GS21 model versions 01.49.000 and prior allows a remote unauthenticated attacker to hijack data connections (session hijacking) or prevent legitimate users from establishing data connections (to cause DoS condition) by guessing the listening port of the data connection on FTP server and connecting to it.
SHA1 implementation in JetBrains Ktor Native 2.0.0 was returning the same value. The issue was fixed in Ktor version 2.0.1.
⚠️ Guess what? If you're using MSC800 before version 4.15, an attacker can predict your TCP sequence numbers and send forged packets — like a magician pulling a rabbit out of a hat, but way less fun! 🎩 Think of the TCP initial sequence number like a dance sequence in a choreographed routine. If an attacker knows the dance steps ahead of time, they can swoop in and take over the performance, making it look like they belong there. This could lead to unauthorized access where an attacker can impersonate a trusted computer, potentially compromising services on the MSC800. The risk is significant because it undermines the trust necessary for secure communication — like allowing someone to waltz into a party under false pretenses!