CVE-2024-36048

QAbstractOAuth in Qt Network Authorization in Qt before 5.15.17, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.6, and 6.6.x through 6.7.x before 6.7.1 uses only the time to seed the PRNG, which may result in guessable values.
PRNG
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
CISA-ADPADP
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 40%
VendorProductVersion
qtqt
𝑥
< 5.15.17
qtqt
6.0.0 ≤
𝑥
< 6.2.13
qtqt
6.3.0 ≤
𝑥
< 6.5.6
qtqt
6.6.0 ≤
𝑥
< 6.7.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
qt6-networkauth
bookworm
ignored
bullseye
no-dsa
buster
postponed
trixie
6.8.2-4
fixed
sid
6.8.2-4
fixed
qtnetworkauth-everywhere-src
bullseye
no-dsa
bookworm
ignored
buster
postponed
trixie
5.15.15-3
fixed
sid
5.15.15-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
qtnetworkauth-everywhere-src
plucky
needs-triage
oracular
ignored
noble
needs-triage
mantic
ignored
jammy
needs-triage
focal
needs-triage