CVEbaza.plSłownik CWECWE-341
Common Weakness Enumeration

CWE-341

Predictable from Observable State

Kategoria: BaseCVE: 17
Opis

Liczba lub obiekt jest przewidywalny na podstawie obserwacji, które atakujący może dokonać na temat stanu systemu lub sieci, takich jak czas, identyfikator procesu itp. Słabość ta pozwala atakującemu na przewidzenie wartości, które powinny być losowe lub trudne do odgadnięcia.

Description (EN)

A number or object is predictable based on observations that the attacker can make about the state of the system or network, such as time, process ID, etc.

Podatności CVE z CWE-341 (17)
9.8
CVSS
CRITICAL
CVE-2026-38968

ntopng w wersjach do 6.6 włącznie generuje identyfikatory sesji HTTP w sposób przewidywalny, oparty na słabym ziarnie czasowym. Umożliwia to atakującemu zdalne przejęcie sesji uwierzytelnionych użytkowników bez znajomości ich danych logowania.

pub. 2026-07-02
9.8
CVSS
CRITICAL
CVE-2019-6563

Urządzenia Moxa IKS i EDS generują przewidywalne pliki cookie sesji obliczane przy użyciu skrótu MD5, co umożliwia atakującemu przechwycenie hasła administratora. Skuteczne wykorzystanie podatności prowadzi do pełnego przejęcia kontroli nad urządzeniem.

pub. 2019-03-05
9.1
CVSS
CRITICAL
CVE-2026-5081

Moduł Apache::Session::Generate::ModUniqueId w wersjach od 1.54 do 1.94 generuje identyfikatory sesji Perl w sposób kryptograficznie niepewny, opierając się na przewidywalnych danych. Atakujący może odgadnąć lub odtworzyć identyfikatory sesji innych użytkowników, co prowadzi do przejęcia ich sesji.

pub. 2026-05-06
9.1
CVSS
CRITICAL
CVE-2020-1731

We wszystkich wersjach Keycloak Operator przed 8.0.2 (wyłącznie wersja community) operator generuje losowe hasło administratora podczas instalacji Keycloak, jednak hasło to pozostaje niezmienione przy kolejnych wdrożeniach w tej samej przestrzeni nazw OpenShift. Stwarza to poważne ryzyko nieuprawnionego dostępu do konta administratora.

pub. 2020-03-02
8.6
CVSS
HIGH
CVE-2026-42365

A guessable session cookie vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted series of HTTP requests can lead to an authentication bypas. An attacker can bruteforce session cookies to trigger this vulnerability.

pub. 2026-05-04
8.6
CVSS
HIGH
CVE-2025-40780

In specific circumstances, due to a weakness in the Pseudo Random Number Generator (PRNG) that is used, it is possible for an attacker to predict the source port and query ID that BIND will use. This issue affects BIND 9 versions 9.16.0 through 9.16.50, 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.16.8-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.

pub. 2025-10-22
7.5
CVSS
HIGH
CVE-2026-40164

jq is a command-line JSON processor. Before commit 0c7d133c3c7e37c00b6d46b658a02244fdd3c784, jq used MurmurHash3 with a hardcoded, publicly visible seed (0x432A9843) for all JSON object hash table operations, which allowed an attacker to precompute key collisions offline. By supplying a crafted JSON object (~100 KB) where all keys hashed to the same bucket, hash table lookups degraded from O(1) to O(n), turning any jq expression into an O(n²) operation and causing significant CPU exhaustion. This affected common jq use cases such as CI/CD pipelines, web services, and data processing scripts, and was far more practical to exploit than existing heap overflow issues since it required only a small payload. This issue has been patched in commit 0c7d133c3c7e37c00b6d46b658a02244fdd3c784.

pub. 2026-04-14
7.5
CVSS
HIGH
CVE-2023-49259

The authentication cookies are generated using an algorithm based on the username, hardcoded secret and the up-time, and can be guessed in a reasonable time.

pub. 2024-01-12
7.3
CVSS
HIGH
CVE-2026-15571

A flaw was found in the legacy client-initiated account-linking endpoint of Keycloak, a widely used open-source identity and access management solution. The mechanism used to protect the account-linking process from unauthorized requests relies on a hash that can be predicted by a malicious OIDC client. By tricking a user into authenticating, an attacker-controlled client can forge a valid linking URL to connect the victim's account to an attacker's external identity. This results in a full account takeover, allowing the attacker to log in as the victim.

pub. 2026-08-18
7.3
CVSS
HIGH
CVE-2026-36609

Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 uses a static authentication nonce that does not change between requests from the same source IP. Combined with the predictable XOR-based password encoding (securityEncode function), this allows an attacker to reverse captured authentication tokens to recover the plaintext password.

pub. 2026-06-03
6.3
CVSS
MEDIUM
CVE-2024-10141

A vulnerability, which was classified as problematic, was found in jsbroks COCO Annotator 0.11.1. This affects an unknown part of the component Session Handler. The manipulation of the argument SECRET_KEY leads to predictable from observable state. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used.

pub. 2024-10-19
5.3
CVSS
MEDIUM
CVE-2020-5365

Dell EMC Isilon versions 8.2.2 and earlier contain a remotesupport vulnerability. The pre-configured support account, remotesupport, is bundled in the Dell EMC Isilon OneFS installation. This account is used for diagnostics and other support functions. Although the default password is different for every cluster, it is predictable.

pub. 2020-05-20
5.3
CVSS
MEDIUM
CVE-2018-17917

All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server may allow an attacker to use MAC addresses to enumerate potential Cloud IDs. Using this ID, the attacker can discover and connect to valid devices using one of the supported apps.

pub. 2018-10-10
5.0
CVSS
MEDIUM
CVE-2025-48461

Successful exploitation of the vulnerability could allow an unauthenticated attacker to conduct brute force guessing and account takeover as the session cookies are predictable, potentially allowing the attackers to gain root, admin or user access and reset passwords.

pub. 2025-06-24
4.3
CVSS
MEDIUM
CVE-2025-42925

Due to the lack of randomness in assigning Object Identifiers in the SAP NetWeaver AS JAVA IIOP service, an authenticated attacker with low privileges could predict the identifiers by conducting a brute force search. By leveraging knowledge of several identifiers generated close to the same time, the attacker could determine a desired identifier which could enable them to access limited system information. This poses a low risk to confidentiality without impacting the integrity or availability of the service.

pub. 2025-09-09
3.7
CVSS
LOW
CVE-2026-19565

Apache::AppSamurai::Util versions through 1.01 for Perl generate predictable session authentication keys from the clock and process id in CreateSessionAuthKey. CreateSessionAuthKey runs five rounds of SHA-256, each over a fresh Time::HiRes reading formatted to six decimal places, the running digest, and the process id. CreateSession calls it with an empty key source on every login, and the optional Keysource directive is the only route to the other branch. The result is 64 hex characters. The microsecond field of the first reading takes one of a million values, the later readings follow it within microseconds, and the process id is drawn from a small range. The key is returned to the browser as the session cookie, and is combined with the configured server key to compute the session id and to encrypt the stored session data. An attacker who knows the second in which a session was created and the process id of the worker that created it can enumerate candidate keys and recover the victim's cookie, bypassing authentication for the protected resources. Each candidate has to be tried against the server, which validates the cookie with a key the attacker does not hold.

pub. 2026-08-23
2.6
CVSS
LOW
CVE-2021-4277

W fredsmith utils została odkryta podatność klasyfikowana jako problematyczna. Problem dotyczy nieznanego przetwarzania pliku screenshot_sync w komponencie Filename Handler. Manipulacja prowadzi do przewidywalnego stanu na podstawie obserwowanego zachowania. Patch został zidentyfikowany jako dbab1b66955eeb3d76b34612b358307f5c4e3944. Zalecane jest zastosowanie poprawki w celu usunięcia tej luki.

pub. 2022-12-25
Informacje
ID: CWE-341
Typ: Base
Podatności: 17
MITRE CWE ↗
← Słownik CWE