CVE detail
CVE-2024-57854 — CVE-2024-57854
Published 2026-03-05 · Modified 2026-06-17 · Vendor dougdude · Product net\ · Source nvd
CRITICAL
severity
CVSS-derived band
0.0041
EPSS probability
exploitation probability, 30d
34.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Net::NSCA::Client versions through 0.009002 for Perl uses a poor random number generator.
Version v0.003 switched to use Data::Rand::Obscure instead of Crypt::Random for generation of a random initialisation vectors.
Data::Rand::Obscure uses Perl's built-in rand() function, which is not suitable for cryptographic functions.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References