CVE-2024-10604 - CVE House
Back to Database
Status published Medium CVE-2024-10604

Identifiable Header Values In Fuchsia Leading To Tracking of The User

Vulnerability Description

Vulnerabilities in the algorithms used by Fuchsia to populate network protocol header fields, specifically the TCP ISN, TCP timestamp, TCP and UDP source ports, and IPv4/IPv6 fragment ID allow for these values to be guessed under circumstances

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-10604

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Amit Klein (Hebrew University of Jerusalem)
  • Inon Kaplan (Independent researcher)
  • Ron Even (Independent researcher)

Affected Vendor

Affected Software

Fuchsia
Vulnerable Versions:
Release F19

Timeline

Official Publish: January 30th, 2025
Last Modified: February 24th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.