216.73.216.233

CVE-2025-1828

· Published 11/03/2025 00:15 · Modified 11/03/2025 03:15

Labels: CVE-2025-1828 2025-03-119b29abf9-4ab0-4765-b253-1875cd9b441eCVE-2025-1828CWE-338

Essential information

Published
11/03/2025 00:15
Modified
11/03/2025 03:15
Author
Creator
CVSS
8.8 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS metrics

Description

Crypt::Random Perl package 1.05 through 1.55 may use rand() function, which is not cryptographically strong, for cryptographic functions. Crypt::Random::rand 1.05 through 1.55 uses the rand() function. If the Provider is not specified and /dev/urandom or an Entropy Gathering Daemon (egd) service is not available Crypt::Random will default to use the insecure Crypt::Random::rand provider. In particular, Windows versions of perl will encounter this issue by default.

NVD status

Status
Awaiting Analysis — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
9b29abf9-4ab0-4765-b253-1875cd9b441e
NVD
View on NVD

Affected products (CPE)

ProductCPE
perl / crypt cpe:2.3:a:perl:crypt::random:1.05:*:*:*:*:*:*:*
perl / crypt cpe:2.3:a:perl:crypt::random:1.55:*:*:*:*:*:*:*

References