VYPR
Unrated severityNVD Advisory· Published Jan 30, 2025· Updated Feb 24, 2025

Identifiable Header Values In Fuchsia Leading To Tracking of The User

CVE-2024-10604

Description

CVE-2024-10604: Fuchsia's predictable network protocol header fields allow guessing of TCP ISN, timestamps, ports, and fragment IDs.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

CVE-2024-10604: Fuchsia's predictable network protocol header fields allow guessing of TCP ISN, timestamps, ports, and fragment IDs.

Vulnerability

Fuchsia's algorithms for generating network protocol header fields, including TCP Initial Sequence Numbers (ISN), TCP timestamps, TCP and UDP source ports, and IPv4/IPv6 fragment IDs, are predictable under certain circumstances. This allows an attacker to guess these values without direct access to the system. The vulnerability affects Fuchsia versions prior to the fixes introduced in commits [1] and [2].

Exploitation

An attacker with network access to a Fuchsia device can guess the predictable header fields by observing network traffic or performing statistical analysis. No authentication or user interaction is required; the attacker can remotely infer values such as TCP ISN and source ports, enabling further attacks.

Impact

Successful guessing of these fields can lead to a range of attacks, including TCP connection hijacking, spoofing of network packets, and denial of service by crafting packets that terminate or interfere with existing connections. The attacker may gain the ability to impersonate trusted hosts or disrupt communications.

Mitigation

Fuchsia has addressed these vulnerabilities in commits [1] and [2]. Users should update to the latest Fuchsia build containing these fixes. No workarounds are available for unpatched versions.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.