İçeriğe atla
Noroxi

CWE-323 · 46 kayıt

Reusing a Nonce, Key Pair in Encryption

Bu sınıftaki CVE’ler

46 kayıt

  • CVE-2017-7902
    40Planlayın

    A "Reusing a Nonce, Key Pair in Encryption" issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-logic con

    KritikCVSS 9,8İstismar yokEPSS %3

    rockwellautomation · 1763-l16awa series a29 Haz 2017

  • CVE-2025-59870
    39İzleyin

    Improper management of a static JWT signing secret in the web application, where the secret lacks rotation , introducing a security risk

    KritikCVSS 9,8İstismar yokEPSS %0

    hcltech · myxalytics16 Oca 2026

  • CVE-2026-49952
    38İzleyin

    Discuz! X5.0 Authentication Bypass via dbbak.php Encryption Oracle

    KritikCVSS 9,3Kavram kanıtıEPSS %4

    discuz! · discuz! x5.015 Haz 2026

  • CVE-2026-59099
    37İzleyin

    Apereo CAS 7.3.0 < 8.0.0-RC6 - AES-GCM Nonce Reuse Information Disclosure

    KritikCVSS 9,3İstismar yokEPSS %1

    apereo · cas2 Tem 2026

  • CVE-2019-7593
    36İzleyin

    Metasys use of shared RSA key pairs

    KritikCVSS 9,1İstismar yokEPSS %1

    johnsoncontrols · metasys system20 Ağu 2019

  • CVE-2026-12205
    36İzleyin

    Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, leading to private-key recovery

    KritikCVSS 9,1İstismar yokEPSS %0

    timlegge · crypt::dsa15 Haz 2026

  • CVE-2025-64767
    36İzleyin

    hpke-js reuses AEAD nonces

    KritikCVSS 9,1İstismar yokEPSS %0

    dajiaji · hpke-js21 Kas 2025

  • CVE-2026-25998
    34İzleyin

    strongMan vulnerable to private credential recovery due to key and counter reuse

    YüksekCVSS 8,7İstismar yokEPSS %0

    strongswan · strongman19 Şub 2026

  • CVE-2017-13082
    33İzleyin

    Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11r allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK)

    YüksekCVSS 8,1İstismar yokEPSS %5

    canonical · ubuntu linux17 Eki 2017

  • CVE-2025-47345
    33İzleyin

    Reusing a Nonce, Key Pair in Encryption in Automotive Platform

    YüksekCVSS 8,4İstismar yokEPSS %0

    qualcomm · wcd9385 firmware7 Oca 2026

  • CVE-2026-3559
    32İzleyin

    Philips Hue Bridge HomeKit Accessory Protocol Static Nonce Authentication Bypass Vulnerability

    YüksekCVSS 8,1İstismar yokEPSS %0

    philips · hue bridge v2 firmware16 Mar 2026

  • CVE-2022-24401
    32İzleyin

    Keystream recovery for arbitrary frames in TETRA

    YüksekCVSS 8,1İstismar yokEPSS %0

    midnightblue · tetra\19 Eki 2023

  • CVE-2026-50577
    29İzleyin

    ePA 3.x Integration: AES-GCM Nonce Reuse via Frozen VAU Request Counter

    YüksekCVSS 7,4İstismar yokEPSS %1

    fbeta-gmbh · epa3-service-opensource18 Ağu 2026

  • CVE-2026-3099
    29İzleyin

    Libsoup: libsoup: authentication bypass via digest authentication replay attack

    YüksekCVSS 7,3İstismar yokEPSS %0

    gnome · libsoup12 Mar 2026

  • CVE-2026-81020
    29İzleyin

    wolfEngine reuses the AES-GCM nonce on every TLS 1.2 / DTLS 1.2 record

    YüksekCVSS 7,4İstismar yokEPSS %0

    wolfssl · wolfengine28 Ağu 2026

  • CVE-2026-81019
    29İzleyin

    wolfProvider reuses the AES-GCM nonce on every TLS 1.2 / DTLS 1.2 record

    YüksekCVSS 7,4İstismar yokEPSS %0

    wolfssl · wolfprovider28 Ağu 2026

  • CVE-2017-13084
    28İzleyin

    Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Station-To-Station-Link (STSL) Transient Key (STK) during the PeerKey han

    OrtaCVSS 6,8İstismar yokEPSS %2

    canonical · ubuntu linux17 Eki 2017

  • CVE-2017-13086
    28İzleyin

    Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Tunneled Direct-Link Setup (TDLS) Peer Key (TPK) during the TDLS handshak

    OrtaCVSS 6,8İstismar yokEPSS %2

    canonical · ubuntu linux17 Eki 2017

  • CVE-2025-61739
    28İzleyin

    Johnson Controls IQ Panels2, 2+, IQHub, IQPanel 4, PowerG reusing a nonce, key pair in encryption

    YüksekCVSS 7,2İstismar yokEPSS %0

    johnson controls · iq panels2, 2+, iqhub, iqpanel 4, powerg22 Ara 2025

  • CVE-2026-21383
    28İzleyin

    Reusing a Nonce, Key Pair in Encryption in HLOS

    YüksekCVSS 7,1İstismar yokEPSS %0

    qualcomm · fastconnect 6900 firmware6 Tem 2026

  • CVE-2020-1759
    27İzleyin

    A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2 where, A nonce reuse vulnerability was disco

    OrtaCVSS 6,8İstismar yokEPSS %2

    redhat · ceph storage13 Nis 2020

  • CVE-2023-4680
    27İzleyin

    Vault's Transit Secrets Engine Allowed Nonce Specified without Convergent Encryption

    OrtaCVSS 6,8İstismar yokEPSS %0

    hashicorp · vault14 Eyl 2023

  • CVE-2023-7003
    27İzleyin

    The AES key utilized in the pairing process between a lock using Sciener firmware and a wireless keypad is not unique, and can be reused to

    OrtaCVSS 6,8İstismar yokEPSS %0

    sciener · kontrol lux15 Mar 2024

  • CVE-2023-28997
    26İzleyin

    Nextcloud Desktop: Initialization vector reuse in E2EE allows malicious server admin to break, manipulate, access files

    OrtaCVSS 6,5İstismar yokEPSS %1

    nextcloud · desktop4 Nis 2023

  • CVE-2022-37660
    26İzleyin

    In hostapd 2.10 and earlier, the PKEX code remains active even after a successful PKEX association.

    OrtaCVSS 6,5İstismar yokEPSS %0

    w1.fi · hostapd11 Şub 2025

Tüm zafiyet sınıfları