CWE-323 · 46 kayıt
Reusing a Nonce, Key Pair in Encryption
Bu sınıftaki CVE’ler
46 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2017-7902İstismar yok | A "Reusing a Nonce, Key Pair in Encryption" issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-logic conrockwellautomation · 1763-l16awa series a · CWE-323 | Kritik9,8 | — | %2,6 | 29 Haz 2017 |
39İzleyin | CVE-2025-59870İstismar yok | Improper management of a static JWT signing secret in the web application, where the secret lacks rotation , introducing a security riskhcltech · myxalytics · CWE-323 | Kritik9,8 | — | %0,3 | 16 Oca 2026 |
38İzleyin | CVE-2026-49952Kavram kanıtı | Discuz! X5.0 Authentication Bypass via dbbak.php Encryption Oraclediscuz! · discuz! x5.0 · CWE-323 | Kritik9,3 | — | %3,7 | 15 Haz 2026 |
37İzleyin | CVE-2026-59099İstismar yok | Apereo CAS 7.3.0 < 8.0.0-RC6 - AES-GCM Nonce Reuse Information Disclosureapereo · cas · CWE-323 | Kritik9,3 | — | %0,5 | 2 Tem 2026 |
36İzleyin | CVE-2019-7593İstismar yok | Metasys use of shared RSA key pairsjohnsoncontrols · metasys system · CWE-323 | Kritik9,1 | — | %0,8 | 20 Ağu 2019 |
36İzleyin | CVE-2026-12205İstismar yok | Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, leading to private-key recoverytimlegge · crypt::dsa · CWE-323 | Kritik9,1 | — | %0,3 | 15 Haz 2026 |
36İzleyin | CVE-2025-64767İstismar yok | hpke-js reuses AEAD noncesdajiaji · hpke-js · CWE-323 | Kritik9,1 | — | %0,2 | 21 Kas 2025 |
34İzleyin | CVE-2026-25998İstismar yok | strongMan vulnerable to private credential recovery due to key and counter reusestrongswan · strongman · CWE-323 | Yüksek8,7 | — | %0,3 | 19 Şub 2026 |
33İzleyin | CVE-2017-13082İstismar yok | Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11r allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK)canonical · ubuntu linux · CWE-323 | Yüksek8,1 | — | %4,6 | 17 Eki 2017 |
33İzleyin | CVE-2025-47345İstismar yok | Reusing a Nonce, Key Pair in Encryption in Automotive Platformqualcomm · wcd9385 firmware · CWE-323 | Yüksek8,4 | — | %0,1 | 7 Oca 2026 |
32İzleyin | CVE-2026-3559İstismar yok | Philips Hue Bridge HomeKit Accessory Protocol Static Nonce Authentication Bypass Vulnerabilityphilips · hue bridge v2 firmware · CWE-323 | Yüksek8,1 | — | %0,4 | 16 Mar 2026 |
32İzleyin | CVE-2022-24401İstismar yok | Keystream recovery for arbitrary frames in TETRAmidnightblue · tetra\ · CWE-323 | Yüksek8,1 | — | %0,3 | 19 Eki 2023 |
29İzleyin | CVE-2026-50577İstismar yok | ePA 3.x Integration: AES-GCM Nonce Reuse via Frozen VAU Request Counterfbeta-gmbh · epa3-service-opensource · CWE-323 | Yüksek7,4 | — | %0,5 | 18 Ağu 2026 |
29İzleyin | CVE-2026-3099İstismar yok | Libsoup: libsoup: authentication bypass via digest authentication replay attackgnome · libsoup · CWE-323 | Yüksek7,3 | — | %0,5 | 12 Mar 2026 |
29İzleyin | CVE-2026-81020İstismar yok | wolfEngine reuses the AES-GCM nonce on every TLS 1.2 / DTLS 1.2 recordwolfssl · wolfengine · CWE-323 | Yüksek7,4 | — | %0,4 | 28 Ağu 2026 |
29İzleyin | CVE-2026-81019İstismar yok | wolfProvider reuses the AES-GCM nonce on every TLS 1.2 / DTLS 1.2 recordwolfssl · wolfprovider · CWE-323 | Yüksek7,4 | — | %0,4 | 28 Ağu 2026 |
28İzleyin | CVE-2017-13084İstismar yok | Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Station-To-Station-Link (STSL) Transient Key (STK) during the PeerKey hancanonical · ubuntu linux · CWE-323 | Orta6,8 | — | %2,2 | 17 Eki 2017 |
28İzleyin | CVE-2017-13086İstismar yok | Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Tunneled Direct-Link Setup (TDLS) Peer Key (TPK) during the TDLS handshakcanonical · ubuntu linux · CWE-323 | Orta6,8 | — | %2,0 | 17 Eki 2017 |
28İzleyin | CVE-2025-61739İstismar yok | Johnson Controls IQ Panels2, 2+, IQHub, IQPanel 4, PowerG reusing a nonce, key pair in encryptionjohnson controls · iq panels2, 2+, iqhub, iqpanel 4, powerg · CWE-323 | Yüksek7,2 | — | %0,2 | 22 Ara 2025 |
28İzleyin | CVE-2026-21383İstismar yok | Reusing a Nonce, Key Pair in Encryption in HLOSqualcomm · fastconnect 6900 firmware · CWE-323 | Yüksek7,1 | — | %0,1 | 6 Tem 2026 |
27İzleyin | CVE-2020-1759İstismar yok | A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2 where, A nonce reuse vulnerability was discoredhat · ceph storage · CWE-323 | Orta6,8 | — | %1,6 | 13 Nis 2020 |
27İzleyin | CVE-2023-4680İstismar yok | Vault's Transit Secrets Engine Allowed Nonce Specified without Convergent Encryptionhashicorp · vault · CWE-323 | Orta6,8 | — | %0,4 | 14 Eyl 2023 |
27İzleyin | CVE-2023-7003İstismar yok | The AES key utilized in the pairing process between a lock using Sciener firmware and a wireless keypad is not unique, and can be reused to sciener · kontrol lux · CWE-323 | Orta6,8 | — | %0,3 | 15 Mar 2024 |
26İzleyin | CVE-2023-28997İstismar yok | Nextcloud Desktop: Initialization vector reuse in E2EE allows malicious server admin to break, manipulate, access filesnextcloud · desktop · CWE-323 | Orta6,5 | — | %1,1 | 4 Nis 2023 |
26İzleyin | CVE-2022-37660İstismar yok | In hostapd 2.10 and earlier, the PKEX code remains active even after a successful PKEX association.w1.fi · hostapd · CWE-323 | Orta6,5 | — | %0,4 | 11 Şub 2025 |
- CVE-2017-790240Planlayın
A "Reusing a Nonce, Key Pair in Encryption" issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-logic con
KritikCVSS 9,8İstismar yokEPSS %3rockwellautomation · 1763-l16awa series a29 Haz 2017
- CVE-2025-5987039İzleyin
Improper management of a static JWT signing secret in the web application, where the secret lacks rotation , introducing a security risk
KritikCVSS 9,8İstismar yokEPSS %0hcltech · myxalytics16 Oca 2026
- CVE-2026-4995238İzleyin
Discuz! X5.0 Authentication Bypass via dbbak.php Encryption Oracle
KritikCVSS 9,3Kavram kanıtıEPSS %4discuz! · discuz! x5.015 Haz 2026
- CVE-2026-5909937İzleyin
Apereo CAS 7.3.0 < 8.0.0-RC6 - AES-GCM Nonce Reuse Information Disclosure
KritikCVSS 9,3İstismar yokEPSS %1apereo · cas2 Tem 2026
- CVE-2019-759336İzleyin
Metasys use of shared RSA key pairs
KritikCVSS 9,1İstismar yokEPSS %1johnsoncontrols · metasys system20 Ağu 2019
- CVE-2026-1220536İzleyin
Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, leading to private-key recovery
KritikCVSS 9,1İstismar yokEPSS %0timlegge · crypt::dsa15 Haz 2026
- CVE-2025-6476736İzleyin
hpke-js reuses AEAD nonces
KritikCVSS 9,1İstismar yokEPSS %0dajiaji · hpke-js21 Kas 2025
- CVE-2026-2599834İzleyin
strongMan vulnerable to private credential recovery due to key and counter reuse
YüksekCVSS 8,7İstismar yokEPSS %0strongswan · strongman19 Şub 2026
- CVE-2017-1308233İzleyin
Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11r allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK)
YüksekCVSS 8,1İstismar yokEPSS %5canonical · ubuntu linux17 Eki 2017
- CVE-2025-4734533İzleyin
Reusing a Nonce, Key Pair in Encryption in Automotive Platform
YüksekCVSS 8,4İstismar yokEPSS %0qualcomm · wcd9385 firmware7 Oca 2026
- CVE-2026-355932İzleyin
Philips Hue Bridge HomeKit Accessory Protocol Static Nonce Authentication Bypass Vulnerability
YüksekCVSS 8,1İstismar yokEPSS %0philips · hue bridge v2 firmware16 Mar 2026
- CVE-2022-2440132İzleyin
Keystream recovery for arbitrary frames in TETRA
YüksekCVSS 8,1İstismar yokEPSS %0midnightblue · tetra\19 Eki 2023
- CVE-2026-5057729İzleyin
ePA 3.x Integration: AES-GCM Nonce Reuse via Frozen VAU Request Counter
YüksekCVSS 7,4İstismar yokEPSS %1fbeta-gmbh · epa3-service-opensource18 Ağu 2026
- CVE-2026-309929İzleyin
Libsoup: libsoup: authentication bypass via digest authentication replay attack
YüksekCVSS 7,3İstismar yokEPSS %0gnome · libsoup12 Mar 2026
- CVE-2026-8102029İzleyin
wolfEngine reuses the AES-GCM nonce on every TLS 1.2 / DTLS 1.2 record
YüksekCVSS 7,4İstismar yokEPSS %0wolfssl · wolfengine28 Ağu 2026
- CVE-2026-8101929İzleyin
wolfProvider reuses the AES-GCM nonce on every TLS 1.2 / DTLS 1.2 record
YüksekCVSS 7,4İstismar yokEPSS %0wolfssl · wolfprovider28 Ağu 2026
- CVE-2017-1308428İzleyin
Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Station-To-Station-Link (STSL) Transient Key (STK) during the PeerKey han
OrtaCVSS 6,8İstismar yokEPSS %2canonical · ubuntu linux17 Eki 2017
- CVE-2017-1308628İzleyin
Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Tunneled Direct-Link Setup (TDLS) Peer Key (TPK) during the TDLS handshak
OrtaCVSS 6,8İstismar yokEPSS %2canonical · ubuntu linux17 Eki 2017
- CVE-2025-6173928İzleyin
Johnson Controls IQ Panels2, 2+, IQHub, IQPanel 4, PowerG reusing a nonce, key pair in encryption
YüksekCVSS 7,2İstismar yokEPSS %0johnson controls · iq panels2, 2+, iqhub, iqpanel 4, powerg22 Ara 2025
- CVE-2026-2138328İzleyin
Reusing a Nonce, Key Pair in Encryption in HLOS
YüksekCVSS 7,1İstismar yokEPSS %0qualcomm · fastconnect 6900 firmware6 Tem 2026
- CVE-2020-175927İzleyin
A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2 where, A nonce reuse vulnerability was disco
OrtaCVSS 6,8İstismar yokEPSS %2redhat · ceph storage13 Nis 2020
- CVE-2023-468027İzleyin
Vault's Transit Secrets Engine Allowed Nonce Specified without Convergent Encryption
OrtaCVSS 6,8İstismar yokEPSS %0hashicorp · vault14 Eyl 2023
- CVE-2023-700327İzleyin
The AES key utilized in the pairing process between a lock using Sciener firmware and a wireless keypad is not unique, and can be reused to
OrtaCVSS 6,8İstismar yokEPSS %0sciener · kontrol lux15 Mar 2024
- CVE-2023-2899726İzleyin
Nextcloud Desktop: Initialization vector reuse in E2EE allows malicious server admin to break, manipulate, access files
OrtaCVSS 6,5İstismar yokEPSS %1nextcloud · desktop4 Nis 2023
- CVE-2022-3766026İzleyin
In hostapd 2.10 and earlier, the PKEX code remains active even after a successful PKEX association.
OrtaCVSS 6,5İstismar yokEPSS %0w1.fi · hostapd11 Şub 2025