Threats Tagged 'cwe-323'
View all threats tagged with 'cwe-323'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-323'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-50577: CWE-323: Reusing a Nonce, Key Pair in Encryption in fbeta-GmbH ePA3-Service-OpenSourceCVE-2026-50577 0 ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic patient record. Prior to 1.3.0, ePA 3.x Integration leaves request_counter unchanged in app/vau/VAUProtokoll.py while constructing VAU messages. The frozen client request counter causes the server side to reuse AES-GCM nonce and key combinations across responses. A network attacker who collects repeated ciphertexts can recover the XOR of plaintexts and use predictable inner HTTP headers and JSON fields to recover sensitive data, including patient health records. Repeated nonces can also enable recovery of the GHASH authentication key through the Joux forbidden attack, allowing forged AES-GCM messages and injection of malicious responses. The response-counter check also fails to maintain last_response_counter, weakening replay and ordering validation. This issue is fixed in version 1.3.0. Join the discussion | CVE Database V5 | 08/18/2026, 16:52:38 UTC Added: 08/18/2026, 17:20:40 UTC |
CVE-2026-17578: CWE-323: Reusing a Nonce, Key Pair in Encryption in Kong Kong Event GatewayCVE-2026-17578 0 Kong Event Gateway versions 1.0.0 through 1.1.1 and 1.2.0 have a vulnerability where key rotation is not enforced before reaching the NIST recommended usage limit for AES-GCM encryption keys with random nonces when AWS IAM encryption is enabled. This can lead to nonce reuse, increasing the risk of nonce collisions. An authorized consumer detecting such a collision could recover parts of plaintext from affected messages. Versions 1.1.2 and 1.2.1 address this issue by enforcing automatic key rotation before the usage limit is reached. Join the discussion | CVE Database V5 | 08/05/2026, 10:20:55 UTC Added: 08/05/2026, 11:11:59 UTC |
Showing 1 to 2 of 2 results