Threats Tagged 'cwe-323'
View all threats tagged with 'cwe-323'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-323'
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-81341 is a vulnerability in wolfSSL Inc.'s wolfEngine before version 1.4.1 where the AES-CCM nonce for TLS 1.2 and DTLS 1.2 records is incorrectly sourced from a constant value rather than the TLS sequence number. This causes reuse of the same key and nonce pair across multiple records, weakening confidentiality and integrity. The issue affects only wolfEngine with AES-CCM cipher suites, which are not enabled by default and must be explicitly selected. TLS 1.3 and non-TLS uses are not affected. Join the discussion | CVE Database V5 | 08/28/2026, 14:43:43 UTC Added: 08/28/2026, 15:38:05 UTC |
0 wolfEngine versions up to 1.4.0 have a vulnerability in their AES-GCM implementation for TLS 1.2 and DTLS 1.2. The explicit 8-byte AES-GCM nonce is generated once per connection and not incremented per record, causing reuse of the key and nonce pair. This nonce reuse leaks the keystream and the GHASH authentication key, enabling attackers to forge authentication tags. AES-CCM, TLS 1.3, and non-TLS cipher uses are not affected. The vulnerability has a high severity with a CVSS score of 7.4. Join the discussion | CVE Database V5 | 08/28/2026, 14:42:59 UTC Added: 08/28/2026, 15:38:05 UTC |
0 wolfProvider versions up to 1.2.1 have a vulnerability where the 8-byte explicit AES-GCM nonce is generated once per connection and never incremented per record. This causes every TLS 1.2 and DTLS 1.2 AES-GCM record within a connection to be encrypted with the same key and nonce pair, leading to keystream disclosure and authentication tag forgery. AES-CCM, TLS 1.3, and non-TLS cipher uses are not affected. Join the discussion | CVE Database V5 | 08/28/2026, 14:42:01 UTC Added: 08/28/2026, 15:38:05 UTC |
0 CVE-2026-50577 is a vulnerability in fbeta-GmbH's ePA3-Service-OpenSource prior to version 1.3.0. The flaw involves reuse of AES-GCM nonce and key pairs due to a frozen client request counter, which leads to repeated nonces in encrypted responses. This allows an attacker to recover XORs of plaintexts and potentially sensitive patient health data. Additionally, the vulnerability enables recovery of the GHASH authentication key via the Joux forbidden attack, permitting message forgery and injection of malicious responses. The issue also weakens replay and ordering validation by failing to maintain the last response counter. The vulnerability is fixed in version 1.3.0. Join the discussion | CVE Database V5 | 08/18/2026, 16:52:38 UTC Added: 08/18/2026, 17:20:40 UTC |
0 Kong Event Gateway versions 1.0.0 through 1.1.1 and 1.2.0 have a vulnerability where key rotation is not enforced before reaching the NIST recommended usage limit for AES-GCM encryption keys with random nonces when AWS IAM encryption is enabled. This can lead to nonce reuse, increasing the risk of nonce collisions. An authorized consumer detecting such a collision could recover parts of plaintext from affected messages. Versions 1.1.2 and 1.2.1 address this issue by enforcing automatic key rotation before the usage limit is reached. Join the discussion | CVE Database V5 | 08/05/2026, 10:20:55 UTC Added: 08/05/2026, 11:11:59 UTC |
0 Cryptographic Issue when using a static initialization vector for AES-GCM key wrapping, which requires a unique value for each call to ensure security. Join the discussion | CVE Database V5 | 07/06/2026, 20:09:39 UTC Added: 07/06/2026, 20:37:14 UTC |
0 Crypt::DSA versions before 1.21 for Perl contain a vulnerability where the nonce used in digital signatures is reused across multiple signatures. This reuse occurs because the nonce material is cached in the Key object and never cleared, causing identical nonce values in subsequent signatures. As a result, private keys can be recovered if the same key signs more than once. This vulnerability is classified as CWE-323 and has a critical severity with a CVSS score of 9.1. Join the discussion | CVE Database V5 | 06/15/2026, 21:57:18 UTC Added: 06/15/2026, 22:31:25 UTC |
Astro is a web framework. Astro versions prior to 6.1.10 used AES-GCM encryption to protect the confidentiality and integrity of server island props and slots parameters, but did not bind the ciphertext to its intended component or parameter type. An attacker could replay one component's encrypted props (p) value as another component's slots (s) value, or vice versa. Since slots contain raw unescaped HTML while props may contain user-controlled values, this could lead to XSS in applications. This occurs when the application uses server islands, two different server island components share the same key name for a prop and a slot, and an attacker has full control over the value of the overlapping prop (requires a dynamically rendered page). This vulnerability is fixed in 6.1.10. Join the discussion | CVE Database V5 | 05/13/2026, 15:50:49 UTC Added: 05/13/2026, 16:21:32 UTC |
CVE-2026-3559 is a high-severity vulnerability in the Philips Hue Bridge version 1.73.1973146020 that allows network-adjacent attackers to bypass authentication without any privileges. The flaw is due to the reuse of a static nonce in the SRP authentication mechanism of the HomeKit Accessory Protocol service, which listens on TCP port 8080 by default. This static nonce enables attackers to circumvent authentication controls, potentially gaining unauthorized access to the device. There is no indication that a patch or official fix is currently available. Exploits in the wild have not been reported as of the publication date. Join the discussion | CVE Database V5 | 03/13/2026, 20:36:57 UTC Added: 03/13/2026, 20:59:52 UTC |
0 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution'), Use of Password Hash With Insufficient Computational Effort vulnerability in rustdesk-client RustDesk Client rustdesk, hbb_common on Windows, MacOS, Linux (Password security module, config encryption, machine UID modules) allows Retrieve Embedded Sensitive Data. This vulnerability is associated with program files hbb_common/src/password_security.Rs, hbb_common/src/config.Rs, hbb_common/src/lib.Rs (get_uuid), machine-uid/src/lib.Rs and program routines symmetric_crypt(), encrypt_str_or_original(), decrypt_str_or_original(), get_uuid(), get_machine_id(). This issue affects RustDesk Client: through 1.4.5. Join the discussion | CVE Database V5 | 03/05/2026, 16:04:36 UTC Added: 03/05/2026, 16:21:00 UTC |
Showing 1 to 10 of 17 results