Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cwe-323'

View all threats tagged with 'cwe-323'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-323

Threats Tagged 'cwe-323'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-50577: CWE-323: Reusing a Nonce, Key Pair in Encryption in fbeta-GmbH ePA3-Service-OpenSourceCVE-2026-50577
0

ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic patient record. Prior to 1.3.0, ePA 3.x Integration leaves request_counter unchanged in app/vau/VAUProtokoll.py while constructing VAU messages. The frozen client request counter causes the server side to reuse AES-GCM nonce and key combinations across responses. A network attacker who collects repeated ciphertexts can recover the XOR of plaintexts and use predictable inner HTTP headers and JSON fields to recover sensitive data, including patient health records. Repeated nonces can also enable recovery of the GHASH authentication key through the Joux forbidden attack, allowing forged AES-GCM messages and injection of malicious responses. The response-counter check also fails to maintain last_response_counter, weakening replay and ordering validation. This issue is fixed in version 1.3.0.

Join the discussion
CVE-2026-17578: CWE-323: Reusing a Nonce, Key Pair in Encryption in Kong Kong Event GatewayCVE-2026-17578
0

Kong Event Gateway versions 1.0.0 through 1.1.1 and 1.2.0 have a vulnerability where key rotation is not enforced before reaching the NIST recommended usage limit for AES-GCM encryption keys with random nonces when AWS IAM encryption is enabled. This can lead to nonce reuse, increasing the risk of nonce collisions. An authorized consumer detecting such a collision could recover parts of plaintext from affected messages. Versions 1.1.2 and 1.2.1 address this issue by enforcing automatic key rotation before the usage limit is reached.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Tag: cwe-323
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses