VYPR

CWE-323

Reusing a Nonce, Key Pair in Encryption

BaseIncompleteLikelihood: High

Description

Nonces should be used for the present occasion and only once.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (45)

page 3 of 3
  • CVE-2026-21383HigJul 6, 2026
    risk 0.00cvss 7.1epss 0.00

    Cryptographic Issue when using a static initialization vector for AES-GCM key wrapping, which requires a unique value for each call to ensure security.

  • CVE-2026-59099CriJul 2, 2026
    risk 0.00cvss 9.1epss 0.00

    Apereo CAS 7.3.0 before 8.0.0-RC6 contains a cryptographic vulnerability that allows remote unauthenticated attackers to recover plaintext conversation state by exploiting AES-GCM initialization vector reuse across the server lifetime. Attackers can collect multiple client-side…

  • CVE-2023-37467MedJul 28, 2023
    risk 0.00cvss 6.8epss 0.00

    Discourse is an open source discussion platform. Prior to version 3.1.0.beta7 of the `beta` and `tests-passed` branches, a CSP (Content Security Policy) nonce reuse vulnerability was discovered could allow cross-site scripting (XSS) attacks to bypass CSP protection for anonymous…

  • CVE-2023-28997MedApr 4, 2023
    risk 0.00cvss 6.7epss 0.01

    The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server. Starting with version 3.0.0 and prior to version 3.6.5, a malicious server administrator can recover and modify the contents of end-to-end encrypted files. Users should upgrade the Nextcloud…

  • CVE-2021-32791MedJul 26, 2021
    risk 0.00cvss 5.9epss 0.01

    mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. In mod_auth_openidc before version 2.4.9, the AES GCM encryption in…