CWE-323
CVEs classified under CWE-323, newest first.
4 CVEsRSS
CVE-2026-15890Medium· 5.3The default AEAD nonce provider for the PSA Internal Trusted Storage transform module, secure_storage_its_transform_aead_get_nonce() in subsys/secure_storage/src/its/transform/aead_get.c, stores its nonce counter in unsynchronized functi…
The default AEAD nonce provider for the PSA Internal Trusted Storage transform module, secure_storage_its_transform_aead_get_nonce() in subsys/secure_storage/src/its/transform/aead_get.c, stores its nonce counter in unsynchronized functi…
CVE-2026-50577High· 7.4ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic patient record
ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic patient record. Prior to 1.3.0, ePA 3.x Integration leaves request_counter unchanged in app/vau/VAUProtokoll.py whil…
CVE-2022-37660Medium· 6.5In hostapd 2.10 and earlier, the PKEX code remains active even after a successful PKEX association
In hostapd 2.10 and earlier, the PKEX code remains active even after a successful PKEX association. An attacker that successfully bootstrapped public keys with another entity using PKEX in the past, will be able to subvert a future boots…
CVE-2024-23688Medium· 5.3Consensys Discovery versions less than 0.4.5 uses the same AES/GCM nonce for the entire session
Consensys Discovery versions less than 0.4.5 uses the same AES/GCM nonce for the entire session. which should ideally be unique for every message. The node's private key isn't compromised, only the session key generated for specific peer…