CVE Vulnerabilities

CVE-2019-7593

Reusing a Nonce, Key Pair in Encryption

Published: Aug 20, 2019 | Modified: Nov 21, 2024
CVSS 3.x
9.1
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a shared RSA key pair for certain encryption operations involving the Site Management Portal (SMP).

Weakness

Nonces should be used for the present occasion and only once.

Affected Software

NameVendorStart VersionEnd Version
Metasys_systemJohnsoncontrols*9.0 (excluding)

Potential Mitigations

References