CVE Vulnerabilities

CVE-2019-7593

Reusing a Nonce, Key Pair in Encryption

Published: Aug 20, 2019 | Modified: Nov 21, 2024
CVSS 3.x
9.1
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a shared RSA key pair for certain encryption operations involving the Site Management Portal (SMP).

Weakness

Nonces should be used for the present occasion and only once.

Affected Software

Name Vendor Start Version End Version
Metasys_system Johnsoncontrols * 9.0 (excluding)

Potential Mitigations

References