CVE Vulnerabilities

CVE-2023-7003

Reusing a Nonce, Key Pair in Encryption

Published: Mar 15, 2024 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The AES key utilized in the pairing process between a lock using Sciener firmware and a wireless keypad is not unique, and can be reused to compromise other locks using the Sciener firmware.

Weakness

Nonces should be used for the present occasion and only once.

Potential Mitigations

References