CVE Vulnerabilities

CVE-2024-11022

Reusing a Nonce, Key Pair in Encryption

Published: Dec 06, 2024 | Modified: Dec 06, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The authentication process to the web server uses a challenge response procedure which inludes the nonce and additional information. This challenge can be used several times for login and is therefore vulnerable for a replay attack.

Weakness

Nonces should be used for the present occasion and only once.

Potential Mitigations

References