VulnerabilityModified
CVE-2016-10212
Radware devices use the same value for the first two GCM nonces, which allows remote attackers to obtain the authentication key and spoof data via a "forbidden attack," a similar issue to CVE-2016-0270.
MEDIUM 5.9EPSS 3.06%
Does this matter?
Lower severity and a low EPSS score (3.06%). Track it; it rarely justifies an emergency change on its own.
Description
Radware devices use the same value for the first two GCM nonces, which allows remote attackers to obtain the authentication key and spoof data via a "forbidden attack," a similar issue to CVE-2016-0270. NOTE: this issue may be due to the use of a third-party Cavium product.
- CVSS 3.0
- 5.9 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 3.06% probability · 87th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- radware/alteon
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/bid/96172Third Party Advisory, VDB Entry
- https://github.com/nonce-disrespect/nonce-disrespectThird Party Advisory
- https://support.radware.com/app/answers/answer_view/a_id/18456Vendor Advisory
- http://www.securityfocus.com/bid/96172Third Party Advisory, VDB Entry
- https://github.com/nonce-disrespect/nonce-disrespectThird Party Advisory
- https://support.radware.com/app/answers/answer_view/a_id/18456Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.