CVE-2016-10212
Last modified
CVE-2016-10212 is a vulnerability of currently unknown severity. Radware devices use the same value for the first two GCM nonces, which allows remote attackers to obtain the authentication key and spoof data via a "forbidden attack," a similar issue to CVE-2016-0270. NOTE: this issue may be due to the use of a third-party Cavium product.. EPSS estimates a 3.06% chance of exploitation in the next 30 days.
Description
Radware devices use the same value for the first two GCM nonces, which allows remote attackers to obtain the authentication key and spoof data via a "forbidden attack," a similar issue to CVE-2016-0270. NOTE: this issue may be due to the use of a third-party Cavium product.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Radware | Alteon | <= 30.0.5.10 |
| Radware | Alteon | <= 30.2.1.1 |
References
- http://www.securityfocus.com/bid/96172Third Party Advisory, VDB Entry
- https://github.com/nonce-disrespect/nonce-disrespectThird Party Advisory
- http://www.securityfocus.com/bid/96172Third Party Advisory, VDB Entry
- https://github.com/nonce-disrespect/nonce-disrespectThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-10212?
How severe is CVE-2016-10212?
How do I fix CVE-2016-10212?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-10207The Xvnc server in TigerVNC allows remote attackers to cause…
- CVE-2016-10208The ext4_fill_super function in fs/ext4/super.c in the Linux…
- CVE-2016-10209The archive_wstring_append_from_mbs function in archive_stri…
- CVE-2016-1021Adobe Flash Player before 18.0.0.343 and 19.x through 21.x b…8.8
- CVE-2016-10210libyara/lexer.l in YARA 3.5.0 allows remote attackers to cau…
- CVE-2016-10211libyara/grammar.y in YARA 3.5.0 allows remote attackers to c…
- CVE-2016-10213A10 AX1030 and possibly other devices with software before 2…
- CVE-2016-10214Memory leak in the virgl_resource_attach_backing function in…
- CVE-2016-10215An issue was discovered in Fastspot BigTree bigtree-form-bui…
- CVE-2016-10216An issue was discovered in IT ITems DataBase (ITDB) through …
- CVE-2016-10217The pdf14_open function in base/gdevp14.c in Artifex Softwar…
- CVE-2016-10218The pdf14_pop_transparency_group function in base/gdevp14.c …
Are you affected by CVE-2016-10212?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
