CVE-2016-10212
Last modified
CVE-2016-10212 is a vulnerability of currently unknown severity. Radware devices use the same value for the first two GCM nonces, which allows remote attackers to obtain the authentication key and spoof data via a "forbidden attack," a similar issue to CVE-2016-0270. NOTE: this issue may be due to the use of a third-party Cavium product.. EPSS estimates a 3.06% chance of exploitation in the next 30 days.
Description
Radware devices use the same value for the first two GCM nonces, which allows remote attackers to obtain the authentication key and spoof data via a "forbidden attack," a similar issue to CVE-2016-0270. NOTE: this issue may be due to the use of a third-party Cavium product.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Radware | Alteon | <= 30.0.5.10 |
| Radware | Alteon | <= 30.2.1.1 |
References
- http://www.securityfocus.com/bid/96172Third Party Advisory, VDB Entry
- https://github.com/nonce-disrespect/nonce-disrespectThird Party Advisory
- http://www.securityfocus.com/bid/96172Third Party Advisory, VDB Entry
- https://github.com/nonce-disrespect/nonce-disrespectThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-10212?
How severe is CVE-2016-10212?
How do I fix CVE-2016-10212?
Are you affected by CVE-2016-10212?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
