← Vulnerability Intelligence

CVE-2024-23688

Consensys Discovery versions less than 0.4.5 uses the same AES/GCM nonce for the entire session.

medium entropy

Entropy / wallet impact

Consensys Discovery versions less than 0.4.5 uses the same AES/GCM nonce for the entire session.

Description

Consensys Discovery versions less than 0.4.5 uses the same AES/GCM nonce for the entire session. which should ideally be unique for every message. The node's private key isn't compromised, only the session key generated for specific peer communication is exposed.

CWE

CWE-323CWE-330

Primary sources

Published
2024-01-19T22:15:08Z
Last modified
2026-07-14T23:17:17Z
First seen here
2026-08-18T15:11:37Z
CVSS
5.3 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N ([email protected])
Credibility
official_cve