Home

Description

Due to Nonce reuse, attackers can perform reply attack or decrypt captured packets.

PUBLISHED Reserved 2025-09-30 | Published 2025-12-22 | Updated 2025-12-22 | Assigner jci




HIGH: 7.2CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:L/SI:L/SA:N

Problem types

CWE-323 Reusing a Nonce, Key pair in encryption

Product status

Default status
unaffected

IQPanel2 (custom)
affected

IQ Panels 2+ (custom)
affected

IQHub (custom)
affected

IQPanel 4 (custom)
affected

Credits

James Chambers of NCC Group finder

Sultan Qasim Khan of NCC Group finder

References

www.johnsoncontrols.com/...cybersecurity/security-advisories

www.cisa.gov/news-events/ics-advisories/icsa-25-350-02

cve.org (CVE-2025-61739)

nvd.nist.gov (CVE-2025-61739)

Download JSON

Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.