CVE-2025-61739
Due to Nonce reuse, attackers can perform reply attack or decrypt captured packets.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.2
- CVSS vector
- CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:L/SI:L/SA:N
- EPSS probability
- 0.18%
- CWE
- CWE-323
- Published
- 2025-12-22
- Last modified
- 2026-03-12
Affected products
- Johnson Controls IQ Panels2, 2+, IQHub, IQPanel 4, PowerG
- Johnson Controls IQ Panels2, 2+, IQHub, IQPanel 4, PowerG
- Johnson Controls IQ Panels2, 2+, IQHub, IQPanel 4, PowerG
- Johnson Controls IQ Panels2, 2+, IQHub, IQPanel 4, PowerG
Weakness type
Related vulnerabilities
- CVE-2026-81341 — wolfEngine reuses the AES-CCM nonce on TLS 1.2 / DTLS 1.2 records
- CVE-2026-81020 — wolfEngine reuses the AES-GCM nonce on every TLS 1.2 / DTLS 1.2 record
- CVE-2026-81019 — wolfProvider reuses the AES-GCM nonce on every TLS 1.2 / DTLS 1.2 record
- CVE-2026-50577 — ePA 3.x Integration: AES-GCM Nonce Reuse via Frozen VAU Request Counter
- CVE-2026-17578 — Kong Event Gateway AES-GCM nonce reuse due to missing key rotation enforcement
- CVE-2026-21383 — Reusing a Nonce, Key Pair in Encryption in HLOS
- CVE-2026-59099 — Apereo CAS 7.3.0 < 8.0.0-RC6 - AES-GCM Nonce Reuse Information Disclosure
- CVE-2026-13602 — Session takeover vulnerability