{"api_version":"1","generated_at":"2026-07-23T14:35:40+00:00","cve":"CVE-2024-23688","urls":{"html":"https://cve.report/CVE-2024-23688","api":"https://cve.report/api/cve/CVE-2024-23688.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2024-23688","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2024-23688"},"summary":{"title":"Consensys Discovery Nonce Reuse","description":"Consensys Discovery versions less than 0.4.5 uses the same AES/GCM nonce for the entire session. which should ideally be unique for every message. The node's private key isn't compromised, only the session key generated for specific peer communication is exposed.","state":"PUBLISHED","assigner":"VulnCheck","published_at":"2024-01-19 22:15:08","updated_at":"2026-07-14 23:17:17"},"problem_types":["CWE-323","CWE-330","CWE-323 CWE-323 Reusing a Nonce, Key Pair in Encryption"],"metrics":[{"version":"3.1","source":"nvd@nist.gov","type":"Primary","score":"5.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"3.1","source":"ADP","type":"DECLARED","score":"5.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","version":"3.1"}},{"version":"3.1","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","score":"5.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"https://vulncheck.com/advisories/vc-advisory-GHSA-w3hj-wr2q-x83g","name":"https://vulncheck.com/advisories/vc-advisory-GHSA-w3hj-wr2q-x83g","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Consensys Discovery Nonce Reuse | VulnCheck Advisories","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/ConsenSys/discovery/security/advisories/GHSA-w3hj-wr2q-x83g","name":"https://github.com/ConsenSys/discovery/security/advisories/GHSA-w3hj-wr2q-x83g","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Discovery uses the same AES/GCM Nonce throughout the session · Advisory · Consensys/discovery · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/advisories/GHSA-w3hj-wr2q-x83g","name":"https://github.com/advisories/GHSA-w3hj-wr2q-x83g","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Discovery uses the same AES/GCM Nonce throughout the session · GHSA-w3hj-wr2q-x83g · GitHub Advisory Database · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2024-23688","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2024-23688","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2024","cve_id":"23688","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"consensys","cpe5":"discovery","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2024","cve_id":"23688","cve":"CVE-2024-23688","epss":"0.004890000","percentile":"0.388420000","score_date":"2026-07-16","updated_at":"2026-07-17 00:05:21"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-01T23:06:25.353Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["vendor-advisory","x_transferred"],"url":"https://github.com/ConsenSys/discovery/security/advisories/GHSA-w3hj-wr2q-x83g"},{"tags":["third-party-advisory","x_transferred"],"url":"https://github.com/advisories/GHSA-w3hj-wr2q-x83g"},{"tags":["third-party-advisory","x_transferred"],"url":"https://vulncheck.com/advisories/vc-advisory-GHSA-w3hj-wr2q-x83g"}],"title":"CVE Program Container"},{"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","version":"3.1"}},{"other":{"content":{"id":"CVE-2024-23688","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2024-01-22T15:45:15.449903Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2025-06-20T18:28:31.476Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"collectionURL":"https://repo.maven.apache.org/maven2","defaultStatus":"unaffected","packageName":"tech.pegasys.discovery:discovery","packageURL":"pkg:maven/tech.pegasys.discovery/discovery","versions":[{"lessThan":"0.4.5","status":"affected","version":"0","versionType":"maven"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:a:consensys:discovery:*:*:*:*:*:*:*:*","versionEndExcluding":"0.4.5","versionStartIncluding":"0","vulnerable":true}],"negate":false,"operator":"OR"}],"operator":"OR"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Consensys Discovery versions less than 0.4.5 uses the same AES/GCM nonce for the entire session. which should ideally be unique for every message. The node's private key isn't compromised, only the session key generated for specific peer communication is exposed.</p>"}],"value":"Consensys Discovery versions less than 0.4.5 uses the same AES/GCM nonce for the entire session. which should ideally be unique for every message. The node's private key isn't compromised, only the session key generated for specific peer communication is exposed."}],"problemTypes":[{"descriptions":[{"cweId":"CWE-323","description":"CWE-323 Reusing a Nonce, Key Pair in Encryption","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-07-14T22:54:47.458Z","orgId":"83251b91-4cc7-4094-a5c7-464a1b83ea10","shortName":"VulnCheck"},"references":[{"tags":["vendor-advisory"],"url":"https://github.com/ConsenSys/discovery/security/advisories/GHSA-w3hj-wr2q-x83g"},{"tags":["vendor-advisory"],"url":"https://github.com/advisories/GHSA-w3hj-wr2q-x83g"},{"tags":["third-party-advisory"],"url":"https://vulncheck.com/advisories/vc-advisory-GHSA-w3hj-wr2q-x83g"}],"source":{"discovery":"INTERNAL"},"title":"Consensys Discovery Nonce Reuse","x_generator":{"engine":"vulncheck"}}},"cveMetadata":{"assignerOrgId":"83251b91-4cc7-4094-a5c7-464a1b83ea10","assignerShortName":"VulnCheck","cveId":"CVE-2024-23688","datePublished":"2024-01-19T21:26:35.282Z","dateReserved":"2024-01-19T17:35:09.985Z","dateUpdated":"2026-07-14T22:54:47.458Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2024-01-19 22:15:08","lastModifiedDate":"2026-07-14 23:17:17","problem_types":["CWE-323","CWE-330","CWE-323 CWE-323 Reusing a Nonce, Key Pair in Encryption"],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-01-22T15:45:15.449903Z","id":"CVE-2024-23688","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:consensys:discovery:*:*:*:*:*:*:*:*","versionEndExcluding":"0.4.5","matchCriteriaId":"33F278C7-2BA2-400A-AB54-C1CC096B8D31"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2024","CveId":"23688","Ordinal":"1","Title":"Consensys Discovery Nonce Reuse","CVE":"CVE-2024-23688","Year":"2024"},"notes":[{"CveYear":"2024","CveId":"23688","Ordinal":"1","NoteData":"Consensys Discovery versions less than 0.4.5 uses the same AES/GCM nonce for the entire session. which should ideally be unique for every message. The node's private key isn't compromised, only the session key generated for specific peer communication is exposed.","Type":"Description","Title":"Consensys Discovery Nonce Reuse"}]}}}