First published: Wed Feb 08 2017(Updated: )
A10 AX1030 and possibly other devices with software before 2.7.2-P8 uses random GCM nonce generations, which makes it easier for remote attackers to obtain the authentication key and spoof data by leveraging a reused nonce in a session and a "forbidden attack," a similar issue to CVE-2016-0270.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
A10 Networks Advanced Core Operating System | <=2.7.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-10213 is classified as a medium severity vulnerability that may allow remote attackers to spoof data.
To mitigate CVE-2016-10213, upgrade to A10 Networks Advanced Core Operating System version 2.7.2-P8 or later.
The impact of CVE-2016-10213 includes potential unauthorized access to authentication keys and data spoofing.
CVE-2016-10213 affects A10 AX1030 and possibly other A10 devices running software versions before 2.7.2-P8.
In the context of CVE-2016-10213, a nonce is a unique number that should not be reused; its improper generation can lead to vulnerabilities.