Database/Firmware, BMC & network fabric
Juniper Junos OS MACsec key configuration (CKN/CAK): If you configure a MACsec connectivity-association name or key
Impact
If you configure a MACsec connectivity-association name or key shorter than its full length, Junos silently zero-fills the remainder. A 16-character passphrase you believed was a 256-bit key is 16 characters followed by a long run of zeros, and it falls to dictionary and brute-force attack. MACsec is what protects inter-site and inter-pod links carrying every tenant's traffic, so a recoverable CAK means an attacker with a tap decrypts the lot — and nothing in the config output tells you the key is weak.
Who can reach it
An attacker with a passive tap on the MACsec-protected link who recovers the key offline. No access to the devices is needed.
What to do
Config change, not a patch: reconfigure every MACsec association with the full 64-digit CKN and full 32-digit CAK, generated from a CSPRNG. Rekeying a MACsec link drops it briefly, so do redundant links one at a time. Then audit every MACsec key in the fabric for length — this is the kind of defect that survives for years because the config looks fine.
References
Related entries
- swtpm (state blob header parsing): An invalid hdrsize in swtpm's saved state header causes an out-of-bounds accessCVE-2022-23645 · swtpm (state blob header parsing)Unscored
- Supermicro BMC (IPMI web interface): Part of the same 2023 Supermicro BMC web-interface batchCVE-2023-40286 · Supermicro BMC (IPMI web interface)Unscored
- Linux x86/srso - SRSO mitigation missing for Hygon processors: The kernel's Speculative Return Stack OverflowCVE-2023-52482 · Linux x86/srso - SRSO mitigation missing for Hygon processorsUnscored
- Linux KVM/SVM - source vCPU selection in SEV-ES intra-host migration: KVM fetched source vCPUs from the wrong VMCVE-2023-54296 · Linux KVM/SVM - source vCPU selection in SEV-ES intra-host migrationUnscored
- tpm2-tools (tpm2_checkquote TPM2_GENERATED magic validation): tpm2_checkquote does not verify that the structureCVE-2024-29038 · tpm2-tools (tpm2_checkquote TPM2_GENERATED magic validation)Unscored
- tpm2-tools (tpm2_checkquote PCR selection handling): tpm2_checkquote does not validate the TPML_PCR_SELECTIONCVE-2024-29039 · tpm2-tools (tpm2_checkquote PCR selection handling)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.