Simple authentication protocols are subject to reflection attacks if a malicious user can use the target machine to impersonate a trusted user.
Use different keys for the initiator and responder or of a different type of challenge for the initiator and responder.
Let the initiator prove its identity before proceeding.
Our security experts can help you identify and remediate CWE-301 vulnerabilities in your codebase.
Get Security Assessment