If I am not completely mistaken the encryption lacks a proper randomization and therefore is susceptible to a replay attack.
Who would prevent an attacker from intercepting an encrypted cookie and sending the encrypted packet a second time, not bothering that she does not know the key - since she already has the encrypted version and could deduce the meaning from context?