VYPR

CWE-325

Missing Cryptographic Step

BaseDraft

Description

The product does not implement a required step in a cryptographic algorithm, resulting in weaker encryption than advertised by the algorithm.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-68

CVEs mapped to this weakness (62)

page 1 of 4
  • CVE-2022-24116CriDec 26, 2022
    risk 0.64cvss 9.8epss 0.00

    Certain General Electric Renewable Energy products have inadequate encryption strength. This affects iNET and iNET II before 8.3.0.

  • CVE-2026-17666CriJul 30, 2026
    risk 0.59cvss 9.1epss 0.00

    Cryptographic Flaw in Enterprise in Google Chrome prior to 151.0.7922.72 allowed an attacker in a privileged network position to bypass discretionary access control via malicious network traffic. (Chromium security severity: High)

  • CVE-2024-53441CriDec 9, 2024
    risk 0.59cvss 9.1epss 0.00

    An issue in the index.js decryptCookie function of cookie-encrypter v1.0.1 allows attackers to execute a bit flipping attack.

  • CVE-2020-15086CriJul 29, 2020
    risk 0.57cvss 9.8epss 0.03

    In TYPO3 installations with the "mediace" extension from version 7.6.2 and before version 7.6.5, it has been discovered that an internal verification mechanism can be used to generate arbitrary checksums. The allows to inject arbitrary data having a valid cryptographic message…

  • CVE-2026-4601HigMar 23, 2026
    risk 0.50cvss 8.7epss 0.00

    Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.signWithMessageHash process in the DSA signing implementation. An attacker can recover the private key by forcing r or s to be zero, so the library emits an…

  • CVE-2025-30147HigMay 7, 2025
    risk 0.50cvss epss 0.00

    Besu Native contains scripts and tooling that is used to build and package the native libraries used by the Ethereum client Hyperledger Besu. Besu 24.7.1 through 25.2.2, corresponding to besu-native versions 0.9.0 through 1.2.1, have a potential consensus bug for the precompiles…

  • CVE-2020-15098HigJul 29, 2020
    risk 0.50cvss 8.8epss 0.02

    In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.20, and greater than or equal to 10.0.0 and less than 10.4.6, it has been discovered that an internal verification mechanism can be used to generate arbitrary checksums. This allows to inject arbitrary data having a…

  • CVE-2025-60704HigNov 11, 2025
    risk 0.49cvss 7.5epss 0.01

    Missing cryptographic step in Windows Kerberos allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2021-33560HigJun 8, 2021
    risk 0.49cvss 7.5epss 0.02

    Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm, and the window size is not chosen appropriately. This, for example, affects use of ElGamal in OpenPGP.

  • CVE-2022-20742HigMay 3, 2022
    risk 0.48cvss 7.4epss 0.00

    A vulnerability in an IPsec VPN library of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to read or modify data within an IPsec IKEv2 VPN tunnel. This vulnerability is due to an…

  • CVE-2025-47383HigMar 2, 2026
    risk 0.47cvss 7.2epss 0.00

    Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.

  • CVE-2026-9266HigJun 12, 2026
    risk 0.45cvss epss 0.00

    A Missing Required Cryptographic Step vulnerability has been identified in Moxa's embedded Linux firmware for industrial computers and controllers. This vulnerability represents an incomplete remediation of CVE-2026-0714. The firmware introduced TPM2 parameter encryption as a…

  • CVE-2025-3938MedMay 22, 2025
    risk 0.44cvss 6.8epss 0.00

    Missing Cryptographic Step vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Cryptanalysis. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise…

  • CVE-2022-20793MedNov 15, 2024
    risk 0.44cvss 6.8epss 0.00

    A vulnerability in pairing process of Cisco TelePresence CE Software and RoomOS Software for Cisco Touch 10 Devices could allow an unauthenticated, remote attacker to impersonate a legitimate device and pair with an affected device. This vulnerability is due to…

  • CVE-2018-5383MedAug 7, 2018
    risk 0.44cvss 6.8epss 0.01

    Bluetooth firmware or operating system software drivers in macOS versions before 10.13, High Sierra and iOS versions before 11.4, and Android versions before the 2018-06-05 patch may not sufficiently validate elliptic curve parameters used to generate public keys during a…

  • CVE-2026-45445HigJun 9, 2026
    risk 0.42cvss 7.5epss 0.01

    Issue summary: When an application drives an AES-OCB context through the public EVP_Cipher() one-shot interface, the application-supplied initialisation vector (IV) is silently discarded. Impact summary: Every message encrypted under the same key uses the same effective nonce…

  • CVE-2026-41395HigApr 28, 2026
    risk 0.42cvss 7.5epss 0.00

    OpenClaw before 2026.3.28 contains a webhook replay vulnerability in Plivo V3 signature verification that canonicalizes query ordering for signatures but hashes raw URLs for replay detection. Attackers can reorder query parameters to bypass replay cache detection and trigger…

  • CVE-2026-4258HigMar 17, 2026
    risk 0.42cvss 7.5epss 0.00

    Versions of the package sjcl before 1.0.9 are vulnerable to Improper Verification of Cryptographic Signature due to missing point-on-curve validation in sjcl.ecc.basicKey.publicKey(). An attacker can recover a victim's ECDH private key by sending crafted off-curve public keys…

  • CVE-2026-28498HigMar 16, 2026
    risk 0.42cvss 7.5epss 0.00

    Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a library-level vulnerability was identified in the Authlib Python library concerning the validation of OpenID Connect (OIDC) ID Tokens. Specifically, the internal hash…

  • CVE-2026-22863HigJan 15, 2026
    risk 0.42cvss 7.5epss 0.00

    Deno is a JavaScript, TypeScript, and WebAssembly runtime. Before 2.6.0, node:crypto doesn't finalize cipher. The vulnerability allows an attacker to have infinite encryptions. This can lead to naive attempts at brute forcing, as well as more refined attacks with the goal to…