VYPR

CWE-325

Missing Cryptographic Step

BaseDraft

Description

The product does not implement a required step in a cryptographic algorithm, resulting in weaker encryption than advertised by the algorithm.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-68

CVEs mapped to this weakness (62)

page 3 of 4
  • CVE-2026-0420MedJun 9, 2026
    risk 0.30cvss epss 0.00

    An improper implementation of TLS certificate validation vulnerability found in NETGEAR's ReadyCloud client app which could allow an attacker to perform attacker-in-the-middle (MiTM) style attacks impacting the product's confidentiality. This vulnerability affects the listed…

  • CVE-2022-30115MedJun 2, 2022
    risk 0.28cvss 4.3epss 0.01

    Using its HSTS support, curl can be instructed to use HTTPS directly insteadof using an insecure clear-text HTTP step even when HTTP is provided in theURL. This mechanism could be bypassed if the host name in the given URL used atrailing dot while not using one when it built the…

  • CVE-2026-6458MedJun 24, 2026
    risk 0.26cvss epss 0.00

    Missing cryptographic step in Caliptra Core Firmware (aes_256_gcm_update module) results in an incorrect GCM authentication tag. When the streaming AES-256-GCM API is used with empty AAD, the hardware GHASH accumulator state is not saved after the first update call, causing the…

  • CVE-2025-69418MedJan 27, 2026
    risk 0.26cvss 4.0epss 0.00

    Issue summary: When using the low-level OCB API directly with AES-NI orother hardware-accelerated code paths, inputs whose length is not a multipleof 16 bytes can leave the final partial block unencrypted and unauthenticated.Impact summary: The trailing 1-15…

  • CVE-2021-3680MedAug 4, 2021
    risk 0.25cvss 4.9epss 0.00

    showdoc is vulnerable to Missing Cryptographic Step

  • CVE-2026-45446MedJun 9, 2026
    risk 0.24cvss 4.8epss 0.00

    Issue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) mishandle the authentication of AAD (Additional Authenticated Data) with an empty ciphertext allowing a forgery of such messages. Impact summary: An attacker can forge empty messages with…

  • CVE-2025-5323LowMay 29, 2025
    risk 0.24cvss 3.7epss 0.00

    A vulnerability, which was classified as problematic, has been found in fossasia open-event-server 1.19.1. This issue affects the function send_email_change_user_email of the file /fossasia/open-event-server/blob/development/app/api/helpers/mail.py of the component Mail…

  • CVE-2025-59339MedSep 17, 2025
    risk 0.22cvss 4.4epss 0.00

    The Bastion provides authentication, authorization, traceability and auditability for SSH accesses. Session-recording ttyrec files, may be handled by the provided osh-encrypt-rsync script that is a helper to rotate, encrypt, sign, copy, and optionally move them to a remote…

  • CVE-2017-2598MedMay 23, 2018
    risk 0.21cvss 4.3epss 0.01

    Jenkins before versions 2.44, 2.32.2 uses AES ECB block cipher mode without IV for encrypting secrets which makes Jenkins and the stored secrets vulnerable to unnecessary risks (SECURITY-304).

  • CVE-2017-2600MedMay 15, 2018
    risk 0.21cvss 4.3epss 0.01

    In jenkins before versions 2.44, 2.32.2 node monitor data could be viewed by low privilege users via the remote API. These included system configuration and runtime information of these nodes (SECURITY-343).

  • CVE-2026-42770LowJun 9, 2026
    risk 0.17cvss 3.7epss 0.00

    Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the peer key is not properly checked for the subgroup membership. Impact summary: A malicious peer which presents an X9.42 key carrying the victim's p and g parameters, a forged q = r (a small…

  • CVE-2015-20112LowJun 29, 2025
    risk 0.15cvss 3.4epss 0.00

    RLPx 5 has two CTR streams based on the same key, IV, and nonce. This can facilitate decryption on a private network.

  • CVE-2024-55655LowDec 10, 2024
    risk 0.11cvss epss 0.00

    sigstore-python is a Python tool for generating and verifying Sigstore signatures. Versions of sigstore-python newer than 2.0.0 but prior to 3.6.0 perform insufficient validation of the "integration time" present in "v2" and "v3" bundles during the verification flow: the…

  • CVE-2017-2603LowMay 15, 2018
    risk 0.10cvss 2.6epss 0.01

    Jenkins before versions 2.44, 2.32.2 is vulnerable to a user data leak in disconnected agents' config.xml API. This could leak sensitive data such as API tokens (SECURITY-362).

  • CVE-2026-59776MedJul 21, 2026
    risk 0.00cvss 6.8epss 0.00

    Missing Cryptographic Step (CWE-325) vulnerability exists in certain FeliCa IC chips shipped in or before 2017. If the vulnerability is exploited, information stored in the IC chip may be read or tampered with.

  • CVE-2026-58638MedJul 14, 2026
    risk 0.00cvss 6.0epss 0.00

    Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.

  • CVE-2026-55144HigJul 14, 2026
    risk 0.00cvss 7.1epss 0.00

    Missing cryptographic step in Windows CryptoAPI allows an authorized attacker to perform tampering locally.

  • CVE-2023-40012MedAug 9, 2023
    risk 0.00cvss 5.9epss 0.00

    uthenticode is a small cross-platform library for partially verifying Authenticode digital signatures. Versions of uthenticode prior to the 2.x series did not check Extended Key Usages in certificates, in violation of the Authenticode X.509 certificate profile. As a result, a…

  • CVE-2023-28999MedApr 4, 2023
    risk 0.00cvss 6.9epss 0.01

    Nextcloud is an open-source productivity platform. In Nextcloud Desktop client 3.0.0 until 3.8.0, Nextcloud Android app 3.13.0 until 3.25.0, and Nextcloud iOS app 3.0.5 until 4.8.0, a malicious server administrator can gain full access to an end-to-end encrypted folder. They can…

  • CVE-2023-28998MedApr 4, 2023
    risk 0.00cvss 6.7epss 0.01

    The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server. Starting with version 3.0.0 and prior to version 3.6.5, a malicious server administrator can gain full access to an end-to-end encrypted folder. They can decrypt files, recover the folder…