VYPR

CWE-326

Inadequate Encryption Strength

ClassDraft

Description

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

A weak encryption scheme can be subjected to brute force attacks that have a reasonable chance of succeeding using current attack methods and resources.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-112 · CAPEC-192 · CAPEC-20

CVEs mapped to this weakness (471)

page 1 of 24
  • CVE-2017-1000486CriKEVJan 3, 2018
    risk 0.86cvss 9.8epss 0.94

    Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution

  • CVE-2017-11317CriKEVAug 23, 2017
    risk 0.85cvss 9.8epss 0.83

    Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload encryption, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.

  • CVE-2018-18325HigKEVJul 3, 2019
    risk 0.70cvss 7.5epss 0.74

    DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue exists because of an incomplete fix for CVE-2018-15811.

  • CVE-2018-15811HigKEVJul 3, 2019
    risk 0.70cvss 7.5epss 0.74

    DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters.

  • CVE-2020-6966CriJan 24, 2020
    risk 0.65cvss 10.0epss 0.02

    In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X, the affected products utilize a weak encryption scheme for remote desktop control,…

  • CVE-2019-16649CriSep 21, 2019
    risk 0.65cvss 10.0epss 0.01

    On Supermicro H11, H12, M11, X9, X10, and X11 products, a combination of encryption and authentication problems in the virtual media service allows capture of BMC credentials and data transferred over virtual media devices. Attackers can use captured credentials to connect…

  • CVE-2018-25272CriApr 22, 2026
    risk 0.64cvss 9.8epss 0.00

    ELBA5 5.8.0 contains a remote code execution vulnerability that allows attackers to obtain database credentials and execute arbitrary commands with SYSTEM level permissions. Attackers can connect to the database using default connector credentials, decrypt the DBA password, and…

  • CVE-2025-12478CriOct 29, 2025
    risk 0.64cvss 9.8epss 0.00

    Non-Compliant TLS Configuration.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .

  • CVE-2022-45141CriMar 6, 2023
    risk 0.64cvss 9.8epss 0.00

    Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was disclosed by Microsoft on Nov 8 2022 and per RFC8429 it is assumed that rc4-hmac is weak, Vulnerable Samba Active Directory DCs will issue rc4-hmac encrypted tickets despite the target server supporting…

  • CVE-2022-24116CriDec 26, 2022
    risk 0.64cvss 9.8epss 0.00

    Certain General Electric Renewable Energy products have inadequate encryption strength. This affects iNET and iNET II before 8.3.0.

  • CVE-2022-36555CriAug 29, 2022
    risk 0.64cvss 9.8epss 0.01

    Hytec Inter HWL-2511-SS v1.05 and below implements a SHA512crypt hash for the root account which can be easily cracked via a brute-force attack.

  • CVE-2022-30285CriAug 2, 2022
    risk 0.64cvss 9.8epss 0.01

    In Quest KACE Systems Management Appliance (SMA) through 12.0, a hash collision is possible during authentication. This may allow authentication with invalid credentials.

  • CVE-2021-42216CriDec 15, 2021
    risk 0.64cvss 9.8epss 0.01

    A Broken or Risky Cryptographic Algorithm exists in AnonAddy 0.8.5 via VerificationController.php.

  • CVE-2020-14517CriSep 16, 2020
    risk 0.64cvss 9.8epss 0.01

    Protocol encryption can be easily broken for CodeMeter (All versions prior to 6.90 are affected, including Version 6.90 or newer only if CodeMeter Runtime is running as server) and the server accepts external connections, which may allow an attacker to remotely communicate with…

  • CVE-2020-10275CriJun 24, 2020
    risk 0.64cvss 9.8epss 0.01

    The access tokens for the REST API are directly derived from the publicly available default credentials for the web interface. Given a USERNAME and a PASSWORD, the token string is generated directly with base64(USERNAME:sha256(PASSWORD)). An unauthorized attacker inside the…

  • CVE-2013-7287CriFeb 13, 2020
    risk 0.64cvss 9.8epss 0.01

    MobileIron VSP < 5.9.1 and Sentry < 5.0 has an insecure encryption scheme.

  • CVE-2019-15806CriAug 29, 2019
    risk 0.64cvss 9.8epss 0.01

    CommScope ARRIS TR4400 devices with firmware through A1.00.004-180301 are vulnerable to an authentication bypass to the administrative interface because they include the current base64 encoded password within http://192.168.1.1/basic_sett.html. Any user connected to the Wi-Fi…

  • CVE-2019-15805CriAug 29, 2019
    risk 0.64cvss 9.8epss 0.01

    CommScope ARRIS TR4400 devices with firmware through A1.00.004-180301 are vulnerable to an authentication bypass to the administrative interface because they include the current base64 encoded password within http://192.168.1.1/login.html. Any user connected to the Wi-Fi can…

  • CVE-2018-20810CriJun 28, 2019
    risk 0.64cvss 9.8epss 0.02

    Session data between cluster nodes during cluster synchronization is not properly encrypted in Pulse Secure Pulse Connect Secure (PCS) 8.3RX before 8.3R2 and Pulse Policy Secure (PPS) 5.4RX before 5.4R2. This is not applicable to PCS 8.1RX, PPS 5.2RX, or stand-alone devices.

  • CVE-2018-0448CriOct 5, 2018
    risk 0.64cvss 9.8epss 0.02

    A vulnerability in the identity management service of Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to bypass authentication and take complete control of identity management functions. The vulnerability is due to insufficient…