CWE-326
Inadequate Encryption Strength
Description
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-112 · CAPEC-192 · CAPEC-20
CVEs mapped to this weakness (471)
page 1 of 24| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-1000486 | Cri | 0.86 | 9.8 | 0.94 | KEV | Jan 3, 2018 | Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution | |
| CVE-2017-11317 | Cri | 0.85 | 9.8 | 0.83 | KEV | Aug 23, 2017 | Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload encryption, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code. | |
| CVE-2018-18325 | Hig | 0.70 | 7.5 | 0.74 | KEV | Jul 3, 2019 | DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue exists because of an incomplete fix for CVE-2018-15811. | |
| CVE-2018-15811 | Hig | 0.70 | 7.5 | 0.74 | KEV | Jul 3, 2019 | DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters. | |
| CVE-2020-6966 | Cri | 0.65 | 10.0 | 0.02 | Jan 24, 2020 | In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X, the affected products utilize a weak encryption scheme for remote desktop control,… | ||
| CVE-2019-16649 | Cri | 0.65 | 10.0 | 0.01 | Sep 21, 2019 | On Supermicro H11, H12, M11, X9, X10, and X11 products, a combination of encryption and authentication problems in the virtual media service allows capture of BMC credentials and data transferred over virtual media devices. Attackers can use captured credentials to connect… | ||
| CVE-2018-25272 | Cri | 0.64 | 9.8 | 0.00 | Apr 22, 2026 | ELBA5 5.8.0 contains a remote code execution vulnerability that allows attackers to obtain database credentials and execute arbitrary commands with SYSTEM level permissions. Attackers can connect to the database using default connector credentials, decrypt the DBA password, and… | ||
| CVE-2025-12478 | Cri | 0.64 | 9.8 | 0.00 | Oct 29, 2025 | Non-Compliant TLS Configuration.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 . | ||
| CVE-2022-45141 | Cri | 0.64 | 9.8 | 0.00 | Mar 6, 2023 | Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was disclosed by Microsoft on Nov 8 2022 and per RFC8429 it is assumed that rc4-hmac is weak, Vulnerable Samba Active Directory DCs will issue rc4-hmac encrypted tickets despite the target server supporting… | ||
| CVE-2022-24116 | Cri | 0.64 | 9.8 | 0.00 | Dec 26, 2022 | Certain General Electric Renewable Energy products have inadequate encryption strength. This affects iNET and iNET II before 8.3.0. | ||
| CVE-2022-36555 | Cri | 0.64 | 9.8 | 0.01 | Aug 29, 2022 | Hytec Inter HWL-2511-SS v1.05 and below implements a SHA512crypt hash for the root account which can be easily cracked via a brute-force attack. | ||
| CVE-2022-30285 | Cri | 0.64 | 9.8 | 0.01 | Aug 2, 2022 | In Quest KACE Systems Management Appliance (SMA) through 12.0, a hash collision is possible during authentication. This may allow authentication with invalid credentials. | ||
| CVE-2021-42216 | Cri | 0.64 | 9.8 | 0.01 | Dec 15, 2021 | A Broken or Risky Cryptographic Algorithm exists in AnonAddy 0.8.5 via VerificationController.php. | ||
| CVE-2020-14517 | Cri | 0.64 | 9.8 | 0.01 | Sep 16, 2020 | Protocol encryption can be easily broken for CodeMeter (All versions prior to 6.90 are affected, including Version 6.90 or newer only if CodeMeter Runtime is running as server) and the server accepts external connections, which may allow an attacker to remotely communicate with… | ||
| CVE-2020-10275 | Cri | 0.64 | 9.8 | 0.01 | Jun 24, 2020 | The access tokens for the REST API are directly derived from the publicly available default credentials for the web interface. Given a USERNAME and a PASSWORD, the token string is generated directly with base64(USERNAME:sha256(PASSWORD)). An unauthorized attacker inside the… | ||
| CVE-2013-7287 | Cri | 0.64 | 9.8 | 0.01 | Feb 13, 2020 | MobileIron VSP < 5.9.1 and Sentry < 5.0 has an insecure encryption scheme. | ||
| CVE-2019-15806 | Cri | 0.64 | 9.8 | 0.01 | Aug 29, 2019 | CommScope ARRIS TR4400 devices with firmware through A1.00.004-180301 are vulnerable to an authentication bypass to the administrative interface because they include the current base64 encoded password within http://192.168.1.1/basic_sett.html. Any user connected to the Wi-Fi… | ||
| CVE-2019-15805 | Cri | 0.64 | 9.8 | 0.01 | Aug 29, 2019 | CommScope ARRIS TR4400 devices with firmware through A1.00.004-180301 are vulnerable to an authentication bypass to the administrative interface because they include the current base64 encoded password within http://192.168.1.1/login.html. Any user connected to the Wi-Fi can… | ||
| CVE-2018-20810 | Cri | 0.64 | 9.8 | 0.02 | Jun 28, 2019 | Session data between cluster nodes during cluster synchronization is not properly encrypted in Pulse Secure Pulse Connect Secure (PCS) 8.3RX before 8.3R2 and Pulse Policy Secure (PPS) 5.4RX before 5.4R2. This is not applicable to PCS 8.1RX, PPS 5.2RX, or stand-alone devices. | ||
| CVE-2018-0448 | Cri | 0.64 | 9.8 | 0.02 | Oct 5, 2018 | A vulnerability in the identity management service of Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to bypass authentication and take complete control of identity management functions. The vulnerability is due to insufficient… |
- risk 0.86cvss 9.8epss 0.94
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
- risk 0.85cvss 9.8epss 0.83
Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload encryption, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.
- risk 0.70cvss 7.5epss 0.74
DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue exists because of an incomplete fix for CVE-2018-15811.
- risk 0.70cvss 7.5epss 0.74
DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters.
- risk 0.65cvss 10.0epss 0.02
In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X, the affected products utilize a weak encryption scheme for remote desktop control,…
- risk 0.65cvss 10.0epss 0.01
On Supermicro H11, H12, M11, X9, X10, and X11 products, a combination of encryption and authentication problems in the virtual media service allows capture of BMC credentials and data transferred over virtual media devices. Attackers can use captured credentials to connect…
- risk 0.64cvss 9.8epss 0.00
ELBA5 5.8.0 contains a remote code execution vulnerability that allows attackers to obtain database credentials and execute arbitrary commands with SYSTEM level permissions. Attackers can connect to the database using default connector credentials, decrypt the DBA password, and…
- risk 0.64cvss 9.8epss 0.00
Non-Compliant TLS Configuration.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .
- risk 0.64cvss 9.8epss 0.00
Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was disclosed by Microsoft on Nov 8 2022 and per RFC8429 it is assumed that rc4-hmac is weak, Vulnerable Samba Active Directory DCs will issue rc4-hmac encrypted tickets despite the target server supporting…
- risk 0.64cvss 9.8epss 0.00
Certain General Electric Renewable Energy products have inadequate encryption strength. This affects iNET and iNET II before 8.3.0.
- risk 0.64cvss 9.8epss 0.01
Hytec Inter HWL-2511-SS v1.05 and below implements a SHA512crypt hash for the root account which can be easily cracked via a brute-force attack.
- risk 0.64cvss 9.8epss 0.01
In Quest KACE Systems Management Appliance (SMA) through 12.0, a hash collision is possible during authentication. This may allow authentication with invalid credentials.
- risk 0.64cvss 9.8epss 0.01
A Broken or Risky Cryptographic Algorithm exists in AnonAddy 0.8.5 via VerificationController.php.
- risk 0.64cvss 9.8epss 0.01
Protocol encryption can be easily broken for CodeMeter (All versions prior to 6.90 are affected, including Version 6.90 or newer only if CodeMeter Runtime is running as server) and the server accepts external connections, which may allow an attacker to remotely communicate with…
- risk 0.64cvss 9.8epss 0.01
The access tokens for the REST API are directly derived from the publicly available default credentials for the web interface. Given a USERNAME and a PASSWORD, the token string is generated directly with base64(USERNAME:sha256(PASSWORD)). An unauthorized attacker inside the…
- risk 0.64cvss 9.8epss 0.01
MobileIron VSP < 5.9.1 and Sentry < 5.0 has an insecure encryption scheme.
- risk 0.64cvss 9.8epss 0.01
CommScope ARRIS TR4400 devices with firmware through A1.00.004-180301 are vulnerable to an authentication bypass to the administrative interface because they include the current base64 encoded password within http://192.168.1.1/basic_sett.html. Any user connected to the Wi-Fi…
- risk 0.64cvss 9.8epss 0.01
CommScope ARRIS TR4400 devices with firmware through A1.00.004-180301 are vulnerable to an authentication bypass to the administrative interface because they include the current base64 encoded password within http://192.168.1.1/login.html. Any user connected to the Wi-Fi can…
- risk 0.64cvss 9.8epss 0.02
Session data between cluster nodes during cluster synchronization is not properly encrypted in Pulse Secure Pulse Connect Secure (PCS) 8.3RX before 8.3R2 and Pulse Policy Secure (PPS) 5.4RX before 5.4R2. This is not applicable to PCS 8.1RX, PPS 5.2RX, or stand-alone devices.
- risk 0.64cvss 9.8epss 0.02
A vulnerability in the identity management service of Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to bypass authentication and take complete control of identity management functions. The vulnerability is due to insufficient…