CWE-326
Inadequate Encryption Strength
Description
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-112 · CAPEC-192 · CAPEC-20
CVEs mapped to this weakness (471)
page 13 of 24| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-26941 | Med | 0.42 | 6.5 | 0.00 | Dec 5, 2023 | Weak encryption mechanisms in RFID Tags in Yale Conexis L1 v1.1.0 allows attackers to create a cloned tag via physical proximity to the original. | ||
| CVE-2023-43757 | Med | 0.42 | 6.5 | 0.01 | Nov 16, 2023 | Inadequate encryption strength vulnerability in multiple routers provided by ELECOM CO.,LTD. and LOGITEC CORPORATION allows a network-adjacent unauthenticated attacker to guess the encryption key used for wireless LAN communication and intercept the communication. As for the… | ||
| CVE-2023-47373 | Med | 0.42 | 6.5 | 0.00 | Nov 9, 2023 | The leakage of channel access token in DRAGON FAMILY Line 13.6.1 allows remote attackers to send malicious notifications to victims. | ||
| CVE-2023-47372 | Med | 0.42 | 6.5 | 0.00 | Nov 9, 2023 | The leakage of channel access token in UPDATESALON C-LOUNGE Line 13.6.1 allows remote attackers to send malicious notifications to victims. | ||
| CVE-2023-47370 | Med | 0.42 | 6.5 | 0.00 | Nov 9, 2023 | The leakage of channel access token in bluetrick Line 13.6.1 allows remote attackers to send malicious notifications to victims. | ||
| CVE-2023-47368 | Med | 0.42 | 6.5 | 0.00 | Nov 9, 2023 | The leakage of channel access token in taketorinoyu Line 13.6.1 allows remote attackers to send malicious notifications to victims. | ||
| CVE-2023-47369 | Med | 0.42 | 6.5 | 0.00 | Nov 9, 2023 | The leakage of channel access token in best_training_member Line 13.6.1 allows remote attackers to send malicious notifications. | ||
| CVE-2023-47367 | Med | 0.42 | 6.5 | 0.00 | Nov 9, 2023 | The leakage of channel access token in platinum clinic Line 13.6.1 allows remote attackers to send malicious notifications to victims. | ||
| CVE-2023-47366 | Med | 0.42 | 6.5 | 0.00 | Nov 9, 2023 | The leakage of channel access token in craft_members Line 13.6.1 allows remote attackers to send malicious notifications to victims. | ||
| CVE-2023-47365 | Med | 0.42 | 6.5 | 0.00 | Nov 9, 2023 | The leakage of channel access token in Lil.OFF-PRICE STORE Line 13.6.1 allows remote attackers to send malicious notifications to victims. | ||
| CVE-2023-47364 | Med | 0.42 | 6.5 | 0.00 | Nov 9, 2023 | The leakage of channel access token in nagaoka taxi Line 13.6.1 allows remote attackers to send malicious notifications to victims | ||
| CVE-2023-47363 | Med | 0.42 | 6.5 | 0.00 | Nov 9, 2023 | The leakage of channel access token in F.B.P members Line 13.6.1 allows remote attackers to send malicious notifications to victims. | ||
| CVE-2023-29549 | Med | 0.42 | 6.5 | 0.00 | Jun 2, 2023 | Under certain circumstances, a call to the bind function may have resulted in the incorrect realm. This may have created a vulnerability relating to JavaScript-implemented sandboxes such as SES. This vulnerability affects Firefox for Android < 112, Firefox < 112,… | ||
| CVE-2023-23597 | Med | 0.42 | 6.5 | 0.00 | Jun 2, 2023 | A compromised web child process could disable web security opening restrictions, leading to a new child process being spawned within the `file://` context. Given a reliable exploit primitive, this new process could be exploited again leading to arbitrary file read. This… | ||
| CVE-2023-1764 | Med | 0.42 | 6.5 | 0.00 | May 17, 2023 | Canon IJ Network Tool/Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),IJ Network Tool/Ver.4.7.3 and earlier (supported OS: OS X 10.7.5-OS X 10.8) allows an attacker to acquire sensitive information on the Wi-Fi connection setup of the printer from the communication of… | ||
| CVE-2022-45379 | Hig | 0.42 | 7.5 | 0.00 | Nov 15, 2022 | Jenkins Script Security Plugin 1189.vb_a_b_7c8fd5fde and earlier stores whole-script approvals as the SHA-1 hash of the script, making it vulnerable to collision attacks. | ||
| CVE-2021-35226 | Med | 0.42 | 6.5 | 0.00 | Oct 10, 2022 | An entity in Network Configuration Manager product is misconfigured and exposing password field to Solarwinds Information Service (SWIS). Exposed credentials are encrypted and require authenticated access with an NCM role. | ||
| CVE-2022-3433 | Med | 0.42 | 6.5 | 0.01 | Oct 10, 2022 | The aeson library is not safe to use to consume untrusted JSON input. A remote user could abuse this flaw to produce a hash collision in the underlying unordered-containers library by sending specially crafted JSON data, resulting in a denial of service. | ||
| CVE-2022-2758 | Med | 0.42 | 6.5 | 0.00 | Aug 31, 2022 | Passwords are not adequately encrypted during the communication process between all versions of LS Industrial Systems (LSIS) Co. Ltd LS Electric XG5000 software prior to V4.0 and LS Electric PLCs: all versions of XGK-CPUU/H/A/S/E prior to V3.50, all versions of XGI-CPUU/UD/H/S/E… | ||
| CVE-2022-29249 | Hig | 0.42 | 7.5 | 0.01 | May 24, 2022 | JavaEZ is a library that adds new functions to make Java easier. A weakness in JavaEZ 1.6 allows force decryption of locked text by unauthorized actors. The issue is NOT critical for non-secure applications, however may be critical in a situation where the highest levels of… |
- risk 0.42cvss 6.5epss 0.00
Weak encryption mechanisms in RFID Tags in Yale Conexis L1 v1.1.0 allows attackers to create a cloned tag via physical proximity to the original.
- risk 0.42cvss 6.5epss 0.01
Inadequate encryption strength vulnerability in multiple routers provided by ELECOM CO.,LTD. and LOGITEC CORPORATION allows a network-adjacent unauthenticated attacker to guess the encryption key used for wireless LAN communication and intercept the communication. As for the…
- risk 0.42cvss 6.5epss 0.00
The leakage of channel access token in DRAGON FAMILY Line 13.6.1 allows remote attackers to send malicious notifications to victims.
- risk 0.42cvss 6.5epss 0.00
The leakage of channel access token in UPDATESALON C-LOUNGE Line 13.6.1 allows remote attackers to send malicious notifications to victims.
- risk 0.42cvss 6.5epss 0.00
The leakage of channel access token in bluetrick Line 13.6.1 allows remote attackers to send malicious notifications to victims.
- risk 0.42cvss 6.5epss 0.00
The leakage of channel access token in taketorinoyu Line 13.6.1 allows remote attackers to send malicious notifications to victims.
- risk 0.42cvss 6.5epss 0.00
The leakage of channel access token in best_training_member Line 13.6.1 allows remote attackers to send malicious notifications.
- risk 0.42cvss 6.5epss 0.00
The leakage of channel access token in platinum clinic Line 13.6.1 allows remote attackers to send malicious notifications to victims.
- risk 0.42cvss 6.5epss 0.00
The leakage of channel access token in craft_members Line 13.6.1 allows remote attackers to send malicious notifications to victims.
- risk 0.42cvss 6.5epss 0.00
The leakage of channel access token in Lil.OFF-PRICE STORE Line 13.6.1 allows remote attackers to send malicious notifications to victims.
- risk 0.42cvss 6.5epss 0.00
The leakage of channel access token in nagaoka taxi Line 13.6.1 allows remote attackers to send malicious notifications to victims
- risk 0.42cvss 6.5epss 0.00
The leakage of channel access token in F.B.P members Line 13.6.1 allows remote attackers to send malicious notifications to victims.
- risk 0.42cvss 6.5epss 0.00
Under certain circumstances, a call to the bind function may have resulted in the incorrect realm. This may have created a vulnerability relating to JavaScript-implemented sandboxes such as SES. This vulnerability affects Firefox for Android < 112, Firefox < 112,…
- risk 0.42cvss 6.5epss 0.00
A compromised web child process could disable web security opening restrictions, leading to a new child process being spawned within the `file://` context. Given a reliable exploit primitive, this new process could be exploited again leading to arbitrary file read. This…
- risk 0.42cvss 6.5epss 0.00
Canon IJ Network Tool/Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),IJ Network Tool/Ver.4.7.3 and earlier (supported OS: OS X 10.7.5-OS X 10.8) allows an attacker to acquire sensitive information on the Wi-Fi connection setup of the printer from the communication of…
- risk 0.42cvss 7.5epss 0.00
Jenkins Script Security Plugin 1189.vb_a_b_7c8fd5fde and earlier stores whole-script approvals as the SHA-1 hash of the script, making it vulnerable to collision attacks.
- risk 0.42cvss 6.5epss 0.00
An entity in Network Configuration Manager product is misconfigured and exposing password field to Solarwinds Information Service (SWIS). Exposed credentials are encrypted and require authenticated access with an NCM role.
- risk 0.42cvss 6.5epss 0.01
The aeson library is not safe to use to consume untrusted JSON input. A remote user could abuse this flaw to produce a hash collision in the underlying unordered-containers library by sending specially crafted JSON data, resulting in a denial of service.
- risk 0.42cvss 6.5epss 0.00
Passwords are not adequately encrypted during the communication process between all versions of LS Industrial Systems (LSIS) Co. Ltd LS Electric XG5000 software prior to V4.0 and LS Electric PLCs: all versions of XGK-CPUU/H/A/S/E prior to V3.50, all versions of XGI-CPUU/UD/H/S/E…
- risk 0.42cvss 7.5epss 0.01
JavaEZ is a library that adds new functions to make Java easier. A weakness in JavaEZ 1.6 allows force decryption of locked text by unauthorized actors. The issue is NOT critical for non-secure applications, however may be critical in a situation where the highest levels of…