VYPR

CWE-326

Inadequate Encryption Strength

ClassDraft

Description

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

A weak encryption scheme can be subjected to brute force attacks that have a reasonable chance of succeeding using current attack methods and resources.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-112 · CAPEC-192 · CAPEC-20

CVEs mapped to this weakness (471)

page 13 of 24
  • CVE-2023-26941MedDec 5, 2023
    risk 0.42cvss 6.5epss 0.00

    Weak encryption mechanisms in RFID Tags in Yale Conexis L1 v1.1.0 allows attackers to create a cloned tag via physical proximity to the original.

  • CVE-2023-43757MedNov 16, 2023
    risk 0.42cvss 6.5epss 0.01

    Inadequate encryption strength vulnerability in multiple routers provided by ELECOM CO.,LTD. and LOGITEC CORPORATION allows a network-adjacent unauthenticated attacker to guess the encryption key used for wireless LAN communication and intercept the communication. As for the…

  • CVE-2023-47373MedNov 9, 2023
    risk 0.42cvss 6.5epss 0.00

    The leakage of channel access token in DRAGON FAMILY Line 13.6.1 allows remote attackers to send malicious notifications to victims.

  • CVE-2023-47372MedNov 9, 2023
    risk 0.42cvss 6.5epss 0.00

    The leakage of channel access token in UPDATESALON C-LOUNGE Line 13.6.1 allows remote attackers to send malicious notifications to victims.

  • CVE-2023-47370MedNov 9, 2023
    risk 0.42cvss 6.5epss 0.00

    The leakage of channel access token in bluetrick Line 13.6.1 allows remote attackers to send malicious notifications to victims.

  • CVE-2023-47368MedNov 9, 2023
    risk 0.42cvss 6.5epss 0.00

    The leakage of channel access token in taketorinoyu Line 13.6.1 allows remote attackers to send malicious notifications to victims.

  • CVE-2023-47369MedNov 9, 2023
    risk 0.42cvss 6.5epss 0.00

    The leakage of channel access token in best_training_member Line 13.6.1 allows remote attackers to send malicious notifications.

  • CVE-2023-47367MedNov 9, 2023
    risk 0.42cvss 6.5epss 0.00

    The leakage of channel access token in platinum clinic Line 13.6.1 allows remote attackers to send malicious notifications to victims.

  • CVE-2023-47366MedNov 9, 2023
    risk 0.42cvss 6.5epss 0.00

    The leakage of channel access token in craft_members Line 13.6.1 allows remote attackers to send malicious notifications to victims.

  • CVE-2023-47365MedNov 9, 2023
    risk 0.42cvss 6.5epss 0.00

    The leakage of channel access token in Lil.OFF-PRICE STORE Line 13.6.1 allows remote attackers to send malicious notifications to victims.

  • CVE-2023-47364MedNov 9, 2023
    risk 0.42cvss 6.5epss 0.00

    The leakage of channel access token in nagaoka taxi Line 13.6.1 allows remote attackers to send malicious notifications to victims

  • CVE-2023-47363MedNov 9, 2023
    risk 0.42cvss 6.5epss 0.00

    The leakage of channel access token in F.B.P members Line 13.6.1 allows remote attackers to send malicious notifications to victims.

  • CVE-2023-29549MedJun 2, 2023
    risk 0.42cvss 6.5epss 0.00

    Under certain circumstances, a call to the bind function may have resulted in the incorrect realm. This may have created a vulnerability relating to JavaScript-implemented sandboxes such as SES. This vulnerability affects Firefox for Android < 112, Firefox < 112,…

  • CVE-2023-23597MedJun 2, 2023
    risk 0.42cvss 6.5epss 0.00

    A compromised web child process could disable web security opening restrictions, leading to a new child process being spawned within the `file://` context. Given a reliable exploit primitive, this new process could be exploited again leading to arbitrary file read. This…

  • CVE-2023-1764MedMay 17, 2023
    risk 0.42cvss 6.5epss 0.00

    Canon IJ Network Tool/Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),IJ Network Tool/Ver.4.7.3 and earlier (supported OS: OS X 10.7.5-OS X 10.8) allows an attacker to acquire sensitive information on the Wi-Fi connection setup of the printer from the communication of…

  • CVE-2022-45379HigNov 15, 2022
    risk 0.42cvss 7.5epss 0.00

    Jenkins Script Security Plugin 1189.vb_a_b_7c8fd5fde and earlier stores whole-script approvals as the SHA-1 hash of the script, making it vulnerable to collision attacks.

  • CVE-2021-35226MedOct 10, 2022
    risk 0.42cvss 6.5epss 0.00

    An entity in Network Configuration Manager product is misconfigured and exposing password field to Solarwinds Information Service (SWIS). Exposed credentials are encrypted and require authenticated access with an NCM role.

  • CVE-2022-3433MedOct 10, 2022
    risk 0.42cvss 6.5epss 0.01

    The aeson library is not safe to use to consume untrusted JSON input. A remote user could abuse this flaw to produce a hash collision in the underlying unordered-containers library by sending specially crafted JSON data, resulting in a denial of service.

  • CVE-2022-2758MedAug 31, 2022
    risk 0.42cvss 6.5epss 0.00

    Passwords are not adequately encrypted during the communication process between all versions of LS Industrial Systems (LSIS) Co. Ltd LS Electric XG5000 software prior to V4.0 and LS Electric PLCs: all versions of XGK-CPUU/H/A/S/E prior to V3.50, all versions of XGI-CPUU/UD/H/S/E…

  • CVE-2022-29249HigMay 24, 2022
    risk 0.42cvss 7.5epss 0.01

    JavaEZ is a library that adds new functions to make Java easier. A weakness in JavaEZ 1.6 allows force decryption of locked text by unauthorized actors. The issue is NOT critical for non-secure applications, however may be critical in a situation where the highest levels of…