VYPR

CWE-326

Inadequate Encryption Strength

ClassDraft

Description

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

A weak encryption scheme can be subjected to brute force attacks that have a reasonable chance of succeeding using current attack methods and resources.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-112 · CAPEC-192 · CAPEC-20

CVEs mapped to this weakness (471)

page 14 of 24
  • CVE-2020-10636MedFeb 24, 2022
    risk 0.42cvss 6.5epss 0.00

    Inadequate encryption may allow the passwords for Emerson OpenEnterprise versions through 3.3.4 user accounts to be obtained.

  • CVE-2022-21800MedFeb 18, 2022
    risk 0.42cvss 6.5epss 0.01

    MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 uses the MD5 algorithm to hash the passwords before storing them but does not salt the hash. As a result, attackers may be able to…

  • CVE-2019-4291MedFeb 16, 2022
    risk 0.42cvss 6.5epss 0.00

    IBM Maximo Anywhere 7.6.4.0 could allow an attacker to reverse engineer the application due to the lack of binary protection precautions. IBM X-Force ID: 160697.

  • CVE-2021-36337MedDec 21, 2021
    risk 0.42cvss 6.5epss 0.00

    Dell Wyse Management Suite version 3.3.1 and prior support insecure Transport Security Protocols TLS 1.0 and TLS 1.1 which are susceptible to Man-In-The-Middle attacks thereby compromising Confidentiality and Integrity of data.

  • CVE-2021-39182HigNov 8, 2021
    risk 0.42cvss 7.5epss 0.01

    EnroCrypt is a Python module for encryption and hashing. Prior to version 1.1.4, EnroCrypt used the MD5 hashing algorithm in the hashing file. Beginners who are unfamiliar with hashes can face problems as MD5 is considered an insecure hashing algorithm. The vulnerability is…

  • CVE-2021-38464MedOct 19, 2021
    risk 0.42cvss 6.4epss 0.00

    InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 have inadequate encryption strength, which may allow an attacker to intercept the communication and steal sensitive information or hijack the session.

  • CVE-2021-28094MedJul 30, 2021
    risk 0.42cvss 6.5epss 0.01

    OX Documents before 7.10.5-rev7 has Incorrect Access Control for converted documents because hash collisions can occur, due to use of CRC32.

  • CVE-2021-28093MedJul 30, 2021
    risk 0.42cvss 6.5epss 0.01

    OX Documents before 7.10.5-rev5 has Incorrect Access Control of converted images because hash collisions can occur, due to use of Adler32.

  • CVE-2021-23982MedMar 31, 2021
    risk 0.42cvss 6.5epss 0.01

    Using techniques that built on the slipstream research, a malicious webpage could have scanned both an internal network's hosts as well as services running on the user's local machine utilizing WebRTC connections. This vulnerability affects Firefox ESR < 78.9, Firefox < 87, and…

  • CVE-2021-21474MedFeb 9, 2021
    risk 0.42cvss 6.5epss 0.01

    SAP HANA Database, versions - 1.0, 2.0, accepts SAML tokens with MD5 digest, an attacker who manages to obtain an MD5-digest signed SAML Assertion issued for an SAP HANA instance might be able to tamper with it and alter it in a way that the digest continues to be the same and…

  • CVE-2020-26263HigDec 21, 2020
    risk 0.42cvss 7.5epss 0.01

    tlslite-ng is an open source python library that implements SSL and TLS cryptographic protocols. In tlslite-ng before versions 0.7.6 and 0.8.0-alpha39, the code that performs decryption and padding check in RSA PKCS#1 v1.5 decryption is data dependant. In particular, the code…

  • CVE-2020-5938MedOct 29, 2020
    risk 0.42cvss 6.5epss 0.01

    On BIG-IP 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, when negotiating IPSec tunnels with configured, authenticated peers, the peer may negotiate a different key length than the BIG-IP configuration would otherwise allow.

  • CVE-2019-19101MedApr 29, 2020
    risk 0.42cvss 6.5epss 0.01

    A missing secure communication definition and an incomplete TLS validation in the upgrade service in B&R Automation Studio versions 4.0.x, 4.1.x, 4.2.x, < 4.3.11SP, < 4.4.9SP, < 4.5.5SP, < 4.6.4 and < 4.7.2 enable unauthenticated users to perform MITM attacks via the B&R upgrade…

  • CVE-2015-5361MedFeb 28, 2020
    risk 0.42cvss 6.5epss 0.00

    Background For regular, unencrypted FTP traffic, the FTP ALG can inspect the unencrypted control channel and open related sessions for the FTP data channel. These related sessions (gates) are specific to source and destination IPs and ports of client and server. The design…

  • CVE-2020-9337MedFeb 26, 2020
    risk 0.42cvss 6.5epss 0.01

    In GolfBuddy Course Manager 1.1, passwords are sent (with base64 encoding) via a GET request.

  • CVE-2019-18263MedDec 20, 2019
    risk 0.42cvss 6.5epss 0.00

    An issue was found in Philips Veradius Unity, Pulsera, and Endura Dual WAN Router, Veradius Unity (718132) with wireless option (shipped between 2016-August 2018), Veradius Unity (718132) with ViewForum option (shipped between 2016-August 2018), Pulsera (718095) and Endura…

  • CVE-2019-18241MedNov 26, 2019
    risk 0.42cvss 6.5epss 0.00

    In Philips IntelliBridge EC40 and EC80, IntelliBridge EC40 Hub all versions, and IntelliBridge EC80 Hub all versions, the SSH server running on the affected products is configured to allow weak ciphers. This could enable an unauthorized attacker with access to the network to…

  • CVE-2018-5461MedMar 6, 2018
    risk 0.42cvss 6.5epss 0.00

    An Inadequate Encryption Strength issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, and OCTOPUS Classic Platform Switches. An inadequate encryption strength vulnerability in the web interface has been identified, which may allow an attacker…

  • CVE-2018-6594HigFeb 3, 2018
    risk 0.42cvss 7.5epss 0.02

    lib/Crypto/PublicKey/ElGamal.py in PyCrypto through 2.6.1 generates weak ElGamal key parameters, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not have semantic security in face of a ciphertext-only attack). The Decisional…

  • CVE-2012-6707HigOct 19, 2017
    risk 0.42cvss 7.5epss 0.01

    WordPress through 4.8.2 uses a weak MD5-based password hashing algorithm, which makes it easier for attackers to determine cleartext values by leveraging access to the hash values. NOTE: the approach to changing this may not be fully compatible with certain use cases, such as…