VYPR

CWE-326

Inadequate Encryption Strength

ClassDraft

Description

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

A weak encryption scheme can be subjected to brute force attacks that have a reasonable chance of succeeding using current attack methods and resources.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-112 · CAPEC-192 · CAPEC-20

CVEs mapped to this weakness (471)

page 15 of 24
  • CVE-2017-9645MedSep 20, 2017
    risk 0.42cvss 6.5epss 0.00

    An Inadequate Encryption Strength issue was discovered in Mirion Technologies DMC 3000 Transmitter Module, iPam Transmitter f/DMC 2000, RDS-31 iTX and variants (including RSD31-AM Package), DRM-1/2 and variants (including Solar PWR Package), DRM and RDS Based Boundary Monitors,…

  • CVE-2014-7808HigSep 15, 2017
    risk 0.42cvss 7.5epss 0.01

    Apache Wicket before 1.5.13, 6.x before 6.19.0, and 7.x before 7.0.0-M5 make it easier for attackers to defeat a cryptographic protection mechanism and predict encrypted URLs by leveraging use of CryptoMapper as the default encryption provider.

  • CVE-2016-3019MedJun 7, 2017
    risk 0.42cvss 6.5epss 0.01

    IBM Security Access Manager for Web 9.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 114462.

  • CVE-2016-7798HigJan 30, 2017
    risk 0.42cvss 7.5epss 0.03

    The openssl gem for Ruby uses the same initialization vector (IV) in GCM Mode (aes-*-gcm) when the IV is set before the key, which makes it easier for context-dependent attackers to bypass the encryption protection mechanism.

  • CVE-2026-33488HigMar 23, 2026
    risk 0.41cvss 7.4epss 0.00

    WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `createKeys()` function in the LoginControl plugin's PGP 2FA system generates 512-bit RSA keys, which have been publicly factorable since 1999. An attacker who obtains a target user's public…

  • CVE-2016-1000352HigJun 4, 2018
    risk 0.41cvss 7.4epss 0.02

    In the Bouncy Castle JCE Provider version 1.55 and earlier the ECIES implementation allowed the use of ECB mode. This mode is regarded as unsafe and support for it has been removed from the provider.

  • CVE-2024-13026MedJan 17, 2025
    risk 0.40cvss epss 0.00

    A vulnerability exists in Algo Edge up to 2.1.1 - a previously used (legacy) component of navify® Algorithm Suite. The vulnerability impacts the authentication mechanism of this component and could allow an attacker with adjacent access to the laboratory network and the Algo…

  • CVE-2023-48034MedNov 27, 2023
    risk 0.40cvss 6.1epss 0.00

    An issue discovered in Acer Wireless Keyboard SK-9662 allows attacker in physical proximity to both decrypt wireless keystrokes and inject arbitrary keystrokes via use of weak encryption.

  • CVE-2022-1318MedApr 20, 2022
    risk 0.40cvss 6.2epss 0.00

    Hills ComNav version 3002-19 suffers from a weak communication channel. Traffic across the local network for the configuration pages can be viewed by a malicious actor. The size of certain communications packets are predictable. This would allow an attacker to learn the state of…

  • CVE-2018-1518MedOct 18, 2018
    risk 0.40cvss 6.2epss 0.00

    IBM InfoSphere Information Server 11.7 is affected by a weak password encryption vulnerability that could allow a local user to obtain highly sensitive information. IBM X-Force ID: 141682.

  • CVE-2026-59651HigAug 3, 2026
    risk 0.39cvss epss 0.00

    In Bouncy Castle for Java before 1.85, BKS keystore accepts legacy version with 16-bit integrity MAC key. This issue also affects Bouncy Castle for Java LTS before 2.73.12.

  • CVE-2022-38659MedDec 19, 2022
    risk 0.39cvss 6.0epss 0.00

    In specific scenarios, on Windows the operator credentials may be encrypted in a manner that is not completely machine-dependent.

  • CVE-2025-1241MedApr 21, 2026
    risk 0.38cvss 5.8epss 0.00

    Encrypted values in Fortra's GoAnywhere MFT prior to version 7.10.0 and GoAnywhere Agents prior to version 2.2.0 utilize a static IV which allows admin users to brute-force decryption of data.

  • CVE-2025-36379MedFeb 17, 2026
    risk 0.38cvss 5.9epss 0.00

    IBM Security QRadar EDR 3.12 through 3.12.23 IBM Security ReaQta uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

  • CVE-2025-48823MedJul 8, 2025
    risk 0.38cvss 5.9epss 0.01

    Cryptographic issues in Windows Cryptographic Services allows an unauthorized attacker to disclose information over a network.

  • CVE-2025-48960MedJun 4, 2025
    risk 0.38cvss 5.9epss 0.00

    Weak server key used for TLS encryption. The following products are affected: Acronis Cyber Protect 16 (Linux, macOS, Windows) before build 39938.

  • CVE-2024-38341MedMay 28, 2025
    risk 0.38cvss 5.9epss 0.00

    IBM Sterling Secure Proxy 6.0.0.0 through 6.0.3.1, 6.1.0.0 through 6.1.0.0, and 6.2.0.0 through 6.2.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

  • CVE-2024-43382MedOct 30, 2024
    risk 0.38cvss 5.9epss 0.00

    Snowflake JDBC driver versions >= 3.2.6 and <= 3.19.1 have an Incorrect Security Setting that can result in data being uploaded to an encrypted stage without the additional layer of protection provided by client side encryption.

  • CVE-2024-37034MedJul 26, 2024
    risk 0.38cvss 5.9epss 0.00

    An issue was discovered in Couchbase Server before 7.2.5 and 7.6.0 before 7.6.1. It does not ensure that credentials are negotiated with the Key-Value (KV) service using SCRAM-SHA when remote link encryption is configured for Half-Secure.

  • CVE-2024-38867MedJul 9, 2024
    risk 0.38cvss 5.9epss 0.00

    A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V9.64), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 6MD85 (CP300) (All versions < V9.64), SIPROTEC 5 6MD86 (CP200) (All versions), SIPROTEC 5 6MD86 (CP300) (All versions < V9.64), SIPROTEC 5…