VYPR

CWE-326

Inadequate Encryption Strength

ClassDraft

Description

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

A weak encryption scheme can be subjected to brute force attacks that have a reasonable chance of succeeding using current attack methods and resources.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-112 · CAPEC-192 · CAPEC-20

CVEs mapped to this weakness (471)

page 16 of 24
  • CVE-2022-48193MedNov 6, 2023
    risk 0.38cvss 5.9epss 0.00

    Weak ciphers in Softing smartLink SW-HT before 1.30 are enabled during secure communication (SSL).

  • CVE-2023-4129MedSep 27, 2023
    risk 0.38cvss 5.9epss 0.00

    Dell Data Protection Central, version 19.9, contains an Inadequate Encryption Strength Vulnerability. An unauthenticated network attacker could potentially exploit this vulnerability, allowing an attacker to recover plaintext from a block of ciphertext.

  • CVE-2023-28021MedJul 18, 2023
    risk 0.38cvss 5.9epss 0.00

    The BigFix WebUI uses weak cipher suites.

  • CVE-2023-36748MedJul 11, 2023
    risk 0.38cvss 5.9epss 0.00

    A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V2.16.0), RUGGEDCOM ROX RX1501 (All versions < V2.16.0),…

  • CVE-2023-33982MedMay 24, 2023
    risk 0.38cvss 5.9epss 0.00

    Bramble Handshake Protocol (BHP) in Briar before 1.5.3 is not forward secure: eavesdroppers can decrypt network traffic between two accounts if they later compromise both accounts. NOTE: the eavesdropping is typically impractical because BHP runs over an encrypted session that…

  • CVE-2020-4099MedNov 1, 2022
    risk 0.38cvss 5.9epss 0.00

    The application was signed using a key length less than or equal to 1024 bits, making it potentially vulnerable to forged digital signatures. An attacker could forge the same digital signature of the app after maliciously modifying the app.

  • CVE-2021-20369MedJul 13, 2021
    risk 0.38cvss 5.9epss 0.01

    IBM Cloud Pak for Applications 4.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 195361.

  • CVE-2018-16499MedMay 26, 2021
    risk 0.38cvss 5.9epss 0.00

    In VOS compromised, an attacker at network endpoints can possibly view communications between an unsuspecting user and the service using man-in-the-middle attacks. Usage of unapproved SSH encryption protocols or cipher suites also violates the Data Protection TSR (Technical…

  • CVE-2020-5917MedAug 26, 2020
    risk 0.38cvss 5.9epss 0.01

    In BIG-IP versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.2 and BIG-IQ versions 5.2.0-7.0.0, the host OpenSSH servers utilize keys of less than 2048 bits which are no longer considered secure.

  • CVE-2020-10919MedJul 23, 2020
    risk 0.38cvss 5.9epss 0.02

    This vulnerability allows remote attackers to disclose sensitive information on affected installations of C-MORE HMI EA9 Firmware version 6.52 touch screen panels. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of…

  • CVE-2017-1712MedJul 1, 2020
    risk 0.38cvss 5.9epss 0.01

    "A vulnerability in the TLS protocol implementation of the Domino server could allow an unauthenticated, remote attacker to access sensitive information, aka a Return of Bleichenbacher's Oracle Threat (ROBOT) attack. An attacker could iteratively query a server running a…

  • CVE-2020-3929MedJun 12, 2020
    risk 0.38cvss 5.9epss 0.01

    GeoVision Door Access Control device family employs shared cryptographic private keys for SSH and HTTPS. Attackers may conduct MITM attack with the derived keys and plaintext recover of encrypted messages.

  • CVE-2020-12714MedJun 11, 2020
    risk 0.38cvss 5.9epss 0.01

    An issue was discovered in CipherMail Community Gateway Virtual Appliances and Professional/Enterprise Gateway Virtual Appliances versions 1.0.1 through 4.7.1-0 and CipherMail Webmail Messenger Virtual Appliances 1.1.1 through 3.1.1-0. A Diffie-Hellman parameter of insufficient…

  • CVE-2019-19097MedApr 2, 2020
    risk 0.38cvss 5.9epss 0.01

    ABB eSOMS versions 4.0 to 6.0.3 accept connections using medium strength ciphers. If a connection is enabled using such a cipher, an attacker might be able to eavesdrop and/or intercept the connection.

  • CVE-2019-18863MedMar 2, 2020
    risk 0.38cvss 5.9epss 0.01

    A key length vulnerability in the implementation of the SRTP 128-bit key on Mitel 6800 and 6900 SIP series phones, versions 5.1.0.2051 SP2 and earlier, could allow an attacker to launch a man-in-the-middle attack when SRTP is used in a call. A successful exploit may allow the…

  • CVE-2019-13163MedFeb 7, 2020
    risk 0.38cvss 5.9epss 0.01

    The Fujitsu TLS library allows a man-in-the-middle attack. This affects Interstage Application Development Cycle Manager V10 and other versions, Interstage Application Server V12 and other versions, Interstage Business Application Manager V2 and other versions, Interstage…

  • CVE-2019-4102MedJul 1, 2019
    risk 0.38cvss 5.9epss 0.01

    IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 158092.

  • CVE-2019-4151MedJun 25, 2019
    risk 0.38cvss 5.9epss 0.01

    IBM Security Access Manager 9.0.1 through 9.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 158512.

  • CVE-2018-1608MedMay 1, 2019
    risk 0.38cvss 5.9epss 0.01

    IBM Rational Engineering Lifecycle Manager 6.0 through 6.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 143798.

  • CVE-2018-2007MedApr 29, 2019
    risk 0.38cvss 5.9epss 0.01

    IBM API Connect 2018.1 and 2018.4.1.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 155078.