VYPR

CWE-326

Inadequate Encryption Strength

ClassDraft

Description

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

A weak encryption scheme can be subjected to brute force attacks that have a reasonable chance of succeeding using current attack methods and resources.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-112 · CAPEC-192 · CAPEC-20

CVEs mapped to this weakness (471)

page 18 of 24
  • CVE-2025-12439MedNov 10, 2025
    risk 0.36cvss 5.5epss 0.00

    Inappropriate implementation in App-Bound Encryption in Google Chrome on Windows prior to 142.0.7444.59 allowed a local attacker to obtain potentially sensitive information from process memory via a malicious file. (Chromium security severity: Medium)

  • CVE-2024-34113MedJun 13, 2024
    risk 0.36cvss 5.5epss 0.00

    ColdFusion versions 2023u7, 2021u13 and earlier are affected by a Weak Cryptography for Passwords vulnerability that could result in a security feature bypass. This vulnerability arises due to the use of insufficiently strong cryptographic algorithms or flawed implementation…

  • CVE-2022-40745MedApr 19, 2024
    risk 0.36cvss 5.5epss 0.00

    IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain sensitive information due to weaker than expected security. IBM X-Force ID: 236452.

  • CVE-2023-4333MedAug 15, 2023
    risk 0.36cvss 5.5epss 0.00

    Broadcom RAID Controller web interface doesn’t enforce SSL cipher ordering by server

  • CVE-2023-20942MedJul 13, 2023
    risk 0.36cvss 5.5epss 0.00

    In openMmapStream of AudioFlinger.cpp, there is a possible way to record audio without displaying the microphone privacy indicator due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction…

  • CVE-2023-33283MedJun 7, 2023
    risk 0.36cvss 5.5epss 0.00

    Marval MSM through 14.19.0.12476 uses a static encryption key for secrets. An attacker that gains access to encrypted secrets can decrypt them by using this key.

  • CVE-2023-28124MedApr 19, 2023
    risk 0.36cvss 5.5epss 0.00

    Improper usage of symmetric encryption in UI Desktop for Windows (Version 0.59.1.71 and earlier) could allow users with access to UI Desktop configuration files to decrypt their content.This vulnerability is fixed in Version 0.62.3 and later.

  • CVE-2022-34385MedFeb 11, 2023
    risk 0.36cvss 5.5epss 0.00

    SupportAssist for Home PCs (version 3.11.4 and prior) and  SupportAssist for Business PCs (version 3.2.0 and prior) contain cryptographic weakness vulnerability. An authenticated non-admin user could potentially exploit the issue and obtain sensitive information.

  • CVE-2021-32010MedMay 4, 2022
    risk 0.36cvss 5.6epss 0.00

    Inadequate Encryption Strength vulnerability in TLS stack of Secomea SiteManager, LinkManager, GateManager may facilitate man in the middle attacks. This issue affects: Secomea SiteManager All versions prior to 9.7. Secomea LinkManager versions prior to 9.7. Secomea GateManager…

  • CVE-2022-20677MedApr 15, 2022
    risk 0.36cvss 5.5epss 0.01

    Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install…

  • CVE-2022-25012MedMar 1, 2022
    risk 0.36cvss 5.5epss 0.00

    Argus Surveillance DVR v4.0 employs weak password encryption.

  • CVE-2022-22321MedMar 1, 2022
    risk 0.36cvss 5.5epss 0.00

    IBM MQ Appliance 9.2 CD and 9.2 LTS local messaging users stored with a password hash that provides insufficient protection. IBM X-Force ID: 218368.

  • CVE-2020-10375MedFeb 5, 2021
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in New Media Smarty before 9.10. Passwords are stored in the database in an obfuscated format that can be easily reversed. The file data.mdb contains these obfuscated passwords in the second column. NOTE: this is unrelated to the popular Smarty template…

  • CVE-2020-12872MedMay 15, 2020
    risk 0.36cvss 5.5epss 0.00

    yaws_config.erl in Yaws through 2.0.2 and/or 2.0.7 loads obsolete TLS ciphers, as demonstrated by ones that allow Sweet32 attacks, if running on an Erlang/OTP virtual machine with a version less than 21.0.

  • CVE-2017-6284MedMar 6, 2018
    risk 0.36cvss 5.5epss 0.00

    NVIDIA Security Engine contains a vulnerability in the Deterministic Random Bit Generator (DRBG) where the DRBG does not properly initialize and store or transmits sensitive data using a weakened encryption scheme that is unable to protect sensitive data which may lead to…

  • CVE-2002-1682MedDec 31, 2002
    risk 0.36cvss 5.5epss 0.00

    NewsReactor 1.0 uses a weak encryption scheme, which could allow local users to decrypt the passwords and gain access to other users' newsgroup accounts.

  • CVE-2002-1975MedDec 31, 2002
    risk 0.36cvss 5.5epss 0.00

    Sharp Zaurus PDA SL-5000D and SL-5500 uses a salt of "A0" to encrypt the screen-locking password as stored in the Security.conf file, which makes it easier for local users to guess the password via brute force methods.

  • CVE-2002-1739MedDec 31, 2002
    risk 0.36cvss 5.5epss 0.00

    Alt-N Technologies Mdaemon 5.0 through 5.0.6 uses a weak encryption algorithm to store user passwords, which allows local users to crack passwords.

  • CVE-2002-1946MedDec 31, 2002
    risk 0.36cvss 5.5epss 0.00

    Videsh Sanchar Nigam Limited (VSNL) Integrated Dialer Software 1.2.000, when the "Save Password" option is used, stores the password with a weak encryption scheme (one-to-one mapping) in a registry key, which allows local users to obtain and decrypt the password.

  • CVE-2025-55039MedOct 15, 2025
    risk 0.35cvss 6.5epss 0.00

    This issue affects Apache Spark versions before 3.4.4, 3.5.2 and 4.0.0. Apache Spark versions before 4.0.0, 3.5.2 and 3.4.4 use an insecure default network encryption cipher for RPC communication between nodes. When spark.network.crypto.enabled is set to true (it is set to…