VYPR

CWE-326

Inadequate Encryption Strength

ClassDraft

Description

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

A weak encryption scheme can be subjected to brute force attacks that have a reasonable chance of succeeding using current attack methods and resources.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-112 · CAPEC-192 · CAPEC-20

CVEs mapped to this weakness (471)

page 19 of 24
  • CVE-2025-45769MedJul 31, 2025
    risk 0.35cvss 6.5epss 0.00

    php-jwt v6.11.0 was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key lengths are expected to be set by an application, not by this library. This dispute is subject to review under CNA rules 4.1.4, 4.1.14, and other rules; the…

  • CVE-2024-52317MedNov 18, 2024
    risk 0.35cvss 6.5epss 0.02

    Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the request and response used by HTTP/2 requests could lead to request and/or response mix-up between users. This issue affects Apache Tomcat: from 11.0.0-M23 through 11.0.0-M26,…

  • CVE-2023-22271MedMar 22, 2023
    risk 0.35cvss 5.3epss 0.01

    Experience Manager versions 6.5.15.0 (and earlier) are affected by a Weak Cryptography for Passwords vulnerability that can lead to a security feature bypass. A low-privileged attacker can exploit this in order to decrypt a user's password. The attack complexity is high since a…

  • CVE-2022-2097MedJul 5, 2022
    risk 0.35cvss 5.3epss 0.04

    AES OCB mode for 32-bit x86 platforms using the AES-NI assembly optimised implementation will not encrypt the entirety of the data under some circumstances. This could reveal sixteen bytes of data that was preexisting in the memory that wasn't written. In the special case of "in…

  • CVE-2021-37606MedJul 30, 2021
    risk 0.35cvss 5.3epss 0.01

    Meow hash 0.5/calico does not sufficiently thwart key recovery by an attacker who can query whether there's a collision in the bottom bits of the hashes of two messages, as demonstrated by an attack against a long-running web service that allows the attacker to infer collisions…

  • CVE-2020-17494MedNov 12, 2020
    risk 0.35cvss 5.3epss 0.01

    Untangle Firewall NG before 16.0 uses MD5 for passwords.

  • CVE-2020-7069MedOct 2, 2020
    risk 0.35cvss 5.4epss 0.02

    In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when AES-CCM mode is used with openssl_encrypt() function with 12 bytes IV, only first 7 bytes of the IV is actually used. This can lead to both decreased security and incorrect encryption data.

  • CVE-2020-5224MedJan 24, 2020
    risk 0.35cvss 6.5epss 0.01

    In Django User Sessions (django-user-sessions) before 1.7.1, the views provided allow users to terminate specific sessions. The session key is used to identify sessions, and thus included in the rendered HTML. In itself this is not a problem. However if the website has an XSS…

  • CVE-2018-1466MedMay 17, 2018
    risk 0.35cvss 5.3epss 0.01

    IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products (6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) use weaker than expected cryptographic algorithms that could allow an attacker to…

  • CVE-2017-2391MedApr 2, 2017
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in certain Apple products. Pages before 6.1, Numbers before 4.1, and Keynote before 7.1 on macOS and Pages before 3.1, Numbers before 3.1, and Keynote before 3.1 on iOS are affected. The issue involves the "Export" component. It allows users to bypass…

  • CVE-2026-65777MedAug 11, 2026
    risk 0.34cvss 5.3epss 0.00

    Inadequate encryption strength in Windows Active Directory allows an authorized attacker to bypass a security feature over a network.

  • CVE-2025-27524MedMay 15, 2025
    risk 0.34cvss 5.3epss 0.00

    Weak encryption vulnerability in Hitachi JP1/IT Desktop Management 2 - Smart Device Manager on Windows.This issue affects JP1/IT Desktop Management 2 - Smart Device Manager: from 12-00 before 12-00-08, from 11-10 through 11-10-08, from 11-00 through 11-00-05, from 10-50 through…

  • CVE-2024-13454MedJan 20, 2025
    risk 0.34cvss 5.3epss 0.00

    Weak encryption algorithm in Easy-RSA version 3.0.5 through 3.1.7 allows a local attacker to more easily bruteforce the private CA key when created using OpenSSL 3

  • CVE-2024-3387MedApr 10, 2024
    risk 0.34cvss 5.3epss 0.00

    A weak (low bit strength) device certificate in Palo Alto Networks Panorama software enables an attacker to perform a meddler-in-the-middle (MitM) attack to capture encrypted traffic between the Panorama management server and the firewalls it manages. With sufficient computing…

  • CVE-2022-46783MedAug 28, 2023
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in Stormshield SSL VPN Client before 3.2.0. If multiple address books are used, an attacker may be able to access the other encrypted address book.

  • CVE-2023-37301MedJun 30, 2023
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in SubmitEntityAction in Wikibase in MediaWiki through 1.39.3. Because it doesn't use EditEntity for undo and restore, the intended interaction with AbuseFilter does not occur.

  • CVE-2023-36539MedJun 30, 2023
    risk 0.34cvss 5.3epss 0.01

    Exposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information.

  • CVE-2022-43922MedFeb 1, 2023
    risk 0.34cvss 5.3epss 0.00

    IBM App Connect Enterprise Certified Container 4.1, 4.2, 5.0, 5.1, 5.2, 6.0, 6.1, and 6.2 could disclose sensitive information to an attacker due to a weak hash of an API Key in the configuration. IBM X-Force ID: 241583.

  • CVE-2022-4036MedNov 29, 2022
    risk 0.34cvss 5.3epss 0.00

    The Appointment Hour Booking plugin for WordPress is vulnerable to CAPTCHA bypass in versions up to, and including, 1.3.72. This is due to the use of insufficiently strong hashing algorithm on the CAPTCHA secret that is also displayed to the user via a cookie.

  • CVE-2022-41209MedOct 11, 2022
    risk 0.34cvss 5.2epss 0.00

    SAP Customer Data Cloud (Gigya mobile app for Android) - version 7.4, uses encryption method which lacks proper diffusion and does not hide the patterns well. This can lead to information disclosure. In certain scenarios, application might also be susceptible to replay attacks.