VYPR

CWE-326

Inadequate Encryption Strength

ClassDraft

Description

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

A weak encryption scheme can be subjected to brute force attacks that have a reasonable chance of succeeding using current attack methods and resources.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-112 · CAPEC-192 · CAPEC-20

CVEs mapped to this weakness (471)

page 20 of 24
  • CVE-2022-29835MedSep 19, 2022
    risk 0.34cvss 5.3epss 0.00

    WD Discovery software executable files were signed with an unsafe SHA-1 hashing algorithm. An attacker could use this weakness to create forged certificate signatures due to the use of a hashing algorithm that is not collision-free. This could thereby impact the confidentiality…

  • CVE-2021-32496MedJun 28, 2021
    risk 0.34cvss 5.3epss 0.00

    SICK Visionary-S CX up version 5.21.2.29154R are vulnerable to an Inadequate Encryption Strength vulnerability concerning the internal SSH interface solely used by SICK for recovering returned devices. The use of weak ciphers make it easier for an attacker to break the security…

  • CVE-2021-25761MedFeb 3, 2021
    risk 0.34cvss 5.3epss 0.01

    In JetBrains Ktor before 1.5.0, a birthday attack on SessionStorage key was possible.

  • CVE-2014-0841MedApr 27, 2018
    risk 0.34cvss 5.3epss 0.00

    IBM Rational Focal Point 6.4.0, 6.4.1, 6.5.1, 6.5.2, and 6.6.0 use a weak algorithm to hash passwords, which makes it easier for context-dependent attackers to obtain cleartext values via a brute-force attack. IBM X-Force ID: 90704.

  • CVE-2018-4839MedMar 8, 2018
    risk 0.34cvss 5.3epss 0.01

    A vulnerability has been identified in DIGSI 4 (All versions < V4.92), EN100 Ethernet module DNP3 variant (All versions < V1.05.00), EN100 Ethernet module IEC 104 variant (All versions), EN100 Ethernet module IEC 61850 variant (All versions < V4.30), EN100 Ethernet module Modbus…

  • CVE-2018-6653MedMar 1, 2018
    risk 0.34cvss 5.3epss 0.00

    comforte SWAP 1049 through 1069 and 20.0.0 through 21.5.3 (as used in SSLOBJ on HPE NonStop SSL T0910, and in the comforte SecurCS, SecurFTP, SecurLib/SSL-AT, and SecurTN products), after executing the RELOAD CERTIFICATES command, does not ensure that clients use a strong TLS…

  • CVE-2017-5160MedApr 20, 2017
    risk 0.34cvss 5.3epss 0.01

    An Inadequate Encryption Strength issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. The software will connect via Transport Layer Security without verifying the peer's SSL certificate properly.

  • CVE-2024-52318MedNov 18, 2024
    risk 0.33cvss 6.1epss 0.02

    Incorrect object recycling and reuse vulnerability in Apache Tomcat. This issue affects Apache Tomcat: 11.0.0, 10.1.31, 9.0.96. Users are recommended to upgrade to version 11.0.1, 10.1.32 or 9.0.97, which fixes the issue.

  • CVE-2015-8086MedOct 3, 2016
    risk 0.32cvss 4.9epss 0.00

    Huawei AR routers with software before V200R007C00SPC100; Quidway S9300 routers with software before V200R009C00; S12700 routers with software before V200R008C00SPC500; S9300, Quidway S5300, and S5300 routers with software before V200R007C00; and S5700 routers with software…

  • CVE-2015-8085MedOct 3, 2016
    risk 0.32cvss 4.9epss 0.00

    Huawei AR routers with software before V200R007C00SPC100; Quidway S9300 routers with software before V200R009C00; S12700 routers with software before V200R008C00SPC500; S9300, Quidway S5300, and S5300 routers with software before V200R007C00; and S5700 routers with software…

  • CVE-2025-55248MedOct 14, 2025
    risk 0.31cvss 4.8epss 0.01

    Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network.

  • CVE-2021-27761MedMay 6, 2022
    risk 0.31cvss 4.8epss 0.00

    Weak web transport security (Weak TLS): An attacker may be able to decrypt the data using attacks

  • CVE-2021-28095MedJul 30, 2021
    risk 0.31cvss 4.8epss 0.01

    OX Documents before 7.10.5-rev5 has Incorrect Access Control for documents that contain XML structures because hash collisions can occur, due to use of CRC32.

  • CVE-2020-1982MedJul 8, 2020
    risk 0.31cvss 4.8epss 0.00

    Certain communication between PAN-OS and cloud-delivered services inadvertently use TLS 1.0, which is known to be a cryptographically weak protocol. These cloud services include Cortex Data Lake, the Customer Support Portal, and the Prisma Access infrastructure. Conditions…

  • CVE-2015-4953MedMar 29, 2018
    risk 0.31cvss 4.8epss 0.00

    IBM BigFix Remote Control before Interim Fix pack 9.1.2-TIV-IBRC912-IF0001 makes it easier for man-in-the-middle attackers to decrypt traffic by leveraging a weakness in its encryption protocol. IBM X-Force ID: 105197.

  • CVE-2017-12871MedSep 1, 2017
    risk 0.31cvss 5.9epss 0.00

    The aesEncrypt method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.x through 1.14.11 makes it easier for context-dependent attackers to bypass the encryption protection mechanism by leveraging use of the first 16 bytes of the secret key as the initialization vector…

  • CVE-2025-43925MedJun 3, 2025
    risk 0.30cvss 4.6epss 0.00

    An issue was discovered in Unicom Focal Point 7.6.1. The database is encrypted with a hardcoded key, making it easier to recover the cleartext data.

  • CVE-2025-22446MedMay 13, 2025
    risk 0.30cvss 4.6epss 0.00

    Inadequate encryption strength for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated user to potentially enable escalation of privilege via adjacent access.

  • CVE-2020-8761MedNov 12, 2020
    risk 0.30cvss 4.6epss 0.00

    Inadequate encryption strength in subsystem for Intel(R) CSME versions before 13.0.40 and 13.30.10 may allow an unauthenticated user to potentially enable information disclosure via physical access.

  • CVE-2018-21080MedApr 8, 2020
    risk 0.30cvss 4.6epss 0.00

    An issue was discovered on Samsung mobile devices with N(7.x) software. A physically proximate attacker wielding a magnet can activate NFC to bypass the lockscreen. The Samsung ID is SVE-2017-10897 (March 2018).