VYPR

CWE-326

Inadequate Encryption Strength

ClassDraft

Description

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

A weak encryption scheme can be subjected to brute force attacks that have a reasonable chance of succeeding using current attack methods and resources.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-112 · CAPEC-192 · CAPEC-20

CVEs mapped to this weakness (471)

page 6 of 24
  • CVE-2024-54089HigFeb 11, 2025
    risk 0.49cvss 7.5epss 0.00

    A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions), APOGEE PXC Series (P2 Ethernet) (All versions), TALON TC Series (BACnet) (All versions). Affected devices contain a weak encryption mechanism based on a hard-coded key. This could allow an…

  • CVE-2024-41594HigOct 3, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue in DrayTek Vigor310 devices through 4.3.2.6 allows an attacker to obtain sensitive information because the httpd server of the Vigor management UI uses a static string for seeding the PRNG of OpenSSL.

  • CVE-2024-33662HigOct 2, 2024
    risk 0.49cvss 7.5epss 0.00

    Portainer before 2.20.2 improperly uses an encryption algorithm in the AesEncrypt function.

  • CVE-2024-22892HigSep 25, 2024
    risk 0.49cvss 7.5epss 0.00

    OpenSlides 4.0.15 was discovered to be using a weak hashing algorithm to store passwords.

  • CVE-2024-5800HigAug 12, 2024
    risk 0.49cvss 7.5epss 0.00

    Diffie-Hellman groups with insufficient strength are used in the SSL/TLS stack of B&R Automation Runtime versions before 6.0.2, allowing a network attacker to decrypt the SSL/TLS communication.

  • CVE-2024-32758HigAug 1, 2024
    risk 0.49cvss 7.5epss 0.00

    Under certain circumstances the communication between exacqVision Client and exacqVision Server will use insufficient key length and exchange

  • CVE-2024-36823HigJun 6, 2024
    risk 0.49cvss 7.5epss 0.01

    The encrypt() function of Ninja Core v7.0.0 was discovered to use a weak cryptographic algorithm, leading to a possible leakage of sensitive information.

  • CVE-2024-28974HigMay 29, 2024
    risk 0.49cvss 7.6epss 0.00

    Dell Data Protection Advisor, version(s) 19.9, contain(s) an Inadequate Encryption Strength vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of service.

  • CVE-2024-29969HigApr 19, 2024
    risk 0.49cvss 7.5epss 0.00

    When a Brocade SANnav installation is upgraded from Brocade SANnav v2.2.2 to Brocade SANnav 2.3.0, TLS/SSL weak message authentication code ciphers are added by default for port 18082.

  • CVE-2024-29950HigApr 17, 2024
    risk 0.49cvss 7.5epss 0.00

    The class FileTransfer implemented in Brocade SANnav before v2.3.1, v2.3.0a, uses the ssh-rsa signature scheme, which has a SHA-1 hash. The vulnerability could allow a remote, unauthenticated attacker to perform a man-in-the-middle attack.

  • CVE-2023-48051HigNov 20, 2023
    risk 0.49cvss 7.5epss 0.00

    An issue in /upydev/keygen.py in upydev v0.4.3 allows attackers to decrypt sensitive information via weak encryption padding.

  • CVE-2023-46894HigNov 9, 2023
    risk 0.49cvss 7.5epss 0.00

    An issue discovered in esptool 4.6.2 allows attackers to view sensitive information via weak cryptographic algorithm.

  • CVE-2023-44690HigOct 19, 2023
    risk 0.49cvss 7.5epss 0.00

    Inadequate encryption strength in mycli 1.27.0 allows attackers to view sensitive information via /mycli/config.py

  • CVE-2023-41305HigSep 27, 2023
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of 5G messages being sent without being encrypted in a VPN environment in the SMS message module. Successful exploitation of this vulnerability may affect confidentiality.

  • CVE-2023-0525HigAug 4, 2023
    risk 0.49cvss 7.5epss 0.01

    Weak Encoding for Password vulnerability in Mitsubishi Electric Corporation GOT2000 Series GT27 model versions 01.49.000 and prior, GT25 model versions 01.49.000 and prior, GT23 model versions 01.49.000 and prior, GT21 model versions 01.49.000 and prior, GOT SIMPLE Series GS25…

  • CVE-2023-34337HigJul 5, 2023
    risk 0.49cvss 7.6epss 0.00

    AMI SPx contains a vulnerability in the BMC where a user may cause an inadequate encryption strength by hash-based message authentication code (HMAC). A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity, and availability.

  • CVE-2022-45453HigMay 18, 2023
    risk 0.49cvss 7.5epss 0.00

    TLS/SSL weak cipher suites enabled. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 30984.

  • CVE-2023-2443HigMay 11, 2023
    risk 0.49cvss 7.5epss 0.01

    Rockwell Automation ThinManager product allows the use of medium strength ciphers.  If the client requests an insecure cipher, a malicious actor could potentially decrypt traffic sent between the client and server API.

  • CVE-2023-30351HigMay 10, 2023
    risk 0.49cvss 7.5epss 0.00

    Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard-coded default password for root which is stored using weak encryption. This vulnerability allows attackers to connect to the TELNET service (or UART) by using the exposed credentials.

  • CVE-2023-24502HigApr 17, 2023
    risk 0.49cvss 7.5epss 0.00

    Electra Central AC unit – The unit opens an AP with an easily calculated password.