CWE-326
Inadequate Encryption Strength
Description
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-112 · CAPEC-192 · CAPEC-20
CVEs mapped to this weakness (471)
page 6 of 24| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-54089 | Hig | 0.49 | 7.5 | 0.00 | Feb 11, 2025 | A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions), APOGEE PXC Series (P2 Ethernet) (All versions), TALON TC Series (BACnet) (All versions). Affected devices contain a weak encryption mechanism based on a hard-coded key. This could allow an… | ||
| CVE-2024-41594 | Hig | 0.49 | 7.5 | 0.00 | Oct 3, 2024 | An issue in DrayTek Vigor310 devices through 4.3.2.6 allows an attacker to obtain sensitive information because the httpd server of the Vigor management UI uses a static string for seeding the PRNG of OpenSSL. | ||
| CVE-2024-33662 | Hig | 0.49 | 7.5 | 0.00 | Oct 2, 2024 | Portainer before 2.20.2 improperly uses an encryption algorithm in the AesEncrypt function. | ||
| CVE-2024-22892 | Hig | 0.49 | 7.5 | 0.00 | Sep 25, 2024 | OpenSlides 4.0.15 was discovered to be using a weak hashing algorithm to store passwords. | ||
| CVE-2024-5800 | Hig | 0.49 | 7.5 | 0.00 | Aug 12, 2024 | Diffie-Hellman groups with insufficient strength are used in the SSL/TLS stack of B&R Automation Runtime versions before 6.0.2, allowing a network attacker to decrypt the SSL/TLS communication. | ||
| CVE-2024-32758 | Hig | 0.49 | 7.5 | 0.00 | Aug 1, 2024 | Under certain circumstances the communication between exacqVision Client and exacqVision Server will use insufficient key length and exchange | ||
| CVE-2024-36823 | Hig | 0.49 | 7.5 | 0.01 | Jun 6, 2024 | The encrypt() function of Ninja Core v7.0.0 was discovered to use a weak cryptographic algorithm, leading to a possible leakage of sensitive information. | ||
| CVE-2024-28974 | Hig | 0.49 | 7.6 | 0.00 | May 29, 2024 | Dell Data Protection Advisor, version(s) 19.9, contain(s) an Inadequate Encryption Strength vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of service. | ||
| CVE-2024-29969 | Hig | 0.49 | 7.5 | 0.00 | Apr 19, 2024 | When a Brocade SANnav installation is upgraded from Brocade SANnav v2.2.2 to Brocade SANnav 2.3.0, TLS/SSL weak message authentication code ciphers are added by default for port 18082. | ||
| CVE-2024-29950 | Hig | 0.49 | 7.5 | 0.00 | Apr 17, 2024 | The class FileTransfer implemented in Brocade SANnav before v2.3.1, v2.3.0a, uses the ssh-rsa signature scheme, which has a SHA-1 hash. The vulnerability could allow a remote, unauthenticated attacker to perform a man-in-the-middle attack. | ||
| CVE-2023-48051 | Hig | 0.49 | 7.5 | 0.00 | Nov 20, 2023 | An issue in /upydev/keygen.py in upydev v0.4.3 allows attackers to decrypt sensitive information via weak encryption padding. | ||
| CVE-2023-46894 | Hig | 0.49 | 7.5 | 0.00 | Nov 9, 2023 | An issue discovered in esptool 4.6.2 allows attackers to view sensitive information via weak cryptographic algorithm. | ||
| CVE-2023-44690 | Hig | 0.49 | 7.5 | 0.00 | Oct 19, 2023 | Inadequate encryption strength in mycli 1.27.0 allows attackers to view sensitive information via /mycli/config.py | ||
| CVE-2023-41305 | Hig | 0.49 | 7.5 | 0.00 | Sep 27, 2023 | Vulnerability of 5G messages being sent without being encrypted in a VPN environment in the SMS message module. Successful exploitation of this vulnerability may affect confidentiality. | ||
| CVE-2023-0525 | Hig | 0.49 | 7.5 | 0.01 | Aug 4, 2023 | Weak Encoding for Password vulnerability in Mitsubishi Electric Corporation GOT2000 Series GT27 model versions 01.49.000 and prior, GT25 model versions 01.49.000 and prior, GT23 model versions 01.49.000 and prior, GT21 model versions 01.49.000 and prior, GOT SIMPLE Series GS25… | ||
| CVE-2023-34337 | Hig | 0.49 | 7.6 | 0.00 | Jul 5, 2023 | AMI SPx contains a vulnerability in the BMC where a user may cause an inadequate encryption strength by hash-based message authentication code (HMAC). A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity, and availability. | ||
| CVE-2022-45453 | Hig | 0.49 | 7.5 | 0.00 | May 18, 2023 | TLS/SSL weak cipher suites enabled. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 30984. | ||
| CVE-2023-2443 | Hig | 0.49 | 7.5 | 0.01 | May 11, 2023 | Rockwell Automation ThinManager product allows the use of medium strength ciphers. If the client requests an insecure cipher, a malicious actor could potentially decrypt traffic sent between the client and server API. | ||
| CVE-2023-30351 | Hig | 0.49 | 7.5 | 0.00 | May 10, 2023 | Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard-coded default password for root which is stored using weak encryption. This vulnerability allows attackers to connect to the TELNET service (or UART) by using the exposed credentials. | ||
| CVE-2023-24502 | Hig | 0.49 | 7.5 | 0.00 | Apr 17, 2023 | Electra Central AC unit – The unit opens an AP with an easily calculated password. |
- risk 0.49cvss 7.5epss 0.00
A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions), APOGEE PXC Series (P2 Ethernet) (All versions), TALON TC Series (BACnet) (All versions). Affected devices contain a weak encryption mechanism based on a hard-coded key. This could allow an…
- risk 0.49cvss 7.5epss 0.00
An issue in DrayTek Vigor310 devices through 4.3.2.6 allows an attacker to obtain sensitive information because the httpd server of the Vigor management UI uses a static string for seeding the PRNG of OpenSSL.
- risk 0.49cvss 7.5epss 0.00
Portainer before 2.20.2 improperly uses an encryption algorithm in the AesEncrypt function.
- risk 0.49cvss 7.5epss 0.00
OpenSlides 4.0.15 was discovered to be using a weak hashing algorithm to store passwords.
- risk 0.49cvss 7.5epss 0.00
Diffie-Hellman groups with insufficient strength are used in the SSL/TLS stack of B&R Automation Runtime versions before 6.0.2, allowing a network attacker to decrypt the SSL/TLS communication.
- risk 0.49cvss 7.5epss 0.00
Under certain circumstances the communication between exacqVision Client and exacqVision Server will use insufficient key length and exchange
- risk 0.49cvss 7.5epss 0.01
The encrypt() function of Ninja Core v7.0.0 was discovered to use a weak cryptographic algorithm, leading to a possible leakage of sensitive information.
- risk 0.49cvss 7.6epss 0.00
Dell Data Protection Advisor, version(s) 19.9, contain(s) an Inadequate Encryption Strength vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of service.
- risk 0.49cvss 7.5epss 0.00
When a Brocade SANnav installation is upgraded from Brocade SANnav v2.2.2 to Brocade SANnav 2.3.0, TLS/SSL weak message authentication code ciphers are added by default for port 18082.
- risk 0.49cvss 7.5epss 0.00
The class FileTransfer implemented in Brocade SANnav before v2.3.1, v2.3.0a, uses the ssh-rsa signature scheme, which has a SHA-1 hash. The vulnerability could allow a remote, unauthenticated attacker to perform a man-in-the-middle attack.
- risk 0.49cvss 7.5epss 0.00
An issue in /upydev/keygen.py in upydev v0.4.3 allows attackers to decrypt sensitive information via weak encryption padding.
- risk 0.49cvss 7.5epss 0.00
An issue discovered in esptool 4.6.2 allows attackers to view sensitive information via weak cryptographic algorithm.
- risk 0.49cvss 7.5epss 0.00
Inadequate encryption strength in mycli 1.27.0 allows attackers to view sensitive information via /mycli/config.py
- risk 0.49cvss 7.5epss 0.00
Vulnerability of 5G messages being sent without being encrypted in a VPN environment in the SMS message module. Successful exploitation of this vulnerability may affect confidentiality.
- risk 0.49cvss 7.5epss 0.01
Weak Encoding for Password vulnerability in Mitsubishi Electric Corporation GOT2000 Series GT27 model versions 01.49.000 and prior, GT25 model versions 01.49.000 and prior, GT23 model versions 01.49.000 and prior, GT21 model versions 01.49.000 and prior, GOT SIMPLE Series GS25…
- risk 0.49cvss 7.6epss 0.00
AMI SPx contains a vulnerability in the BMC where a user may cause an inadequate encryption strength by hash-based message authentication code (HMAC). A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity, and availability.
- risk 0.49cvss 7.5epss 0.00
TLS/SSL weak cipher suites enabled. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 30984.
- risk 0.49cvss 7.5epss 0.01
Rockwell Automation ThinManager product allows the use of medium strength ciphers. If the client requests an insecure cipher, a malicious actor could potentially decrypt traffic sent between the client and server API.
- risk 0.49cvss 7.5epss 0.00
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard-coded default password for root which is stored using weak encryption. This vulnerability allows attackers to connect to the TELNET service (or UART) by using the exposed credentials.
- risk 0.49cvss 7.5epss 0.00
Electra Central AC unit – The unit opens an AP with an easily calculated password.