CWE-326
Inadequate Encryption Strength
Description
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-112 · CAPEC-192 · CAPEC-20
CVEs mapped to this weakness (471)
page 7 of 24| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-23911 | Hig | 0.49 | 7.5 | 0.00 | Mar 10, 2023 | An improper access control vulnerability exists prior to v6 that could allow an attacker to break the E2E encryption of a chat room by a user changing the group key of a chat room. | ||
| CVE-2023-21444 | Hig | 0.49 | 7.5 | 0.00 | Feb 9, 2023 | Improper cryptographic implementation in Samsung Flow for PC 4.9.14.0 allows adjacent attackers to decrypt encrypted messages or inject commands. | ||
| CVE-2023-21443 | Hig | 0.49 | 7.5 | 0.00 | Feb 9, 2023 | Improper cryptographic implementation in Samsung Flow for Android prior to version 4.9.04 allows adjacent attackers to decrypt encrypted messages or inject commands. | ||
| CVE-2022-2640 | Hig | 0.49 | 7.5 | 0.00 | Dec 2, 2022 | The Config-files of Horner Automation’s RCC 972 with firmware version 15.40 are encrypted with weak XOR encryption vulnerable to reverse engineering. This could allow an attacker to obtain credentials to run services such as File Transfer Protocol (FTP) and Hypertext Transfer… | ||
| CVE-2022-26306 | Hig | 0.49 | 7.5 | 0.01 | Jul 25, 2022 | LibreOffice supports the storage of passwords for web connections in the user’s configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in LibreOffice existed where the required initialization vector for encryption was… | ||
| CVE-2022-22453 | Hig | 0.49 | 7.5 | 0.00 | Jul 14, 2022 | IBM Security Verify Identity Manager 10.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 224919. | ||
| CVE-2022-22464 | Hig | 0.49 | 7.5 | 0.01 | Jul 8, 2022 | IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 225081. | ||
| CVE-2022-22368 | Hig | 0.49 | 7.5 | 0.01 | May 3, 2022 | IBM Spectrum Scale 5.1.0 through 5.1.3.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 221012. | ||
| CVE-2021-32945 | Hig | 0.49 | 7.5 | 0.00 | Apr 1, 2022 | An attacker could decipher the encryption and gain access to MDT AutoSave versions prior to v6.02.06. | ||
| CVE-2022-24318 | Hig | 0.49 | 7.5 | 0.00 | Feb 9, 2022 | A CWE-326: Inadequate Encryption Strength vulnerability exists that could cause non-encrypted communication with the server when outdated versions of the ViewX client are used. Affected Product: ClearSCADA (All Versions), EcoStruxure Geo SCADA Expert 2019 (All Versions),… | ||
| CVE-2021-38947 | Hig | 0.49 | 7.5 | 0.01 | Dec 13, 2021 | IBM Spectrum Copy Data Management 2.2.13 and earlier uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 211242. | ||
| CVE-2021-20400 | Hig | 0.49 | 7.5 | 0.01 | Dec 1, 2021 | IBM QRadar SIEM 7.3 and 7.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 196074. | ||
| CVE-2021-38891 | Hig | 0.49 | 7.5 | 0.01 | Nov 23, 2021 | IBM Sterling Connect:Direct Web Services 1.0 and 6.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 209508. | ||
| CVE-2021-44150 | Hig | 0.49 | 7.5 | 0.01 | Nov 22, 2021 | The client in tusdotnet through 2.5.0 relies on SHA-1 to prevent spoofing of file content. | ||
| CVE-2021-38984 | Hig | 0.49 | 7.5 | 0.01 | Nov 15, 2021 | IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 212793. | ||
| CVE-2021-38983 | Hig | 0.49 | 7.5 | 0.01 | Nov 15, 2021 | IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 212792. | ||
| CVE-2021-38862 | Hig | 0.49 | 7.5 | 0.01 | Oct 12, 2021 | IBM Data Risk Manager (iDNA) 2.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 207980. | ||
| CVE-2021-38925 | Hig | 0.49 | 7.5 | 0.01 | Oct 6, 2021 | IBM Sterling B2B Integrator Standard Edition 5.2.0. 0 through 6.1.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 210171. | ||
| CVE-2017-16632 | Hig | 0.49 | 7.5 | 0.01 | Aug 11, 2021 | In SapphireIMS 4097_1, the password in the database is stored in Base64 format. | ||
| CVE-2021-20360 | Hig | 0.49 | 7.5 | 0.01 | Jul 13, 2021 | IBM Cloud Pak for Applications 4.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 195031. |
- risk 0.49cvss 7.5epss 0.00
An improper access control vulnerability exists prior to v6 that could allow an attacker to break the E2E encryption of a chat room by a user changing the group key of a chat room.
- risk 0.49cvss 7.5epss 0.00
Improper cryptographic implementation in Samsung Flow for PC 4.9.14.0 allows adjacent attackers to decrypt encrypted messages or inject commands.
- risk 0.49cvss 7.5epss 0.00
Improper cryptographic implementation in Samsung Flow for Android prior to version 4.9.04 allows adjacent attackers to decrypt encrypted messages or inject commands.
- risk 0.49cvss 7.5epss 0.00
The Config-files of Horner Automation’s RCC 972 with firmware version 15.40 are encrypted with weak XOR encryption vulnerable to reverse engineering. This could allow an attacker to obtain credentials to run services such as File Transfer Protocol (FTP) and Hypertext Transfer…
- risk 0.49cvss 7.5epss 0.01
LibreOffice supports the storage of passwords for web connections in the user’s configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in LibreOffice existed where the required initialization vector for encryption was…
- risk 0.49cvss 7.5epss 0.00
IBM Security Verify Identity Manager 10.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 224919.
- risk 0.49cvss 7.5epss 0.01
IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 225081.
- risk 0.49cvss 7.5epss 0.01
IBM Spectrum Scale 5.1.0 through 5.1.3.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 221012.
- risk 0.49cvss 7.5epss 0.00
An attacker could decipher the encryption and gain access to MDT AutoSave versions prior to v6.02.06.
- risk 0.49cvss 7.5epss 0.00
A CWE-326: Inadequate Encryption Strength vulnerability exists that could cause non-encrypted communication with the server when outdated versions of the ViewX client are used. Affected Product: ClearSCADA (All Versions), EcoStruxure Geo SCADA Expert 2019 (All Versions),…
- risk 0.49cvss 7.5epss 0.01
IBM Spectrum Copy Data Management 2.2.13 and earlier uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 211242.
- risk 0.49cvss 7.5epss 0.01
IBM QRadar SIEM 7.3 and 7.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 196074.
- risk 0.49cvss 7.5epss 0.01
IBM Sterling Connect:Direct Web Services 1.0 and 6.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 209508.
- risk 0.49cvss 7.5epss 0.01
The client in tusdotnet through 2.5.0 relies on SHA-1 to prevent spoofing of file content.
- risk 0.49cvss 7.5epss 0.01
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 212793.
- risk 0.49cvss 7.5epss 0.01
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 212792.
- risk 0.49cvss 7.5epss 0.01
IBM Data Risk Manager (iDNA) 2.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 207980.
- risk 0.49cvss 7.5epss 0.01
IBM Sterling B2B Integrator Standard Edition 5.2.0. 0 through 6.1.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 210171.
- risk 0.49cvss 7.5epss 0.01
In SapphireIMS 4097_1, the password in the database is stored in Base64 format.
- risk 0.49cvss 7.5epss 0.01
IBM Cloud Pak for Applications 4.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 195031.