VYPR

CWE-326

Inadequate Encryption Strength

ClassDraft

Description

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

A weak encryption scheme can be subjected to brute force attacks that have a reasonable chance of succeeding using current attack methods and resources.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-112 · CAPEC-192 · CAPEC-20

CVEs mapped to this weakness (471)

page 7 of 24
  • CVE-2023-23911HigMar 10, 2023
    risk 0.49cvss 7.5epss 0.00

    An improper access control vulnerability exists prior to v6 that could allow an attacker to break the E2E encryption of a chat room by a user changing the group key of a chat room.

  • CVE-2023-21444HigFeb 9, 2023
    risk 0.49cvss 7.5epss 0.00

    Improper cryptographic implementation in Samsung Flow for PC 4.9.14.0 allows adjacent attackers to decrypt encrypted messages or inject commands.

  • CVE-2023-21443HigFeb 9, 2023
    risk 0.49cvss 7.5epss 0.00

    Improper cryptographic implementation in Samsung Flow for Android prior to version 4.9.04 allows adjacent attackers to decrypt encrypted messages or inject commands.

  • CVE-2022-2640HigDec 2, 2022
    risk 0.49cvss 7.5epss 0.00

    The Config-files of Horner Automation’s RCC 972 with firmware version 15.40 are encrypted with weak XOR encryption vulnerable to reverse engineering. This could allow an attacker to obtain credentials to run services such as File Transfer Protocol (FTP) and Hypertext Transfer…

  • CVE-2022-26306HigJul 25, 2022
    risk 0.49cvss 7.5epss 0.01

    LibreOffice supports the storage of passwords for web connections in the user’s configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in LibreOffice existed where the required initialization vector for encryption was…

  • CVE-2022-22453HigJul 14, 2022
    risk 0.49cvss 7.5epss 0.00

    IBM Security Verify Identity Manager 10.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 224919.

  • CVE-2022-22464HigJul 8, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 225081.

  • CVE-2022-22368HigMay 3, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM Spectrum Scale 5.1.0 through 5.1.3.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 221012.

  • CVE-2021-32945HigApr 1, 2022
    risk 0.49cvss 7.5epss 0.00

    An attacker could decipher the encryption and gain access to MDT AutoSave versions prior to v6.02.06.

  • CVE-2022-24318HigFeb 9, 2022
    risk 0.49cvss 7.5epss 0.00

    A CWE-326: Inadequate Encryption Strength vulnerability exists that could cause non-encrypted communication with the server when outdated versions of the ViewX client are used. Affected Product: ClearSCADA (All Versions), EcoStruxure Geo SCADA Expert 2019 (All Versions),…

  • CVE-2021-38947HigDec 13, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Spectrum Copy Data Management 2.2.13 and earlier uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 211242.

  • CVE-2021-20400HigDec 1, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM QRadar SIEM 7.3 and 7.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 196074.

  • CVE-2021-38891HigNov 23, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Sterling Connect:Direct Web Services 1.0 and 6.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 209508.

  • CVE-2021-44150HigNov 22, 2021
    risk 0.49cvss 7.5epss 0.01

    The client in tusdotnet through 2.5.0 relies on SHA-1 to prevent spoofing of file content.

  • CVE-2021-38984HigNov 15, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 212793.

  • CVE-2021-38983HigNov 15, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 212792.

  • CVE-2021-38862HigOct 12, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Data Risk Manager (iDNA) 2.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 207980.

  • CVE-2021-38925HigOct 6, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Sterling B2B Integrator Standard Edition 5.2.0. 0 through 6.1.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 210171.

  • CVE-2017-16632HigAug 11, 2021
    risk 0.49cvss 7.5epss 0.01

    In SapphireIMS 4097_1, the password in the database is stored in Base64 format.

  • CVE-2021-20360HigJul 13, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Cloud Pak for Applications 4.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 195031.