CWE-326
Inadequate Encryption Strength
Description
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-112 · CAPEC-192 · CAPEC-20
CVEs mapped to this weakness (471)
page 8 of 24| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-34430 | Hig | 0.49 | 7.5 | 0.01 | Jul 8, 2021 | Eclipse TinyDTLS through 0.9-rc1 relies on the rand function in the C library, which makes it easier for remote attackers to compute the master key and then decrypt DTLS traffic. | ||
| CVE-2020-18220 | Hig | 0.49 | 7.5 | 0.00 | May 20, 2021 | Weak Encoding for Password in DoraCMS v2.1.1 and earlier allows attackers to obtain sensitive information as it does not use a random salt or IV for its AES-CBC encryption, causes password encrypted for users to be susceptible to dictionary attacks. | ||
| CVE-2021-27457 | Hig | 0.49 | 7.5 | 0.00 | May 20, 2021 | A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected products utilize a weak encryption algorithm for storage of sensitive data, which may allow an attacker to more easily obtain credentials used for access. | ||
| CVE-2020-27020 | Hig | 0.49 | 7.5 | 0.01 | May 14, 2021 | Password generator feature in Kaspersky Password Manager was not completely cryptographically strong and potentially allowed an attacker to predict generated passwords in some cases. An attacker would need to know some additional information (for example, time of password… | ||
| CVE-2020-26197 | Hig | 0.49 | 7.5 | 0.01 | Apr 20, 2021 | Dell PowerScale OneFS 8.1.0 - 9.1.0 contains an LDAP Provider inability to connect over TLSv1.2 vulnerability. It may make it easier to eavesdrop and decrypt such traffic for a malicious actor. Note: This does not affect clusters which are not relying on an LDAP server for the… | ||
| CVE-2020-10554 | Hig | 0.49 | 7.5 | 0.01 | Feb 5, 2021 | An issue was discovered in Psyprax beforee 3.2.2. Passwords used to encrypt the data are stored in the database in an obfuscated format, which can be easily reverted. For example, the password AAAAAAAA is stored in the database as MMMMMMMM. | ||
| CVE-2019-4160 | Hig | 0.49 | 7.5 | 0.01 | Jan 13, 2021 | IBM Security Guardium Data Encryption (GDE) 3.0.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 158577. | ||
| CVE-2021-3131 | Hig | 0.49 | 7.5 | 0.01 | Jan 13, 2021 | The Web server in 1C:Enterprise 8 before 8.3.17.1851 sends base64 encoded credentials in the creds URL parameter. | ||
| CVE-2017-20001 | Hig | 0.49 | 7.5 | 0.00 | Jan 1, 2021 | The AES encryption project 7.x and 8.x for Drupal does not sufficiently prevent attackers from decrypting data, aka SA-CONTRIB-2017-027. NOTE: This project is not covered by Drupal's security advisory policy. | ||
| CVE-2020-10125 | Hig | 0.49 | 7.6 | 0.00 | Aug 21, 2020 | NCR SelfServ ATMs running APTRA XFS 04.02.01 and 05.01.00 implement 512-bit RSA certificates to validate bunch note acceptor (BNA) software updates, which can be broken by an attacker with physical access in a sufficiently short period of time, thereby enabling the attacker to… | ||
| CVE-2020-13785 | Hig | 0.49 | 7.5 | 0.01 | Jun 3, 2020 | D-Link DIR-865L Ax 1.20B01 Beta devices have Inadequate Encryption Strength. | ||
| CVE-2016-11043 | Hig | 0.49 | 7.5 | 0.00 | Apr 7, 2020 | An issue was discovered on Samsung mobile devices with M(6.0) software. The S/MIME implementation in EAS uses DES (where 3DES is intended). The Samsung ID is SVE-2016-5871 (June 2016). | ||
| CVE-2020-10866 | Hig | 0.49 | 7.5 | 0.01 | Apr 1, 2020 | An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to enumerate the network interfaces and access points from a Low Integrity process via RPC. | ||
| CVE-2019-14855 | Hig | 0.49 | 7.5 | 0.01 | Mar 20, 2020 | A flaw was found in the way certificate signatures could be forged using collisions found in the SHA-1 algorithm. An attacker could use this weakness to create forged certificate signatures. This issue affects GnuPG versions before 2.2.18. | ||
| CVE-2019-12121 | Hig | 0.49 | 7.5 | 0.01 | Mar 18, 2020 | An issue was detected in ONAP Portal through Dublin. By executing a padding oracle attack using the ONAPPORTAL/processSingleSignOn UserId field, an attacker is able to decrypt arbitrary information encrypted with the same symmetric key as UserId. All Portal setups are affected. | ||
| CVE-2019-19299 | Hig | 0.49 | 7.5 | 0.01 | Mar 10, 2020 | A vulnerability has been identified in SiNVR/SiVMS Video Server (All versions < V5.0.0), SiNVR/SiVMS Video Server (All versions >= V5.0.0 < V5.0.2), SiNVR/SiVMS Video Server (All versions >= V5.0.2). The streaming service (default port 5410/tcp) of the SiVMS/SiNVR Video Server… | ||
| CVE-2020-10244 | Hig | 0.49 | 7.5 | 0.01 | Mar 9, 2020 | JPaseto before 0.3.0 generates weak hashes when using v2.local tokens. | ||
| CVE-2020-9476 | Hig | 0.49 | 7.5 | 0.01 | Mar 4, 2020 | ARRIS TG1692A devices allow remote attackers to discover the administrator login name and password by reading the /login page and performing base64 decoding. | ||
| CVE-2019-4557 | Hig | 0.49 | 7.5 | 0.01 | Feb 25, 2020 | IBM Qradar Advisor 1.1 through 2.5 with Watson uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 166206. | ||
| CVE-2013-7286 | Hig | 0.49 | 7.5 | 0.01 | Feb 12, 2020 | MobileIron VSP < 5.9.1 and Sentry < 5.0 has a weak password obfuscation algorithm |
- risk 0.49cvss 7.5epss 0.01
Eclipse TinyDTLS through 0.9-rc1 relies on the rand function in the C library, which makes it easier for remote attackers to compute the master key and then decrypt DTLS traffic.
- risk 0.49cvss 7.5epss 0.00
Weak Encoding for Password in DoraCMS v2.1.1 and earlier allows attackers to obtain sensitive information as it does not use a random salt or IV for its AES-CBC encryption, causes password encrypted for users to be susceptible to dictionary attacks.
- risk 0.49cvss 7.5epss 0.00
A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected products utilize a weak encryption algorithm for storage of sensitive data, which may allow an attacker to more easily obtain credentials used for access.
- risk 0.49cvss 7.5epss 0.01
Password generator feature in Kaspersky Password Manager was not completely cryptographically strong and potentially allowed an attacker to predict generated passwords in some cases. An attacker would need to know some additional information (for example, time of password…
- risk 0.49cvss 7.5epss 0.01
Dell PowerScale OneFS 8.1.0 - 9.1.0 contains an LDAP Provider inability to connect over TLSv1.2 vulnerability. It may make it easier to eavesdrop and decrypt such traffic for a malicious actor. Note: This does not affect clusters which are not relying on an LDAP server for the…
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in Psyprax beforee 3.2.2. Passwords used to encrypt the data are stored in the database in an obfuscated format, which can be easily reverted. For example, the password AAAAAAAA is stored in the database as MMMMMMMM.
- risk 0.49cvss 7.5epss 0.01
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 158577.
- risk 0.49cvss 7.5epss 0.01
The Web server in 1C:Enterprise 8 before 8.3.17.1851 sends base64 encoded credentials in the creds URL parameter.
- risk 0.49cvss 7.5epss 0.00
The AES encryption project 7.x and 8.x for Drupal does not sufficiently prevent attackers from decrypting data, aka SA-CONTRIB-2017-027. NOTE: This project is not covered by Drupal's security advisory policy.
- risk 0.49cvss 7.6epss 0.00
NCR SelfServ ATMs running APTRA XFS 04.02.01 and 05.01.00 implement 512-bit RSA certificates to validate bunch note acceptor (BNA) software updates, which can be broken by an attacker with physical access in a sufficiently short period of time, thereby enabling the attacker to…
- risk 0.49cvss 7.5epss 0.01
D-Link DIR-865L Ax 1.20B01 Beta devices have Inadequate Encryption Strength.
- risk 0.49cvss 7.5epss 0.00
An issue was discovered on Samsung mobile devices with M(6.0) software. The S/MIME implementation in EAS uses DES (where 3DES is intended). The Samsung ID is SVE-2016-5871 (June 2016).
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to enumerate the network interfaces and access points from a Low Integrity process via RPC.
- risk 0.49cvss 7.5epss 0.01
A flaw was found in the way certificate signatures could be forged using collisions found in the SHA-1 algorithm. An attacker could use this weakness to create forged certificate signatures. This issue affects GnuPG versions before 2.2.18.
- risk 0.49cvss 7.5epss 0.01
An issue was detected in ONAP Portal through Dublin. By executing a padding oracle attack using the ONAPPORTAL/processSingleSignOn UserId field, an attacker is able to decrypt arbitrary information encrypted with the same symmetric key as UserId. All Portal setups are affected.
- risk 0.49cvss 7.5epss 0.01
A vulnerability has been identified in SiNVR/SiVMS Video Server (All versions < V5.0.0), SiNVR/SiVMS Video Server (All versions >= V5.0.0 < V5.0.2), SiNVR/SiVMS Video Server (All versions >= V5.0.2). The streaming service (default port 5410/tcp) of the SiVMS/SiNVR Video Server…
- risk 0.49cvss 7.5epss 0.01
JPaseto before 0.3.0 generates weak hashes when using v2.local tokens.
- risk 0.49cvss 7.5epss 0.01
ARRIS TG1692A devices allow remote attackers to discover the administrator login name and password by reading the /login page and performing base64 decoding.
- risk 0.49cvss 7.5epss 0.01
IBM Qradar Advisor 1.1 through 2.5 with Watson uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 166206.
- risk 0.49cvss 7.5epss 0.01
MobileIron VSP < 5.9.1 and Sentry < 5.0 has a weak password obfuscation algorithm