VYPR

CWE-326

Inadequate Encryption Strength

ClassDraft

Description

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

A weak encryption scheme can be subjected to brute force attacks that have a reasonable chance of succeeding using current attack methods and resources.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-112 · CAPEC-192 · CAPEC-20

CVEs mapped to this weakness (471)

page 8 of 24
  • CVE-2021-34430HigJul 8, 2021
    risk 0.49cvss 7.5epss 0.01

    Eclipse TinyDTLS through 0.9-rc1 relies on the rand function in the C library, which makes it easier for remote attackers to compute the master key and then decrypt DTLS traffic.

  • CVE-2020-18220HigMay 20, 2021
    risk 0.49cvss 7.5epss 0.00

    Weak Encoding for Password in DoraCMS v2.1.1 and earlier allows attackers to obtain sensitive information as it does not use a random salt or IV for its AES-CBC encryption, causes password encrypted for users to be susceptible to dictionary attacks.

  • CVE-2021-27457HigMay 20, 2021
    risk 0.49cvss 7.5epss 0.00

    A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected products utilize a weak encryption algorithm for storage of sensitive data, which may allow an attacker to more easily obtain credentials used for access.

  • CVE-2020-27020HigMay 14, 2021
    risk 0.49cvss 7.5epss 0.01

    Password generator feature in Kaspersky Password Manager was not completely cryptographically strong and potentially allowed an attacker to predict generated passwords in some cases. An attacker would need to know some additional information (for example, time of password…

  • CVE-2020-26197HigApr 20, 2021
    risk 0.49cvss 7.5epss 0.01

    Dell PowerScale OneFS 8.1.0 - 9.1.0 contains an LDAP Provider inability to connect over TLSv1.2 vulnerability. It may make it easier to eavesdrop and decrypt such traffic for a malicious actor. Note: This does not affect clusters which are not relying on an LDAP server for the…

  • CVE-2020-10554HigFeb 5, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Psyprax beforee 3.2.2. Passwords used to encrypt the data are stored in the database in an obfuscated format, which can be easily reverted. For example, the password AAAAAAAA is stored in the database as MMMMMMMM.

  • CVE-2019-4160HigJan 13, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Security Guardium Data Encryption (GDE) 3.0.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 158577.

  • CVE-2021-3131HigJan 13, 2021
    risk 0.49cvss 7.5epss 0.01

    The Web server in 1C:Enterprise 8 before 8.3.17.1851 sends base64 encoded credentials in the creds URL parameter.

  • CVE-2017-20001HigJan 1, 2021
    risk 0.49cvss 7.5epss 0.00

    The AES encryption project 7.x and 8.x for Drupal does not sufficiently prevent attackers from decrypting data, aka SA-CONTRIB-2017-027. NOTE: This project is not covered by Drupal's security advisory policy.

  • CVE-2020-10125HigAug 21, 2020
    risk 0.49cvss 7.6epss 0.00

    NCR SelfServ ATMs running APTRA XFS 04.02.01 and 05.01.00 implement 512-bit RSA certificates to validate bunch note acceptor (BNA) software updates, which can be broken by an attacker with physical access in a sufficiently short period of time, thereby enabling the attacker to…

  • CVE-2020-13785HigJun 3, 2020
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-865L Ax 1.20B01 Beta devices have Inadequate Encryption Strength.

  • CVE-2016-11043HigApr 7, 2020
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered on Samsung mobile devices with M(6.0) software. The S/MIME implementation in EAS uses DES (where 3DES is intended). The Samsung ID is SVE-2016-5871 (June 2016).

  • CVE-2020-10866HigApr 1, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to enumerate the network interfaces and access points from a Low Integrity process via RPC.

  • CVE-2019-14855HigMar 20, 2020
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in the way certificate signatures could be forged using collisions found in the SHA-1 algorithm. An attacker could use this weakness to create forged certificate signatures. This issue affects GnuPG versions before 2.2.18.

  • CVE-2019-12121HigMar 18, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was detected in ONAP Portal through Dublin. By executing a padding oracle attack using the ONAPPORTAL/processSingleSignOn UserId field, an attacker is able to decrypt arbitrary information encrypted with the same symmetric key as UserId. All Portal setups are affected.

  • CVE-2019-19299HigMar 10, 2020
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in SiNVR/SiVMS Video Server (All versions < V5.0.0), SiNVR/SiVMS Video Server (All versions >= V5.0.0 < V5.0.2), SiNVR/SiVMS Video Server (All versions >= V5.0.2). The streaming service (default port 5410/tcp) of the SiVMS/SiNVR Video Server…

  • CVE-2020-10244HigMar 9, 2020
    risk 0.49cvss 7.5epss 0.01

    JPaseto before 0.3.0 generates weak hashes when using v2.local tokens.

  • CVE-2020-9476HigMar 4, 2020
    risk 0.49cvss 7.5epss 0.01

    ARRIS TG1692A devices allow remote attackers to discover the administrator login name and password by reading the /login page and performing base64 decoding.

  • CVE-2019-4557HigFeb 25, 2020
    risk 0.49cvss 7.5epss 0.01

    IBM Qradar Advisor 1.1 through 2.5 with Watson uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 166206.

  • CVE-2013-7286HigFeb 12, 2020
    risk 0.49cvss 7.5epss 0.01

    MobileIron VSP < 5.9.1 and Sentry < 5.0 has a weak password obfuscation algorithm