CWE-326
Inadequate Encryption Strength
Description
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-112 · CAPEC-192 · CAPEC-20
CVEs mapped to this weakness (471)
page 9 of 24| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2011-3629 | Hig | 0.49 | 7.5 | 0.01 | Feb 4, 2020 | Joomla! core 1.7.1 allows information disclosure due to weak encryption | ||
| CVE-2013-7484 | Hig | 0.49 | 7.5 | 0.01 | Nov 30, 2019 | Zabbix before 5.0 represents passwords in the users table with unsalted MD5. | ||
| CVE-2019-17598 | Hig | 0.49 | 7.5 | 0.01 | Nov 5, 2019 | An issue was discovered in Lightbend Play Framework 2.5.x through 2.6.23. When configured to make requests using an authenticated HTTP proxy, play-ws may sometimes, typically under high load, when connecting to a target host using https, expose the proxy credentials to the… | ||
| CVE-2013-4104 | Hig | 0.49 | 7.5 | 0.01 | Nov 4, 2019 | Cryptocat before 2.0.22 has weak encryption in the Socialist Millionnaire Protocol | ||
| CVE-2019-4339 | Hig | 0.49 | 7.5 | 0.01 | Oct 29, 2019 | IBM Security Guardium Big Data Intelligence (SonarG) 4.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 161418. | ||
| CVE-2019-4175 | Hig | 0.49 | 7.5 | 0.01 | Sep 17, 2019 | IBM Cognos Controller 10.3.0, 10.3.1, 10.4.0, and 10.4.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 158880. | ||
| CVE-2019-6972 | Hig | 0.49 | 7.5 | 0.01 | Jun 19, 2019 | An issue was discovered on TP-Link TL-WR1043ND V2 devices. The credentials can be easily decoded and cracked by brute-force, WordList, or Rainbow Table attacks. Specifically, credentials in the "Authorization" cookie are encoded with URL encoding and base64, leading to easy… | ||
| CVE-2019-4256 | Hig | 0.49 | 7.5 | 0.01 | May 29, 2019 | IBM API Connect 5.0.0.0 through 5.0.8.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 159944. | ||
| CVE-2019-10855 | Hig | 0.49 | 7.5 | 0.01 | May 23, 2019 | Computrols CBAS 18.0.0 mishandles password hashes. The approach is MD5 with a pw prefix, e.g., if the password is admin, it will calculate the MD5 hash of pwadmin and store it in a MySQL database. | ||
| CVE-2019-10112 | Hig | 0.49 | 7.5 | 0.01 | May 16, 2019 | An issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. The construction of the HMAC key was insecurely derived. | ||
| CVE-2013-7469 | Hig | 0.49 | 7.5 | 0.01 | Feb 21, 2019 | Seafile through 6.2.11 always uses the same Initialization Vector (IV) with Cipher Block Chaining (CBC) Mode to encrypt private data, making it easier to conduct chosen-plaintext attacks or dictionary attacks. | ||
| CVE-2019-7648 | Hig | 0.49 | 7.5 | 0.01 | Feb 8, 2019 | controller/fetchpwd.php and controller/doAction.php in Hotels_Server through 2018-11-05 rely on base64 in an attempt to protect password storage. | ||
| CVE-2018-1648 | Hig | 0.49 | 7.5 | 0.01 | Dec 5, 2018 | IBM QRadar SIEM 7.2 and 7.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 144653. | ||
| CVE-2018-19784 | Hig | 0.49 | 7.5 | 0.01 | Dec 1, 2018 | The str_rot_pass function in vendor/atholn1600/php-proxy/src/helpers.php in PHP-Proxy 5.1.0 uses weak cryptography, which makes it easier for attackers to calculate the authorization data needed for local file inclusion. | ||
| CVE-2018-1785 | Hig | 0.49 | 7.5 | 0.01 | Sep 26, 2018 | IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt sensitive information. IBM X-Force ID: 148870. | ||
| CVE-2018-1545 | Hig | 0.49 | 7.5 | 0.01 | Sep 26, 2018 | IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 142649. | ||
| CVE-2018-9028 | Hig | 0.49 | 7.5 | 0.01 | Jun 18, 2018 | Weak cryptography used for passwords in CA Privileged Access Manager 2.x reduces the complexity for password cracking. | ||
| CVE-2018-5184 | Hig | 0.49 | 7.5 | 0.02 | Jun 11, 2018 | Using remote content in encrypted messages can lead to the disclosure of plaintext. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8. | ||
| CVE-2017-1255 | Hig | 0.49 | 7.5 | 0.01 | May 2, 2018 | IBM Security Guardium 10.0, 10.0.1, and 10.1 through 10.1.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 124675. | ||
| CVE-2017-17543 | Hig | 0.49 | 7.5 | 0.00 | Apr 26, 2018 | Users' VPN authentication credentials are unsafely encrypted in Fortinet FortiClient for Windows 5.6.0 and below versions, FortiClient for Mac OSX 5.6.0 and below versions and FortiClient SSLVPN Client for Linux 4.4.2335 and below versions, due to the use of a static encryption… |
- risk 0.49cvss 7.5epss 0.01
Joomla! core 1.7.1 allows information disclosure due to weak encryption
- risk 0.49cvss 7.5epss 0.01
Zabbix before 5.0 represents passwords in the users table with unsalted MD5.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in Lightbend Play Framework 2.5.x through 2.6.23. When configured to make requests using an authenticated HTTP proxy, play-ws may sometimes, typically under high load, when connecting to a target host using https, expose the proxy credentials to the…
- risk 0.49cvss 7.5epss 0.01
Cryptocat before 2.0.22 has weak encryption in the Socialist Millionnaire Protocol
- risk 0.49cvss 7.5epss 0.01
IBM Security Guardium Big Data Intelligence (SonarG) 4.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 161418.
- risk 0.49cvss 7.5epss 0.01
IBM Cognos Controller 10.3.0, 10.3.1, 10.4.0, and 10.4.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 158880.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered on TP-Link TL-WR1043ND V2 devices. The credentials can be easily decoded and cracked by brute-force, WordList, or Rainbow Table attacks. Specifically, credentials in the "Authorization" cookie are encoded with URL encoding and base64, leading to easy…
- risk 0.49cvss 7.5epss 0.01
IBM API Connect 5.0.0.0 through 5.0.8.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 159944.
- risk 0.49cvss 7.5epss 0.01
Computrols CBAS 18.0.0 mishandles password hashes. The approach is MD5 with a pw prefix, e.g., if the password is admin, it will calculate the MD5 hash of pwadmin and store it in a MySQL database.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. The construction of the HMAC key was insecurely derived.
- risk 0.49cvss 7.5epss 0.01
Seafile through 6.2.11 always uses the same Initialization Vector (IV) with Cipher Block Chaining (CBC) Mode to encrypt private data, making it easier to conduct chosen-plaintext attacks or dictionary attacks.
- risk 0.49cvss 7.5epss 0.01
controller/fetchpwd.php and controller/doAction.php in Hotels_Server through 2018-11-05 rely on base64 in an attempt to protect password storage.
- risk 0.49cvss 7.5epss 0.01
IBM QRadar SIEM 7.2 and 7.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 144653.
- risk 0.49cvss 7.5epss 0.01
The str_rot_pass function in vendor/atholn1600/php-proxy/src/helpers.php in PHP-Proxy 5.1.0 uses weak cryptography, which makes it easier for attackers to calculate the authorization data needed for local file inclusion.
- risk 0.49cvss 7.5epss 0.01
IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt sensitive information. IBM X-Force ID: 148870.
- risk 0.49cvss 7.5epss 0.01
IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 142649.
- risk 0.49cvss 7.5epss 0.01
Weak cryptography used for passwords in CA Privileged Access Manager 2.x reduces the complexity for password cracking.
- risk 0.49cvss 7.5epss 0.02
Using remote content in encrypted messages can lead to the disclosure of plaintext. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
- risk 0.49cvss 7.5epss 0.01
IBM Security Guardium 10.0, 10.0.1, and 10.1 through 10.1.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 124675.
- risk 0.49cvss 7.5epss 0.00
Users' VPN authentication credentials are unsafely encrypted in Fortinet FortiClient for Windows 5.6.0 and below versions, FortiClient for Mac OSX 5.6.0 and below versions and FortiClient SSLVPN Client for Linux 4.4.2335 and below versions, due to the use of a static encryption…