VYPR

CWE-326

Inadequate Encryption Strength

ClassDraft

Description

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

A weak encryption scheme can be subjected to brute force attacks that have a reasonable chance of succeeding using current attack methods and resources.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-112 · CAPEC-192 · CAPEC-20

CVEs mapped to this weakness (471)

page 9 of 24
  • CVE-2011-3629HigFeb 4, 2020
    risk 0.49cvss 7.5epss 0.01

    Joomla! core 1.7.1 allows information disclosure due to weak encryption

  • CVE-2013-7484HigNov 30, 2019
    risk 0.49cvss 7.5epss 0.01

    Zabbix before 5.0 represents passwords in the users table with unsalted MD5.

  • CVE-2019-17598HigNov 5, 2019
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Lightbend Play Framework 2.5.x through 2.6.23. When configured to make requests using an authenticated HTTP proxy, play-ws may sometimes, typically under high load, when connecting to a target host using https, expose the proxy credentials to the…

  • CVE-2013-4104HigNov 4, 2019
    risk 0.49cvss 7.5epss 0.01

    Cryptocat before 2.0.22 has weak encryption in the Socialist Millionnaire Protocol

  • CVE-2019-4339HigOct 29, 2019
    risk 0.49cvss 7.5epss 0.01

    IBM Security Guardium Big Data Intelligence (SonarG) 4.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 161418.

  • CVE-2019-4175HigSep 17, 2019
    risk 0.49cvss 7.5epss 0.01

    IBM Cognos Controller 10.3.0, 10.3.1, 10.4.0, and 10.4.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 158880.

  • CVE-2019-6972HigJun 19, 2019
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered on TP-Link TL-WR1043ND V2 devices. The credentials can be easily decoded and cracked by brute-force, WordList, or Rainbow Table attacks. Specifically, credentials in the "Authorization" cookie are encoded with URL encoding and base64, leading to easy…

  • CVE-2019-4256HigMay 29, 2019
    risk 0.49cvss 7.5epss 0.01

    IBM API Connect 5.0.0.0 through 5.0.8.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 159944.

  • CVE-2019-10855HigMay 23, 2019
    risk 0.49cvss 7.5epss 0.01

    Computrols CBAS 18.0.0 mishandles password hashes. The approach is MD5 with a pw prefix, e.g., if the password is admin, it will calculate the MD5 hash of pwadmin and store it in a MySQL database.

  • CVE-2019-10112HigMay 16, 2019
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. The construction of the HMAC key was insecurely derived.

  • CVE-2013-7469HigFeb 21, 2019
    risk 0.49cvss 7.5epss 0.01

    Seafile through 6.2.11 always uses the same Initialization Vector (IV) with Cipher Block Chaining (CBC) Mode to encrypt private data, making it easier to conduct chosen-plaintext attacks or dictionary attacks.

  • CVE-2019-7648HigFeb 8, 2019
    risk 0.49cvss 7.5epss 0.01

    controller/fetchpwd.php and controller/doAction.php in Hotels_Server through 2018-11-05 rely on base64 in an attempt to protect password storage.

  • CVE-2018-1648HigDec 5, 2018
    risk 0.49cvss 7.5epss 0.01

    IBM QRadar SIEM 7.2 and 7.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 144653.

  • CVE-2018-19784HigDec 1, 2018
    risk 0.49cvss 7.5epss 0.01

    The str_rot_pass function in vendor/atholn1600/php-proxy/src/helpers.php in PHP-Proxy 5.1.0 uses weak cryptography, which makes it easier for attackers to calculate the authorization data needed for local file inclusion.

  • CVE-2018-1785HigSep 26, 2018
    risk 0.49cvss 7.5epss 0.01

    IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt sensitive information. IBM X-Force ID: 148870.

  • CVE-2018-1545HigSep 26, 2018
    risk 0.49cvss 7.5epss 0.01

    IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 142649.

  • CVE-2018-9028HigJun 18, 2018
    risk 0.49cvss 7.5epss 0.01

    Weak cryptography used for passwords in CA Privileged Access Manager 2.x reduces the complexity for password cracking.

  • CVE-2018-5184HigJun 11, 2018
    risk 0.49cvss 7.5epss 0.02

    Using remote content in encrypted messages can lead to the disclosure of plaintext. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.

  • CVE-2017-1255HigMay 2, 2018
    risk 0.49cvss 7.5epss 0.01

    IBM Security Guardium 10.0, 10.0.1, and 10.1 through 10.1.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 124675.

  • CVE-2017-17543HigApr 26, 2018
    risk 0.49cvss 7.5epss 0.00

    Users' VPN authentication credentials are unsafely encrypted in Fortinet FortiClient for Windows 5.6.0 and below versions, FortiClient for Mac OSX 5.6.0 and below versions and FortiClient SSLVPN Client for Linux 4.4.2335 and below versions, due to the use of a static encryption…