VYPR

CWE-327

Use of a Broken or Risky Cryptographic Algorithm

ClassDraftLikelihood: High

Description

The product uses a broken or risky cryptographic algorithm or protocol.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-20 · CAPEC-459 · CAPEC-473 · CAPEC-475 · CAPEC-608 · CAPEC-614 · CAPEC-97

CVEs mapped to this weakness (713)

page 10 of 36
  • CVE-2021-31796HigSep 2, 2021
    risk 0.49cvss 7.5epss 0.02

    An inadequate encryption vulnerability discovered in CyberArk Credential Provider before 12.1 may lead to Information Disclosure. An attacker may realistically have enough information that the number of possible keys (for a credential file) is only one, and the number is usually…

  • CVE-2021-29723HigAug 30, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-ForceID: 201100.

  • CVE-2021-29722HigAug 30, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 201095.

  • CVE-2021-29704HigAug 23, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Security SOAR uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

  • CVE-2021-20337HigJul 26, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM QRadar SIEM 7.3.0 to 7.3.3 Patch 8 and 7.4.0 to 7.4.3 GA uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 194448.

  • CVE-2021-20497HigJul 15, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Security Verify Access Docker 10.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 197969

  • CVE-2021-29794HigJul 12, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Tivoli Netcool/Impact 7.1.0.20 and 7.1.0.21 uses an insecure SSH server configuration which enables weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 203556.

  • CVE-2021-20379HigJul 7, 2021
    risk 0.49cvss 7.5epss 0.00

    IBM Guardium Data Encryption (GDE) 3.0.0.3 and 4.0.0.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 195711.

  • CVE-2021-20566HigJun 16, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Resilient SOAR V38.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 199238.

  • CVE-2020-26515HigJun 8, 2021
    risk 0.49cvss 7.5epss 0.01

    An insufficiently protected credentials issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. The remember-me cookie (CB_LOGIN) issued by the application contains the encrypted user's credentials. However, due to a bug in the application code, those credentials…

  • CVE-2021-20419HigMay 24, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Security Guardium 11.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 196280.

  • CVE-2021-27457HigMay 20, 2021
    risk 0.49cvss 7.5epss 0.00

    A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected products utilize a weak encryption algorithm for storage of sensitive data, which may allow an attacker to more easily obtain credentials used for access.

  • CVE-2021-29694HigApr 26, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Spectrum Protect Plus 10.1.0 through 10.1.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 200258.

  • CVE-2020-4965HigApr 12, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Jazz Team Server products use weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 192422.

  • CVE-2019-14852HigMar 18, 2021
    risk 0.49cvss 7.5epss 0.00

    A flaw was found in 3scale’s APIcast gateway that enabled the TLS 1.0 protocol. An attacker could target traffic using this weaker protocol and break its encryption, gaining access to unauthorized information. Version shipped in Red Hat 3scale API Management Platform is…

  • CVE-2020-4831HigMar 12, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM DataPower Gateway 10.0.0.0 through 10.0.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 189965.

  • CVE-2020-25493HigFeb 11, 2021
    risk 0.49cvss 7.5epss 0.01

    Oclean Mobile Application 2.1.2 communicates with an external website using HTTP so it is possible to eavesdrop the network traffic. The content of HTTP payload is encrypted using XOR with a hardcoded key, which allows for the possibility to decode the traffic.

  • CVE-2020-14246HigFeb 4, 2021
    risk 0.49cvss 7.5epss 0.01

    HCL OneTest Performance V9.5, V10.0, V10.1 uses basic authentication which is relatively weak. An attacker could potentially decode the encoded credentials.

  • CVE-2020-36201HigJan 26, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in certain Xerox WorkCentre products. They do not properly encrypt passwords. This affects 3655, 3655i, 58XX, 58XXi 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices.

  • CVE-2020-23162HigJan 26, 2021
    risk 0.49cvss 7.5epss 0.01

    Sensitive information disclosure and weak encryption in Pyrescom Termod4 time management devices before 10.04k allows remote attackers to read a session-file and obtain plain-text user credentials.