VYPR

CWE-327

Use of a Broken or Risky Cryptographic Algorithm

ClassDraftLikelihood: High

Description

The product uses a broken or risky cryptographic algorithm or protocol.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-20 · CAPEC-459 · CAPEC-473 · CAPEC-475 · CAPEC-608 · CAPEC-614 · CAPEC-97

CVEs mapped to this weakness (713)

page 12 of 36
  • CVE-2020-13757HigJun 1, 2020
    risk 0.49cvss 7.5epss 0.01

    Python-RSA before 4.1 ignores leading '\0' bytes during decryption of ciphertext. This could conceivably have a security-relevant impact, e.g., by helping an attacker to infer that an application uses Python-RSA, or if the length of accepted ciphertext affects application…

  • CVE-2020-4379HigMay 27, 2020
    risk 0.49cvss 7.5epss 0.01

    IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 179158.

  • CVE-2020-4350HigMay 27, 2020
    risk 0.49cvss 7.5epss 0.01

    IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 178424.

  • CVE-2020-4349HigMay 27, 2020
    risk 0.49cvss 7.5epss 0.01

    IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 178423.

  • CVE-2020-11035HigMay 5, 2020
    risk 0.49cvss 7.5epss 0.01

    In GLPI after version 0.83.3 and before version 9.4.6, the CSRF tokens are generated using an insecure algorithm. The implementation uses rand and uniqid and MD5 which does not provide secure values. This is fixed in version 9.4.6.

  • CVE-2020-11876HigApr 17, 2020
    risk 0.49cvss 7.5epss 0.02

    airhost.exe in Zoom Client for Meetings 4.6.11 uses the SHA-256 hash of 0123425234234fsdfsdr3242 for initialization of an OpenSSL EVP AES-256 CBC context. NOTE: the vendor states that this initialization only occurs within unreachable code

  • CVE-2020-11872HigApr 17, 2020
    risk 0.49cvss 7.5epss 0.01

    The Cloud Functions subsystem in OpenTrace 1.0 might allow fabrication attacks by making billions of TempID requests before an AES-256-GCM key rotation occurs.

  • CVE-2018-6402HigApr 14, 2020
    risk 0.49cvss 7.5epss 0.00

    Ecobee Ecobee4 4.2.0.171 devices can be forced to deauthenticate and connect to an unencrypted Wi-Fi network with the same SSID, even if the device settings specify use of encryption such as WPA2, as long as the competing network has a stronger signal. An attacker must be able…

  • CVE-2020-11500HigApr 3, 2020
    risk 0.49cvss 7.5epss 0.01

    Zoom Client for Meetings through 4.6.9 uses the ECB mode of AES for video and audio encryption. Within a meeting, all participants use a single 128-bit key.

  • CVE-2020-7001HigMar 24, 2020
    risk 0.49cvss 7.5epss 0.01

    In Moxa EDS-G516E Series firmware, Version 5.2 or lower, the affected products use a weak cryptographic algorithm, which may allow confidential information to be disclosed.

  • CVE-2020-6987HigMar 24, 2020
    risk 0.49cvss 7.5epss 0.01

    In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or lower, the affected products use a weak cryptographic algorithm, which may allow confidential information to be disclosed.

  • CVE-2019-4553HigMar 24, 2020
    risk 0.49cvss 7.5epss 0.01

    IBM API Connect V5.0.0.0 through 5.0.8.7iFix3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 165958.

  • CVE-2019-15653HigMar 19, 2020
    risk 0.49cvss 7.5epss 0.01

    Comba AP2600-I devices through A02,0202N00PD2 are prone to password disclosure via an insecure authentication mechanism. The HTML source code of the login page contains values that allow obtaining the username and password. The username are password values are a double md5 of…

  • CVE-2020-6984HigMar 16, 2020
    risk 0.49cvss 7.5epss 0.03

    Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix 500 Software v12.001 and prior, The cryptographic function utilized to protect the password in MicroLogix is discoverable.

  • CVE-2012-5623HigFeb 13, 2020
    risk 0.49cvss 7.5epss 0.01

    Squirrelmail 4.0 uses the outdated MD5 hash algorithm for passwords.

  • CVE-2019-4427HigFeb 12, 2020
    risk 0.49cvss 7.5epss 0.00

    IBM Cloud CLI 0.6.0 through 0.16.1 windows installers are signed using SHA1 certificate. An attacker might be able to exploit the weak algorithm to generate a installer with malicious software inside. IBM X-Force ID: 162773.

  • CVE-2019-4540HigFeb 4, 2020
    risk 0.49cvss 7.5epss 0.01

    IBM Security Directory Server 6.4.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 165813.

  • CVE-2019-4639HigJan 28, 2020
    risk 0.49cvss 7.5epss 0.01

    IBM Security Secret Server 10.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 170045.

  • CVE-2019-4609HigDec 18, 2019
    risk 0.49cvss 7.5epss 0.01

    IBM API Connect 2018.4.1.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 168510.

  • CVE-2019-16208HigNov 8, 2019
    risk 0.49cvss 7.5epss 0.00

    Password-based encryption (PBE) algorithm, of Brocade SANnav versions before v2.0, has a weakness in generating cryptographic keys that may allow an attacker to decrypt passwords used with several services (Radius, TACAS, etc.).