VYPR

CWE-327

Use of a Broken or Risky Cryptographic Algorithm

ClassDraftLikelihood: High

Description

The product uses a broken or risky cryptographic algorithm or protocol.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-20 · CAPEC-459 · CAPEC-473 · CAPEC-475 · CAPEC-608 · CAPEC-614 · CAPEC-97

CVEs mapped to this weakness (713)

page 17 of 36
  • CVE-2024-30152MedApr 25, 2025
    risk 0.42cvss 6.5epss 0.00

    HCL SX v21 is affected by usage of a weak cryptographic algorithm. An attacker could exploit this weakness to gain access to sensitive information, modify data, or other impacts.

  • CVE-2025-27508HigMar 5, 2025
    risk 0.42cvss 7.5epss 0.00

    Emissary is a P2P based data-driven workflow engine. The ChecksumCalculator class within allows for hashing and checksum generation, but it includes or defaults to algorithms that are no longer recommended for secure cryptographic use cases (e.g., SHA-1, CRC32, and SSDEEP).…

  • CVE-2024-28980MedDec 13, 2024
    risk 0.42cvss 6.5epss 0.01

    Dell RecoverPoint for VMs, version(s) 6.0.x contain(s) a Use of a Broken or Risky Cryptographic Algorithm vulnerability in the SSH. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.

  • CVE-2024-55885HigDec 12, 2024
    risk 0.42cvss 7.5epss 0.00

    beego is an open-source web framework for the Go programming language. Versions of beego prior to 2.3.4 use MD5 as a hashing algorithm. MD5 is no longer considered secure against well-funded opponents due to its vulnerability to collision attacks. Version 2.3.4 replaces MD5 with…

  • CVE-2022-43934MedNov 21, 2024
    risk 0.42cvss 6.5epss 0.00

    Brocade SANnav before Brocade SANnav 2.2.2 supports key exchange algorithms, which are considered weak on ports 24, 6514, 18023, 19094, and 19095.

  • CVE-2024-51556MedNov 4, 2024
    risk 0.42cvss 6.5epss 0.00

    This vulnerability exists in the Wave 2.0 due to insufficient encryption of sensitive data received at the API response. An authenticated remote attacker could exploit this vulnerability by manipulating API input parameters through API request URL/payload leading to unauthorized…

  • CVE-2024-33663MedApr 26, 2024
    risk 0.42cvss 6.5epss 0.00

    python-jose through 3.3.0 has algorithm confusion with OpenSSH ECDSA keys and other key formats. This is similar to CVE-2022-29217.

  • CVE-2024-21670MedJan 16, 2024
    risk 0.42cvss 6.5epss 0.00

    Ursa is a cryptographic library for use with blockchains. The revocation schema that is part of the Ursa CL-Signatures implementations has a flaw that could impact the privacy guarantees defined by the AnonCreds verifiable credential model, allowing a malicious holder of a…

  • CVE-2023-5962MedDec 23, 2023
    risk 0.42cvss 6.5epss 0.00

    A weak cryptographic algorithm vulnerability has been identified in ioLogik E1200 Series firmware versions v3.3 and prior. This vulnerability can help an attacker compromise the confidentiality of sensitive data. This vulnerability may lead an attacker to get unexpected…

  • CVE-2021-27795MedDec 6, 2023
    risk 0.42cvss 6.4epss 0.00

    Brocade Fabric OS (FOS) hardware platforms running any version of Brocade Fabric OS software, which supports the license string format; contain cryptographic issues that could allow for the installation of forged or fraudulent license keys. This would allow attackers or a…

  • CVE-2023-26024MedDec 1, 2023
    risk 0.42cvss 6.5epss 0.00

    IBM Planning Analytics on Cloud Pak for Data 4.0 could allow an attacker on a shared network to obtain sensitive information caused by insecure network communication. IBM X-Force ID: 247898.

  • CVE-2023-47640MedNov 14, 2023
    risk 0.42cvss 6.4epss 0.00

    DataHub is an open-source metadata platform. The HMAC signature for DataHub Frontend sessions was being signed using a SHA-1 HMAC with the frontend secret key. SHA1 with a 10 byte key can be brute forced using sufficient resources (i.e. state level actors with large…

  • CVE-2023-46324HigOct 23, 2023
    risk 0.42cvss 7.5epss 0.00

    pkg/suci/suci.go in free5GC udm before 1.2.0, when Go before 1.19 is used, allows an Invalid Curve Attack because it may compute a shared secret via an uncompressed public key that has not been validated. An attacker can send arbitrary SUCIs to the UDM, which tries to decrypt…

  • CVE-2023-23347MedAug 9, 2023
    risk 0.42cvss 6.4epss 0.00

    HCL DRYiCE iAutomate is affected by the use of a broken cryptographic algorithm. An attacker can potentially compromise the confidentiality and integrity of sensitive information.

  • CVE-2023-23346MedAug 9, 2023
    risk 0.42cvss 6.4epss 0.00

    HCL DRYiCE MyCloud is affected by the use of a broken cryptographic algorithm. An attacker can potentially compromise the confidentiality and integrity of sensitive information.

  • CVE-2023-36608MedJul 3, 2023
    risk 0.42cvss 6.5epss 0.00

    The affected TBox RTUs store hashed passwords using MD5 encryption, which is an insecure encryption algorithm.

  • CVE-2023-28043MedJun 1, 2023
    risk 0.42cvss 6.5epss 0.00

    Dell SCG 5.14 contains an information disclosure vulnerability during the SRS to SCG upgrade path. A remote low privileged malicious user could potentially exploit this vulnerability to retrieve the plain text.

  • CVE-2022-45170MedApr 14, 2023
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Cryptographic Issue can occur under the /api/v1/vencrypt/decrypt/file endpoint. A malicious user, logged into a victim's account, is able to decipher a file without knowing the key set by the user.

  • CVE-2022-46834MedDec 13, 2022
    risk 0.42cvss 6.5epss 0.00

    Use of a Broken or Risky Cryptographic Algorithm in SICK RFU65x firmware version < v2.21 allows a low-privileged remote attacker to decrypt the encrypted data if the user requested weak cipher suites to be used for encryption via the SSH interface. The patch and installation…

  • CVE-2022-46833MedDec 13, 2022
    risk 0.42cvss 6.5epss 0.00

    Use of a Broken or Risky Cryptographic Algorithm in SICK RFU63x firmware version < v2.21 allows a low-privileged remote attacker to decrypt the encrypted data if the user requested weak cipher suites to be used for encryption via the SSH interface. The patch and installation…