VYPR

CWE-327

Use of a Broken or Risky Cryptographic Algorithm

ClassDraftLikelihood: High

Description

The product uses a broken or risky cryptographic algorithm or protocol.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-20 · CAPEC-459 · CAPEC-473 · CAPEC-475 · CAPEC-608 · CAPEC-614 · CAPEC-97

CVEs mapped to this weakness (713)

page 27 of 36
  • CVE-2020-1596MedSep 11, 2020
    risk 0.35cvss 5.4epss 0.01

    A information disclosure vulnerability exists when TLS components use weak hash algorithms. An attacker who successfully exploited this vulnerability could obtain information to further compromise a users's encrypted transmission channel. To exploit the vulnerability,…

  • CVE-2019-5135MedMar 11, 2020
    risk 0.35cvss 5.3epss 0.01

    An exploitable timing discrepancy vulnerability exists in the authentication functionality of the Web-Based Management (WBM) web application on WAGO PFC100/200 controllers. The WBM application makes use of the PHP crypt() function which can be exploited to disclose hashed user…

  • CVE-2019-9836MedJun 25, 2019
    risk 0.35cvss 5.3epss 0.02

    Secure Encrypted Virtualization (SEV) on Advanced Micro Devices (AMD) Platform Security Processor (PSP; aka AMD Secure Processor or AMD-SP) 0.17 build 11 and earlier has an insecure cryptographic implementation.

  • CVE-2018-1996MedFeb 19, 2019
    risk 0.35cvss 5.3epss 0.01

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could provide weaker than expected security, caused by the improper TLS configuration. A remote attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID:…

  • CVE-2026-20996MedMar 16, 2026
    risk 0.34cvss 5.3epss 0.00

    Use of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.69.15 allows remote attackers to configure a downgraded scheme for authentication.

  • CVE-2025-41711MedMar 10, 2026
    risk 0.34cvss 5.3epss 0.00

    An unauthenticated remote attacker can use firmware images to extract password hashes and brute force plaintext passwords of accounts with limited access.

  • CVE-2025-43913MedOct 7, 2025
    risk 0.34cvss 5.3epss 0.00

    Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2025 release version 8.3.1.0, LTS2024 release versions 7.13.1.0 through 7.13.1.30, LTS 2023 release versions 7.10.1.0 through 7.10.1.60, contain an…

  • CVE-2025-43891MedOct 7, 2025
    risk 0.34cvss 5.3epss 0.00

    Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2025 release version 8.3.1.0, LTS2024 release versions 7.13.1.0 through 7.13.1.30, LTS 2023 release versions 7.10.1.0 through 7.10.1.60, contain an…

  • CVE-2024-49784MedJul 8, 2025
    risk 0.34cvss 5.3epss 0.00

    IBM OpenPages with Watson 8.3 and 9.0 could provide weaker than expected security in storage of encrypted data with AES encryption and CBC mode. If an authenticated remote attacker with access to the database or a local attacker with access to server files could extract the…

  • CVE-2024-10405MedFeb 15, 2025
    risk 0.34cvss 5.3epss 0.00

    Brocade SANnav before SANnav 2.3.1b enables weak TLS ciphers on ports 443 and 18082. In case of a successful exploit, an attacker can read Brocade SANnav data stream that includes monitored Brocade Fabric OS switches performance data, port status, zoning information, WWNs,…

  • CVE-2023-41928MedJul 2, 2024
    risk 0.34cvss 5.3epss 0.00

    The device is observed to accept deprecated TLS protocols, increasing the risk of cryptographic weaknesses.

  • CVE-2023-41927MedJul 2, 2024
    risk 0.34cvss 5.3epss 0.00

    The server supports at least one cipher suite which is on the NCSC-NL list of cipher suites to be phased out, increasing the risk of cryptographic weaknesses.

  • CVE-2024-3264MedJun 24, 2024
    risk 0.34cvss 5.3epss 0.00

    Use of a Broken or Risky Cryptographic Algorithm vulnerability in Mia Technology Inc. Mia-Med Health Aplication allows Signature Spoofing by Improper Validation. This issue affects Mia-Med Health Aplication: before 1.0.14.

  • CVE-2023-50313MedApr 2, 2024
    risk 0.34cvss 5.3epss 0.00

    IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security for outbound TLS connections caused by a failure to honor user configuration. IBM X-Force ID: 274812.

  • CVE-2023-50312MedMar 1, 2024
    risk 0.34cvss 5.3epss 0.01

    IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.2 could provide weaker than expected security for outbound TLS connections caused by a failure to honor user configuration. IBM X-Force ID: 274711.

  • CVE-2023-28053MedDec 18, 2023
    risk 0.34cvss 5.3epss 0.00

    Dell NetWorker Virtual Edition versions 19.8 and below contain the use of deprecated cryptographic algorithms in the SSH component. A remote unauthenticated attacker could potentially exploit this vulnerability leading to some information disclosure.

  • CVE-2023-37484MedAug 8, 2023
    risk 0.34cvss 5.3epss 0.02

    SAP PowerDesigner - version 16.7, queries all password hashes in the backend database and compares it with the user provided one during login attempt, which might allow an attacker to access password hashes from the client's memory.

  • CVE-2023-0296MedJan 17, 2023
    risk 0.34cvss 5.3epss 0.00

    The Birthday attack against 64-bit block ciphers flaw (CVE-2016-2183) was reported for the health checks port (9979) on etcd grpc-proxy component. Even though the CVE-2016-2183 has been fixed in the etcd components, to enable periodic health checks from kubelet, it was necessary…

  • CVE-2022-39237MedOct 6, 2022
    risk 0.34cvss 6.3epss 0.01

    syslabs/sif is the Singularity Image Format (SIF) reference implementation. In versions prior to 2.8.1the `github.com/sylabs/sif/v2/pkg/integrity` package did not verify that the hash algorithm(s) used are cryptographically secure when verifying digital signatures. A patch is…

  • CVE-2022-2781MedOct 6, 2022
    risk 0.34cvss 5.3epss 0.00

    In affected versions of Octopus Server it was identified that the same encryption process was used for both encrypting session cookies and variables.