VYPR

CWE-327

Use of a Broken or Risky Cryptographic Algorithm

ClassDraftLikelihood: High

Description

The product uses a broken or risky cryptographic algorithm or protocol.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-20 · CAPEC-459 · CAPEC-473 · CAPEC-475 · CAPEC-608 · CAPEC-614 · CAPEC-97

CVEs mapped to this weakness (713)

page 28 of 36
  • CVE-2021-37546MedAug 6, 2021
    risk 0.34cvss 5.3epss 0.01

    In JetBrains TeamCity before 2021.1, an insecure key generation mechanism for encrypted properties was used.

  • CVE-2021-34687MedJul 15, 2021
    risk 0.34cvss 5.3epss 0.00

    iDrive RemotePC before 7.6.48 on Windows allows information disclosure. A man in the middle can recover a system's Personal Key when a client attempts to make a LAN connection. The Personal Key is transmitted over the network while only being encrypted via a substitution cipher.

  • CVE-2021-25763MedFeb 3, 2021
    risk 0.34cvss 5.3epss 0.01

    In JetBrains Ktor before 1.4.2, weak cipher suites were enabled by default.

  • CVE-2019-4325MedOct 6, 2020
    risk 0.34cvss 5.3epss 0.01

    "HCL AppScan Enterprise makes use of broken or risky cryptographic algorithm to store REST API user details."

  • CVE-2020-1810MedJan 9, 2020
    risk 0.34cvss 5.3epss 0.00

    There is a weak algorithm vulnerability in some Huawei products. The affected products use the RSA algorithm in the SSL key exchange algorithm which have been considered as a weak algorithm. Attackers may exploit this vulnerability to leak some information.

  • CVE-2018-18587MedOct 23, 2018
    risk 0.34cvss 5.3epss 0.01

    BigProf AppGini 5.70 stores the passwords in the database using the MD5 hash.

  • CVE-2017-14937MedOct 20, 2017
    risk 0.34cvss 4.7epss 0.01

    The airbag detonation algorithm allows injury to passenger-car occupants via predictable Security Access (SA) data to the internal CAN bus (or the OBD connector). This affects the airbag control units (aka pyrotechnical control units or PCUs) of unspecified passenger vehicles…

  • CVE-2025-14480MedMar 3, 2026
    risk 0.33cvss 5.1epss 0.00

    IBM Aspera faspio Gateway 1.3.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information

  • CVE-2024-20070MedJun 3, 2024
    risk 0.33cvss 5.1epss 0.00

    In modem, there is a possible information disclosure due to using risky cryptographic algorithm during connection establishment negotiation. This could lead to remote information disclosure, when weak encryption algorithm is used, with no additional execution privileges needed.…

  • CVE-2023-35890MedJul 7, 2023
    risk 0.33cvss 5.1epss 0.00

    IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security, caused by the improper encoding in a local configuration file. IBM X-Force ID: 258637.

  • CVE-2022-38391MedDec 20, 2022
    risk 0.33cvss 5.1epss 0.00

    IBM Spectrum Control 5.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 233982.

  • CVE-2020-15128MedJul 31, 2020
    risk 0.33cvss 6.1epss 0.01

    In OctoberCMS before version 1.0.468, encrypted cookie values were not tied to the name of the cookie the value belonged to. This meant that certain classes of attacks that took advantage of other theoretical vulnerabilities in user facing code (nothing exploitable in the core…

  • CVE-2020-11005MedApr 14, 2020
    risk 0.33cvss 5.1epss 0.00

    The WindowsHello open source library (NuGet HaemmerElectronics.SeppPenner.WindowsHello), before version 1.0.4, has a vulnerability where encrypted data could potentially be decrypted without needing authentication. If the library is used to encrypt text and write the output to a…

  • CVE-2017-1575MedJul 20, 2018
    risk 0.33cvss 5.1epss 0.00

    IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway 2.2.0 through 2.2.6) uses weaker than expected cryptographic algorithms that could allow a local attacker to decrypt highly sensitive information. IBM X-Force ID: 132032.

  • CVE-2017-1571MedMar 22, 2018
    risk 0.33cvss 5.1epss 0.00

    IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 131853.

  • CVE-2021-43774MedMar 3, 2022
    risk 0.32cvss 4.9epss 0.01

    A risky-algorithm issue was discovered on Fujifilm DocuCentre-VI C4471 1.8 devices. An attacker that obtained access to the administrative web interface of a printer (e.g., by using the default credentials) can download the address book file, which contains the list of users…

  • CVE-2018-5745MedOct 9, 2019
    risk 0.32cvss 4.9epss 0.02

    "managed-keys" is a feature which allows a BIND resolver to automatically maintain the keys used by trust anchors which operators configure for use in DNSSEC validation. Due to an error in the managed-keys feature it is possible for a BIND server which uses managed-keys to exit…

  • CVE-2018-10845MedAug 22, 2018
    risk 0.32cvss 5.9epss 0.04

    It was found that the GnuTLS implementation of HMAC-SHA-384 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to conduct distinguishing attacks and plain text recovery attacks via statistical analysis of timing data using crafted packets.

  • CVE-2018-10844MedAug 22, 2018
    risk 0.32cvss 5.9epss 0.04

    It was found that the GnuTLS implementation of HMAC-SHA-256 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data using crafted packets.

  • CVE-2026-56609MedAug 3, 2026
    risk 0.31cvss 4.8epss 0.00

    HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. It was observed that the application was using weak TLS versions such as TLS 1.0 and 1.1. These outdated protocols lack modern security features, making them vulnerable to known attacks and exposing…