CWE-327
Use of a Broken or Risky Cryptographic Algorithm
Description
The product uses a broken or risky cryptographic algorithm or protocol.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-20 · CAPEC-459 · CAPEC-473 · CAPEC-475 · CAPEC-608 · CAPEC-614 · CAPEC-97
CVEs mapped to this weakness (713)
page 28 of 36| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-37546 | Med | 0.34 | 5.3 | 0.01 | Aug 6, 2021 | In JetBrains TeamCity before 2021.1, an insecure key generation mechanism for encrypted properties was used. | ||
| CVE-2021-34687 | Med | 0.34 | 5.3 | 0.00 | Jul 15, 2021 | iDrive RemotePC before 7.6.48 on Windows allows information disclosure. A man in the middle can recover a system's Personal Key when a client attempts to make a LAN connection. The Personal Key is transmitted over the network while only being encrypted via a substitution cipher. | ||
| CVE-2021-25763 | Med | 0.34 | 5.3 | 0.01 | Feb 3, 2021 | In JetBrains Ktor before 1.4.2, weak cipher suites were enabled by default. | ||
| CVE-2019-4325 | Med | 0.34 | 5.3 | 0.01 | Oct 6, 2020 | "HCL AppScan Enterprise makes use of broken or risky cryptographic algorithm to store REST API user details." | ||
| CVE-2020-1810 | Med | 0.34 | 5.3 | 0.00 | Jan 9, 2020 | There is a weak algorithm vulnerability in some Huawei products. The affected products use the RSA algorithm in the SSL key exchange algorithm which have been considered as a weak algorithm. Attackers may exploit this vulnerability to leak some information. | ||
| CVE-2018-18587 | Med | 0.34 | 5.3 | 0.01 | Oct 23, 2018 | BigProf AppGini 5.70 stores the passwords in the database using the MD5 hash. | ||
| CVE-2017-14937 | Med | 0.34 | 4.7 | 0.01 | Oct 20, 2017 | The airbag detonation algorithm allows injury to passenger-car occupants via predictable Security Access (SA) data to the internal CAN bus (or the OBD connector). This affects the airbag control units (aka pyrotechnical control units or PCUs) of unspecified passenger vehicles… | ||
| CVE-2025-14480 | Med | 0.33 | 5.1 | 0.00 | Mar 3, 2026 | IBM Aspera faspio Gateway 1.3.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information | ||
| CVE-2024-20070 | Med | 0.33 | 5.1 | 0.00 | Jun 3, 2024 | In modem, there is a possible information disclosure due to using risky cryptographic algorithm during connection establishment negotiation. This could lead to remote information disclosure, when weak encryption algorithm is used, with no additional execution privileges needed.… | ||
| CVE-2023-35890 | Med | 0.33 | 5.1 | 0.00 | Jul 7, 2023 | IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security, caused by the improper encoding in a local configuration file. IBM X-Force ID: 258637. | ||
| CVE-2022-38391 | Med | 0.33 | 5.1 | 0.00 | Dec 20, 2022 | IBM Spectrum Control 5.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 233982. | ||
| CVE-2020-15128 | Med | 0.33 | 6.1 | 0.01 | Jul 31, 2020 | In OctoberCMS before version 1.0.468, encrypted cookie values were not tied to the name of the cookie the value belonged to. This meant that certain classes of attacks that took advantage of other theoretical vulnerabilities in user facing code (nothing exploitable in the core… | ||
| CVE-2020-11005 | Med | 0.33 | 5.1 | 0.00 | Apr 14, 2020 | The WindowsHello open source library (NuGet HaemmerElectronics.SeppPenner.WindowsHello), before version 1.0.4, has a vulnerability where encrypted data could potentially be decrypted without needing authentication. If the library is used to encrypt text and write the output to a… | ||
| CVE-2017-1575 | Med | 0.33 | 5.1 | 0.00 | Jul 20, 2018 | IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway 2.2.0 through 2.2.6) uses weaker than expected cryptographic algorithms that could allow a local attacker to decrypt highly sensitive information. IBM X-Force ID: 132032. | ||
| CVE-2017-1571 | Med | 0.33 | 5.1 | 0.00 | Mar 22, 2018 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 131853. | ||
| CVE-2021-43774 | Med | 0.32 | 4.9 | 0.01 | Mar 3, 2022 | A risky-algorithm issue was discovered on Fujifilm DocuCentre-VI C4471 1.8 devices. An attacker that obtained access to the administrative web interface of a printer (e.g., by using the default credentials) can download the address book file, which contains the list of users… | ||
| CVE-2018-5745 | Med | 0.32 | 4.9 | 0.02 | Oct 9, 2019 | "managed-keys" is a feature which allows a BIND resolver to automatically maintain the keys used by trust anchors which operators configure for use in DNSSEC validation. Due to an error in the managed-keys feature it is possible for a BIND server which uses managed-keys to exit… | ||
| CVE-2018-10845 | Med | 0.32 | 5.9 | 0.04 | Aug 22, 2018 | It was found that the GnuTLS implementation of HMAC-SHA-384 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to conduct distinguishing attacks and plain text recovery attacks via statistical analysis of timing data using crafted packets. | ||
| CVE-2018-10844 | Med | 0.32 | 5.9 | 0.04 | Aug 22, 2018 | It was found that the GnuTLS implementation of HMAC-SHA-256 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data using crafted packets. | ||
| CVE-2026-56609 | Med | 0.31 | 4.8 | 0.00 | Aug 3, 2026 | HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. It was observed that the application was using weak TLS versions such as TLS 1.0 and 1.1. These outdated protocols lack modern security features, making them vulnerable to known attacks and exposing… |
- risk 0.34cvss 5.3epss 0.01
In JetBrains TeamCity before 2021.1, an insecure key generation mechanism for encrypted properties was used.
- risk 0.34cvss 5.3epss 0.00
iDrive RemotePC before 7.6.48 on Windows allows information disclosure. A man in the middle can recover a system's Personal Key when a client attempts to make a LAN connection. The Personal Key is transmitted over the network while only being encrypted via a substitution cipher.
- risk 0.34cvss 5.3epss 0.01
In JetBrains Ktor before 1.4.2, weak cipher suites were enabled by default.
- risk 0.34cvss 5.3epss 0.01
"HCL AppScan Enterprise makes use of broken or risky cryptographic algorithm to store REST API user details."
- risk 0.34cvss 5.3epss 0.00
There is a weak algorithm vulnerability in some Huawei products. The affected products use the RSA algorithm in the SSL key exchange algorithm which have been considered as a weak algorithm. Attackers may exploit this vulnerability to leak some information.
- risk 0.34cvss 5.3epss 0.01
BigProf AppGini 5.70 stores the passwords in the database using the MD5 hash.
- risk 0.34cvss 4.7epss 0.01
The airbag detonation algorithm allows injury to passenger-car occupants via predictable Security Access (SA) data to the internal CAN bus (or the OBD connector). This affects the airbag control units (aka pyrotechnical control units or PCUs) of unspecified passenger vehicles…
- risk 0.33cvss 5.1epss 0.00
IBM Aspera faspio Gateway 1.3.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information
- risk 0.33cvss 5.1epss 0.00
In modem, there is a possible information disclosure due to using risky cryptographic algorithm during connection establishment negotiation. This could lead to remote information disclosure, when weak encryption algorithm is used, with no additional execution privileges needed.…
- risk 0.33cvss 5.1epss 0.00
IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security, caused by the improper encoding in a local configuration file. IBM X-Force ID: 258637.
- risk 0.33cvss 5.1epss 0.00
IBM Spectrum Control 5.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 233982.
- risk 0.33cvss 6.1epss 0.01
In OctoberCMS before version 1.0.468, encrypted cookie values were not tied to the name of the cookie the value belonged to. This meant that certain classes of attacks that took advantage of other theoretical vulnerabilities in user facing code (nothing exploitable in the core…
- risk 0.33cvss 5.1epss 0.00
The WindowsHello open source library (NuGet HaemmerElectronics.SeppPenner.WindowsHello), before version 1.0.4, has a vulnerability where encrypted data could potentially be decrypted without needing authentication. If the library is used to encrypt text and write the output to a…
- risk 0.33cvss 5.1epss 0.00
IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway 2.2.0 through 2.2.6) uses weaker than expected cryptographic algorithms that could allow a local attacker to decrypt highly sensitive information. IBM X-Force ID: 132032.
- risk 0.33cvss 5.1epss 0.00
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 131853.
- risk 0.32cvss 4.9epss 0.01
A risky-algorithm issue was discovered on Fujifilm DocuCentre-VI C4471 1.8 devices. An attacker that obtained access to the administrative web interface of a printer (e.g., by using the default credentials) can download the address book file, which contains the list of users…
- risk 0.32cvss 4.9epss 0.02
"managed-keys" is a feature which allows a BIND resolver to automatically maintain the keys used by trust anchors which operators configure for use in DNSSEC validation. Due to an error in the managed-keys feature it is possible for a BIND server which uses managed-keys to exit…
- risk 0.32cvss 5.9epss 0.04
It was found that the GnuTLS implementation of HMAC-SHA-384 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to conduct distinguishing attacks and plain text recovery attacks via statistical analysis of timing data using crafted packets.
- risk 0.32cvss 5.9epss 0.04
It was found that the GnuTLS implementation of HMAC-SHA-256 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data using crafted packets.
- risk 0.31cvss 4.8epss 0.00
HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. It was observed that the application was using weak TLS versions such as TLS 1.0 and 1.1. These outdated protocols lack modern security features, making them vulnerable to known attacks and exposing…