VYPR

CWE-327

Use of a Broken or Risky Cryptographic Algorithm

ClassDraftLikelihood: High

Description

The product uses a broken or risky cryptographic algorithm or protocol.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-20 · CAPEC-459 · CAPEC-473 · CAPEC-475 · CAPEC-608 · CAPEC-614 · CAPEC-97

CVEs mapped to this weakness (713)

page 36 of 36
  • CVE-2021-40529MedSep 6, 2021
    risk 0.00cvss 5.9epss 0.02

    The ElGamal implementation in Botan through 2.18.1, as used in Thunderbird and other products, allows plaintext recovery because, during interaction between two cryptographic libraries, a certain dangerous combination of the prime defined by the receiver's public key, the…

  • CVE-2019-25006HigDec 31, 2020
    risk 0.00cvss 7.5epss 0.01

    An issue was discovered in the streebog crate before 0.8.0 for Rust. The Streebog hash function can produce the wrong answer.

  • CVE-2020-27611HigOct 21, 2020
    risk 0.00cvss 7.3epss 0.01

    BigBlueButton through 2.2.28 uses STUN/TURN resources from a third party, which may represent an unintended endpoint.

  • CVE-2020-11031HigSep 23, 2020
    risk 0.00cvss 7.8epss 0.00

    In GLPI before version 9.5.0, the encryption algorithm used is insecure. The security of the data encrypted relies on the password used, if a user sets a weak/predictable password, an attacker could decrypt data. This is fixed in version 9.5.0 by using a more secure encryption…

  • CVE-2020-7689MedJul 1, 2020
    risk 0.00cvss 5.9epss 0.01

    Data is truncated wrong when its length is greater than 255 bytes.

  • CVE-2019-15075HigMar 20, 2020
    risk 0.00cvss 7.5epss 0.00

    An issue was discovered in iNextrix ASTPP before 4.0.1. web_interface/astpp/application/config/config.php does not have strong random keys, as demonstrated by use of the 8YSDaBtDHAB3EQkxPAyTz2I5DttzA9uR private key and the r)fddEw232f encryption key.

  • CVE-2019-20138HigDec 30, 2019
    risk 0.00cvss 7.5epss 0.01

    The HTTP Authentication library before 2019-12-27 for Nim has weak password hashing because the default algorithm for libsodium's crypto_pwhash_str is not used.

  • CVE-2019-9155MedAug 22, 2019
    risk 0.00cvss 5.9epss 0.01

    A cryptographic issue in OpenPGP.js <=4.2.0 allows an attacker who is able provide forged messages and gain feedback about whether decryption of these messages succeeded to conduct an invalid curve attack in order to gain the victim's ECDH private key.

  • CVE-2019-5919CriMar 12, 2019
    risk 0.00cvss 9.1epss 0.01

    An incomplete cryptography of the data store function by using hidden tag in Nablarch 5 (5, and 5u1 to 5u13) allows remote attackers to obtain information of the stored data, to register invalid value, or alter the value via unspecified vectors.

  • CVE-2018-12420HigJun 14, 2018
    risk 0.00cvss 7.5epss 0.01

    IceHrm before 23.0.1.OS has a risky usage of a hashed password in a request.

  • CVE-2007-6755Oct 11, 2013
    risk 0.00cvss epss 0.02

    The NIST SP 800-90A default statement of the Dual Elliptic Curve Deterministic Random Bit Generation (Dual_EC_DRBG) algorithm contains point Q constants with a possible relationship to certain "skeleton key" values, which might allow context-dependent attackers to defeat…

  • CVE-2012-2146Aug 26, 2012
    risk 0.00cvss epss 0.02

    Elixir 0.8.0 uses Blowfish in CFB mode without constructing a unique initialization vector (IV), which makes it easier for context-dependent users to obtain sensitive information and decrypt the database.

  • CVE-2009-2273Jul 1, 2009
    risk 0.00cvss epss 0.01

    The default configuration of the Wi-Fi component on the Huawei D100 does not use encryption, which makes it easier for remote attackers to obtain sensitive information by sniffing the network.