VYPR

CWE-327

Use of a Broken or Risky Cryptographic Algorithm

ClassDraftLikelihood: High

Description

The product uses a broken or risky cryptographic algorithm or protocol.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-20 · CAPEC-459 · CAPEC-473 · CAPEC-475 · CAPEC-608 · CAPEC-614 · CAPEC-97

CVEs mapped to this weakness (713)

page 8 of 36
  • CVE-2024-35537HigJun 21, 2024
    risk 0.49cvss 7.5epss 0.00

    TVS Motor Company Limited TVS Connect Android v4.6.0 and IOS v5.0.0 was discovered to insecurely handle the RSA key pair, allowing attackers to possibly access sensitive information via decryption.

  • CVE-2024-37568HigJun 9, 2024
    risk 0.49cvss 7.5epss 0.00

    lepture Authlib before 1.3.1 has algorithm confusion with asymmetric public keys. Unless an algorithm is specified in a jwt.decode call, HMAC verification is allowed with any asymmetric public key. (This is similar to CVE-2022-29217 and CVE-2024-33663.)

  • CVE-2024-36823HigJun 6, 2024
    risk 0.49cvss 7.5epss 0.01

    The encrypt() function of Ninja Core v7.0.0 was discovered to use a weak cryptographic algorithm, leading to a possible leakage of sensitive information.

  • CVE-2023-51838HigFeb 2, 2024
    risk 0.49cvss 7.5epss 0.01

    Ylianst MeshCentral 1.1.16 suffers from Use of a Broken or Risky Cryptographic Algorithm.

  • CVE-2023-49259HigJan 12, 2024
    risk 0.49cvss 7.5epss 0.00

    The authentication cookies are generated using an algorithm based on the username, hardcoded secret and the up-time, and can be guessed in a reasonable time.

  • CVE-2021-46900HigDec 31, 2023
    risk 0.49cvss 7.5epss 0.00

    Sympa before 6.2.62 relies on a cookie parameter for certain security objectives, but does not ensure that this parameter exists and has an unpredictable value. Specifically, the cookie parameter is both a salt for stored passwords and an XSS protection mechanism.

  • CVE-2023-50481HigDec 21, 2023
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in blinksocks version 3.3.8, allows remote attackers to obtain sensitive information via weak encryption algorithms in the component /presets/ssr-auth-chain.js.

  • CVE-2023-5627HigNov 1, 2023
    risk 0.49cvss 7.5epss 0.00

    A vulnerability has been identified in NPort 6000 Series, making the authentication mechanism vulnerable. This vulnerability arises from the incorrect implementation of sensitive information protection, potentially allowing malicious users to gain unauthorized access to the web…

  • CVE-2023-31582HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.01

    jose4j before v0.9.3 allows attackers to set a low iteration count of 1000 or less.

  • CVE-2023-4331HigAug 15, 2023
    risk 0.49cvss 7.5epss 0.00

    Broadcom RAID Controller web interface is vulnerable has an insecure default TLS configuration that support obsolete and vulnerable TLS protocols

  • CVE-2023-4326HigAug 15, 2023
    risk 0.49cvss 7.5epss 0.00

    Broadcom RAID Controller web interface is vulnerable has an insecure default TLS configuration that supports obsolete SHA1-based ciphersuites

  • CVE-2023-30441HigApr 29, 2023
    risk 0.49cvss 7.5epss 0.01

    IBM Runtime Environment, Java Technology Edition IBMJCEPlus and JSSE 8.0.7.0 through 8.0.7.11 components could expose sensitive information using a combination of flaws and configurations. IBM X-Force ID: 253188.

  • CVE-2023-28509HigMar 29, 2023
    risk 0.49cvss 7.5epss 0.00

    Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 use weak encryption for packet-level security and passwords transferred on the wire.

  • CVE-2023-23040HigFeb 22, 2023
    risk 0.49cvss 7.5epss 0.00

    TP-Link router TL-WR940N V6 3.19.1 Build 180119 uses a deprecated MD5 algorithm to hash the admin password used for basic authentication.

  • CVE-2022-37177HigAug 29, 2022
    risk 0.49cvss 7.5epss 0.00

    HireVue Hiring Platform V1.0 suffers from Use of a Broken or Risky Cryptographic Algorithm. NOTE: this is disputed by the vendor for multiple reasons, e.g., it is inconsistent with CVE ID assignment rules for cloud services, and no product with version V1.0 exists. Furthermore,…

  • CVE-2022-31158HigJul 15, 2022
    risk 0.49cvss 7.5epss 0.01

    LTI 1.3 Tool Library is a library used for building IMS-certified LTI 1.3 tool providers in PHP. Prior to version 5.0, the Nonce Claim Value was not being validated against the nonce value sent in the Authentication Request. Users should upgrade to version 5.0 to receive a…

  • CVE-2022-28622HigJun 27, 2022
    risk 0.49cvss 7.5epss 0.01

    A potential security vulnerability has been identified in HPE StoreOnce Software. The SSH server supports weak key exchange algorithms which could lead to remote unauthorized access. HPE has made the following software update to resolve the vulnerability in HPE StoreOnce…

  • CVE-2022-28166HigJun 27, 2022
    risk 0.49cvss 7.5epss 0.01

    In Brocade SANnav version before SANN2.2.0.2 and Brocade SANNav before 2.1.1.8, the implementation of TLS/SSL Server Supports the Use of Static Key Ciphers (ssl-static-key-ciphers) on ports 443 & 18082.

  • CVE-2022-28382HigJun 8, 2022
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in certain Verbatim drives through 2022-03-31. Due to the use of an insecure encryption AES mode (Electronic Codebook, aka ECB), an attacker may be able to extract information even from encrypted data, for example by observing repeating byte patterns. The…

  • CVE-2022-24296HigJun 8, 2022
    risk 0.49cvss 7.5epss 0.01

    Use of a Broken or Risky Cryptographic Algorithm vulnerability in Air Conditioning System G-150AD Ver. 3.21 and prior, Air Conditioning System AG-150A-A Ver. 3.21 and prior, Air Conditioning System AG-150A-J Ver. 3.21 and prior, Air Conditioning System GB-50AD Ver. 3.21 and…