VYPR

CWE-328

Use of Weak Hash

BaseDraft

Description

The product uses an algorithm that produces a digest (output value) that does not meet security expectations for a hash function that allows an adversary to reasonably determine the original input (preimage attack), find another input that can produce the same hash (2nd preimage attack), or find multiple inputs that evaluate to the same hash (birthday attack).

Hierarchy (View 1000)

Children

Related attack patterns (CAPEC)

CAPEC-461 · CAPEC-68

CVEs mapped to this weakness (97)

page 3 of 5
  • CVE-2024-38341MedMay 28, 2025
    risk 0.38cvss 5.9epss 0.00

    IBM Sterling Secure Proxy 6.0.0.0 through 6.0.3.1, 6.1.0.0 through 6.1.0.0, and 6.2.0.0 through 6.2.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

  • CVE-2025-3576MedApr 15, 2025
    risk 0.38cvss 5.9epss 0.00

    A vulnerability in the MIT Kerberos implementation allows GSSAPI-protected messages using RC4-HMAC-MD5 to be spoofed due to weaknesses in the MD5 checksum design. If RC4 is preferred over stronger encryption types, an attacker could exploit MD5 collisions to forge message…

  • CVE-2025-21604MedJan 6, 2025
    risk 0.38cvss —epss 0.00

    LangChain4j-AIDeepin is a Retrieval enhancement generation (RAG) project. Prior to 3.5.0, LangChain4j-AIDeepin uses MD5 to hash files, which may cause file upload conflicts. This issue is fixed in 3.5.0.

  • CVE-2025-31130MedApr 4, 2025
    risk 0.37cvss 6.8epss 0.00

    gitoxide is an implementation of git written in Rust. Before 0.42.0, gitoxide uses SHA-1 hash implementations without any collision detection, leaving it vulnerable to hash collision attacks. gitoxide uses the sha1_smol or sha1 crate, both of which implement standard SHA-1…

  • CVE-2024-56414MedJan 2, 2025
    risk 0.36cvss 5.5epss 0.00

    Web installer integrity check used weak hash algorithm. The following products are affected: Acronis Cyber Protect 16 (Windows) before build 39169.

  • CVE-2015-8234MedMar 29, 2017
    risk 0.36cvss 5.5epss 0.01

    The image signature algorithm in OpenStack Glance 11.0.0 allows remote attackers to bypass the signature verification process via a crafted image, which triggers an MD5 collision.

  • CVE-2025-59354MedSep 17, 2025
    risk 0.34cvss 5.3epss 0.00

    Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the DragonFly2 uses a variety of hash functions, including the MD5 hash, for downloaded files. This allows attackers to replace files with malicious ones that have a colliding…

  • CVE-2022-43922MedFeb 1, 2023
    risk 0.34cvss 5.3epss 0.00

    IBM App Connect Enterprise Certified Container 4.1, 4.2, 5.0, 5.1, 5.2, 6.0, 6.1, and 6.2 could disclose sensitive information to an attacker due to a weak hash of an API Key in the configuration. IBM X-Force ID: 241583.

  • CVE-2022-29835MedSep 19, 2022
    risk 0.34cvss 5.3epss 0.00

    WD Discovery software executable files were signed with an unsafe SHA-1 hashing algorithm. An attacker could use this weakness to create forged certificate signatures due to the use of a hashing algorithm that is not collision-free. This could thereby impact the confidentiality…

  • CVE-2026-54266MedJun 22, 2026
    risk 0.33cvss 6.1epss 0.00

    Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.1, 21.2.17, and 20.3.25, Angular's HttpTransferCache caches HTTP requests made during Server-Side Rendering (SSR) so that they can be…

  • CVE-2024-8453MedSep 30, 2024
    risk 0.32cvss 4.9epss 0.00

    Certain switch models from PLANET Technology use an insecure hashing function to hash user passwords without being salted. Remote attackers with administrator privileges can read configuration files to obtain the hash values, and potentially crack them to retrieve the plaintext…

  • CVE-2023-44319MedNov 14, 2023
    risk 0.32cvss 4.9epss 0.00

    A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.0), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V8.0), SCALANCE M804PB (6GK5804-0AP00-2AA2) (All versions < V8.0), SCALANCE M812-1 ADSL-Router…

  • CVE-2026-21717MedMar 30, 2026
    risk 0.31cvss 5.9epss 0.00

    A flaw in V8's string hashing mechanism causes integer-like strings to be hashed to their numeric value, making hash collisions trivially predictable. By crafting a request that causes many such collisions in V8's internal string table, an attacker can significantly degrade…

  • CVE-2025-0508MedMar 20, 2025
    risk 0.31cvss 5.9epss 0.00

    A vulnerability in the SageMaker Workflow component of aws/sagemaker-python-sdk allows for the possibility of MD5 hash collisions in all versions. This can lead to workflows being inadvertently replaced due to the reuse of results from different configurations that produce the…

  • CVE-2026-56272MedJun 24, 2026
    risk 0.27cvss 4.1epss 0.00

    Flowise before 3.0.13 uses bcrypt with default salt rounds of 5, providing only 32 iterations instead of the OWASP-recommended minimum of 10 rounds. Attackers can crack password hashes approximately 30 times faster with modern GPU hardware, potentially compromising all user…

  • CVE-2026-34527MedMay 5, 2026
    risk 0.27cvss 5.3epss 0.00

    Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, SbieIniServer::HashPassword converts a SHA-1 digest to hexadecimal incorrectly. The high nibble of each byte is shifted right by 8 instead of 4, which always produces…

  • CVE-2024-34914MedMay 14, 2024
    risk 0.27cvss 5.3epss 0.00

    php-censor v2.1.4 and fixed in v.2.1.5 was discovered to utilize a weak hashing algorithm for its remember_key value. This allows attackers to bruteforce to bruteforce the remember_key value to gain access to accounts that have checked "remember me" when logging in.

  • CVE-2026-8803LowMay 18, 2026
    risk 0.24cvss 3.7epss 0.00

    A flaw has been found in opensourcepos Open Source Point of Sale up to 3.4.2. Impacted is the function Login of the file app/Models/Employee.php of the component Employee Login. This manipulation causes use of weak hash. Remote exploitation of the attack is possible. The attack…

  • CVE-2026-7103LowApr 27, 2026
    risk 0.24cvss 3.7epss 0.00

    A vulnerability was determined in code-projects Chat System 1.0. Affected is an unknown function of the file update_user.php of the component MD5 Hash Handler. This manipulation of the argument Password causes use of weak hash. The attack is possible to be carried out remotely.…

  • CVE-2025-14636LowDec 13, 2025
    risk 0.24cvss 3.7epss 0.00

    A security flaw has been discovered in Tenda AX9 22.03.01.46. This affects the function image_check of the component httpd. The manipulation results in use of weak hash. It is possible to launch the attack remotely. A high complexity level is associated with this attack. It is…