VYPR

CWE-330

Use of Insufficiently Random Values

ClassStableLikelihood: High

Description

The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-112 · CAPEC-485 · CAPEC-59

CVEs mapped to this weakness (398)

page 1 of 20
  • CVE-2019-5420CriMar 27, 2019
    risk 0.74cvss 9.8epss 0.92

    A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess the automatically generated development mode secret token. This secret token can be used in combination with other Rails internals to escalate to a remote code…

  • CVE-2021-34646CriAug 30, 2021
    risk 0.71cvss 9.8epss 0.51

    Versions up to, and including, 5.4.3, of the Booster for WooCommerce WordPress plugin are vulnerable to authentication bypass via the process_email_verification function due to a random token generation weakness in the reset_and_mail_activation_link function found in the…

  • CVE-2018-17888CriOct 12, 2018
    risk 0.69cvss 9.8epss 0.30

    NUUO CMS all versions 3.1 and prior, The application uses a session identification mechanism that could allow attackers to obtain the active session ID, which could allow arbitrary remote code execution.

  • CVE-2022-36536CriSep 16, 2022
    risk 0.67cvss 9.8epss 0.04

    An issue in the component post_applogin.php of Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below allows attackers to escalate privileges via creating crafted session tokens.

  • CVE-2023-22601CriJan 12, 2023
    risk 0.65cvss 10.0epss 0.01

    InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-S-V2.3.0.r5542, contain vulnerability CWE-330: Use of Insufficiently Random Values. They do not properly randomize MQTT ClientID parameters. An unauthorized user could…

  • CVE-2021-40422CriApr 14, 2022
    risk 0.65cvss 10.0epss 0.06

    An authentication bypass vulnerability exists in the device password generation functionality of Swift Sensors Gateway SG3-1010. A specially-crafted network request can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.

  • CVE-2017-6026CriJun 30, 2017
    risk 0.65cvss 9.1epss 0.32

    A Use of Insufficiently Random Values issue was discovered in Schneider Electric Modicon PLCs Modicon M241, firmware versions prior to Version 4.0.5.11, and Modicon M251, firmware versions prior to Version 4.0.5.11. The session numbers generated by the web application are…

  • CVE-2008-2433CriAug 27, 2008
    risk 0.65cvss 9.8epss 0.11

    The web management console in Trend Micro OfficeScan 7.0 through 8.0, Worry-Free Business Security 5.0, and Client/Server/Messaging Suite 3.5 and 3.6 creates a random session token based only on the login time, which makes it easier for remote attackers to hijack sessions via…

  • CVE-2026-25072CriMar 7, 2026
    risk 0.64cvss 9.8epss 0.01

    XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a predictable session identifier vulnerability in the /goform/SetLogin endpoint that allows remote attackers to hijack authenticated sessions. Attackers can predict session identifiers using…

  • CVE-2026-27755CriFeb 27, 2026
    risk 0.64cvss 9.8epss 0.00

    SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a weak session identifier generation vulnerability that allows attackers to forge authenticated sessions by computing predictable MD5-based cookies. Attackers who know or guess valid credentials can calculate the…

  • CVE-2025-4607CriMay 31, 2025
    risk 0.64cvss 9.8epss 0.01

    The PSW Front-end Login & Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.12 via the customer_registration() function. This is due to the use of a weak, low-entropy OTP mechanism in the forget() function. This makes…

  • CVE-2024-36389CriJun 2, 2024
    risk 0.64cvss 9.8epss 0.01

    MileSight DeviceHub - CWE-330 Use of Insufficiently Random Values may allow Authentication Bypass

  • CVE-2020-27631CriOct 10, 2023
    risk 0.64cvss 9.8epss 0.01

    In Oryx CycloneTCP 1.9.6, TCP ISNs are improperly random.

  • CVE-2020-27630CriOct 10, 2023
    risk 0.64cvss 9.8epss 0.01

    In Silicon Labs uC/TCP-IP 3.6.0, TCP ISNs are improperly random.

  • CVE-2023-39979CriSep 2, 2023
    risk 0.64cvss 9.8epss 0.01

    There is a vulnerability in MXsecurity versions prior to 1.0.1 that can be exploited to bypass authentication. A remote attacker might access the system if the web service authenticator has insufficient random values.  

  • CVE-2023-4344CriAug 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Broadcom RAID Controller web interface is vulnerable to insufficient randomness due to improper use of ssl.rnd to setup CIM connection

  • CVE-2023-2884CriMay 25, 2023
    risk 0.64cvss 9.8epss 0.01

    Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG), Use of Insufficiently Random Values vulnerability in CBOT Chatbot allows Signature Spoofing by Key Recreation. This issue affects Chatbot: before Core: v4.0.3.4 Panel: v4.0.3.7.

  • CVE-2022-46353CriDec 13, 2022
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (HSR) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP/HSR) (All…

  • CVE-2022-44938CriDec 8, 2022
    risk 0.64cvss 9.8epss 0.01

    Weak reset token generation in SeedDMS v6.0.20 and v5.1.7 allows attackers to execute a full account takeover via a brute force attack.

  • CVE-2022-25752CriApr 12, 2022
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been identified in SCALANCE X302-7 EEC (230V), SCALANCE X302-7 EEC (230V, coated), SCALANCE X302-7 EEC (24V), SCALANCE X302-7 EEC (24V, coated), SCALANCE X302-7 EEC (2x 230V), SCALANCE X302-7 EEC (2x 230V, coated), SCALANCE X302-7 EEC (2x 24V), SCALANCE…