VYPR

CWE-330

Use of Insufficiently Random Values

ClassStableLikelihood: High

Description

The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-112 · CAPEC-485 · CAPEC-59

CVEs mapped to this weakness (398)

page 11 of 20
  • CVE-2023-41879HigSep 11, 2023
    risk 0.42cvss 7.5epss 0.01

    Magento LTS is the official OpenMage LTS codebase. Guest orders may be viewed without authentication using a "guest-view" cookie which contains the order's "protect_code". This code is 6 hexadecimal characters which is arguably not enough to prevent a brute-force attack.…

  • CVE-2023-30797HigApr 19, 2023
    risk 0.42cvss 7.5epss 0.01

    Netflix Lemur before version 1.3.2 used insufficiently random values when generating default credentials. The insufficiently random values may allow an attacker to guess the credentials and gain access to resources managed by Lemur.

  • CVE-2023-0343MedMar 31, 2023
    risk 0.42cvss 6.5epss 0.01

    Akuvox E11 contains a function that encrypts messages which are then forwarded. The IV vector and the key are static, and this may allow an attacker to decrypt messages.

  • CVE-2022-44795MedNov 7, 2022
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Object First Ootbi BETA build 1.0.7.712. A flaw was found in the Web Service, which could lead to local information disclosure. The command that creates the URL for the support bundle uses an insecure RNG. That can lead to prediction of the generated…

  • CVE-2022-38970MedSep 26, 2022
    risk 0.42cvss 6.5epss 0.01

    ieGeek IG20 hipcam RealServer V1.0 is vulnerable to Incorrect Access Control. The algorithm used to generate device IDs (UIDs) for devices that utilize Shenzhen Yunni Technology iLnkP2P suffers from a predictability flaw that allows remote attackers to establish direct…

  • CVE-2022-39218HigSep 20, 2022
    risk 0.42cvss 7.5epss 0.01

    The JS Compute Runtime for Fastly's Compute@Edge platform provides the environment JavaScript is executed in when using the Compute@Edge JavaScript SDK. In versions prior to 0.5.3, the `Math.random` and `crypto.getRandomValues` methods fail to use sufficiently random values. The…

  • CVE-2022-24406MedJul 27, 2022
    risk 0.42cvss 6.5epss 0.01

    OX App Suite through 7.10.6 allows SSRF because multipart/form-data boundaries are predictable, and this can lead to injection into internal Documentconverter API calls.

  • CVE-2022-31157HigJul 15, 2022
    risk 0.42cvss 7.5epss 0.00

    LTI 1.3 Tool Library is a library used for building IMS-certified LTI 1.3 tool providers in PHP. Prior to version 5.0, the function used to generate random nonces was not sufficiently cryptographically complex. Users should upgrade to version 5.0 to receive a patch. There are…

  • CVE-2022-26317MedMar 8, 2022
    risk 0.42cvss 6.5epss 0.01

    A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.29). When returning the result of a completed Microflow execution call the affected framework does not correctly verify, if the request was initially made by the user requesting the…

  • CVE-2021-3689HigAug 10, 2021
    risk 0.42cvss 7.5epss 0.02

    yii2 is vulnerable to Use of Predictable Algorithm in Random Number Generator

  • CVE-2021-29499HigMay 7, 2021
    risk 0.42cvss 7.5epss 0.01

    SIF is an open source implementation of the Singularity Container Image Format. The `siftool new` command and func siftool.New() produce predictable UUID identifiers due to insecure randomness in the version of the `github.com/satori/go.uuid` module used as a dependency. A patch…

  • CVE-2021-21729MedApr 13, 2021
    risk 0.42cvss 6.5epss 0.00

    Some ZTE products have CSRF vulnerability. Because some pages lack CSRF random value verification, attackers could perform illegal authorization operations by constructing messages.This affects: ZXHN H168N V3.5.0_EG1T5_TE, V2.5.5, ZXHN H108N V2.5.5_BTMT1

  • CVE-2021-25375MedApr 9, 2021
    risk 0.42cvss 6.5epss 0.01

    Using predictable index for attachments in Samsung Email prior to version 6.1.41.0 allows remote attackers to get attachments of another emails when users open the malicious attachment.

  • CVE-2021-26296HigFeb 19, 2021
    risk 0.42cvss 7.5epss 0.03

    In the default configuration, Apache MyFaces Core versions 2.2.0 to 2.2.13, 2.3.0 to 2.3.7, 2.3-next-M1 to 2.3-next-M4, and 3.0.0-RC1 use cryptographically weak implicit and explicit cross-site request forgery (CSRF) tokens. Due to that limitation, it is possible (although…

  • CVE-2020-5408MedMay 14, 2020
    risk 0.42cvss 6.5epss 0.02

    Spring Security versions 5.3.x prior to 5.3.2, 5.2.x prior to 5.2.4, 5.1.x prior to 5.1.10, 5.0.x prior to 5.0.16 and 4.2.x prior to 4.2.16 use a fixed null initialization vector with CBC Mode in the implementation of the queryable text encryptor. A malicious user with access to…

  • CVE-2020-12270MedApr 27, 2020
    risk 0.42cvss 6.5epss 0.01

    React Native Bluetooth Scan in Bluezone 1.0.0 uses six-character alphanumeric IDs, which might make it easier for remote attackers to interfere with COVID-19 contact tracing by using many IDs. NOTE: the vendor disputes the relevance of this report because the recipient of an F1…

  • CVE-2020-1759MedApr 13, 2020
    risk 0.42cvss 6.4epss 0.02

    A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2 where, A nonce reuse vulnerability was discovered in the secure mode of the messenger v2 protocol, which can allow an attacker to forge auth tags and potentially manipulate the data…

  • CVE-2019-13929MedOct 10, 2019
    risk 0.42cvss 6.5epss 0.01

    A vulnerability has been identified in SIMATIC IT UADM (All versions < V1.3). An authenticated remote attacker with network access to port 1434/tcp of SIMATIC IT UADM could potentially recover a password that can be used to gain read and write access to the related TeamCenter…

  • CVE-2019-15955MedSep 5, 2019
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Total.js CMS 12.0.0. A low privilege user can perform a simple transformation of a cookie to obtain the random values inside it. If an attacker can discover a session cookie owned by an admin, then it is possible to brute force it with O(n)=2n instead…

  • CVE-2019-7886HigAug 2, 2019
    risk 0.42cvss 7.5epss 0.01

    A cryptograhic flaw exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. A weak cryptograhic mechanism is used to generate the intialization vector in multiple security relevant contexts.