VYPR

CWE-330

Use of Insufficiently Random Values

ClassStableLikelihood: High

Description

The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-112 · CAPEC-485 · CAPEC-59

CVEs mapped to this weakness (398)

page 2 of 20
  • CVE-2021-36166CriMar 1, 2022
    risk 0.64cvss 9.8epss 0.01

    An improper authentication vulnerability in FortiMail before 7.0.1 may allow a remote attacker to efficiently guess one administrative account's authentication token by means of the observation of certain system's properties.

  • CVE-2022-22922CriFeb 18, 2022
    risk 0.64cvss 9.8epss 0.01

    TP-Link TL-WA850RE Wi-Fi Range Extender before v6_200923 was discovered to use highly predictable and easily detectable session keys, allowing attackers to gain administrative privileges.

  • CVE-2021-36294CriJan 25, 2022
    risk 0.64cvss 9.8epss 0.02

    Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authentication bypass vulnerability. A remote unauthenticated attacker may exploit this vulnerability by forging a cookie to login as any user.

  • CVE-2021-41694CriDec 9, 2021
    risk 0.64cvss 9.8epss 0.01

    An Incorrect Access Control vulnerability exists in Premiumdatingscript 4.2.7.7 via the password change procedure in requests\user.php.

  • CVE-2021-28024CriNov 8, 2021
    risk 0.64cvss 9.8epss 0.01

    Unauthorized system access in the login form in ServiceTonic Helpdesk software version < 9.0.35937 allows attacker to login without using a password.

  • CVE-2021-27200CriJun 11, 2021
    risk 0.64cvss 9.8epss 0.03

    In WoWonder 3.0.4, remote attackers can take over any account due to the weak cryptographic algorithm in recover.php. The code parameter is easily predicted from the time of day.

  • CVE-2020-7548CriDec 1, 2020
    risk 0.64cvss 9.8epss 0.01

    A CWE-330 - Use of Insufficiently Random Values vulnerability exists in Smartlink, PowerTag, and Wiser Series Gateways (see security notification for version information) that could allow unauthorized users to login.

  • CVE-2020-9502CriMay 13, 2020
    risk 0.64cvss 9.8epss 0.01

    Some Dahua products with Build time before December 2019 have Session ID predictable vulnerabilities. During normal user access, an attacker can use the predicted Session ID to construct a data packet to attack the device.

  • CVE-2019-2317CriMar 5, 2020
    risk 0.64cvss 9.8epss 0.01

    The secret key used to make the Initial Sequence Number in the TCP SYN packet could be brute forced and therefore can be predicted in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice &…

  • CVE-2019-16674CriDec 6, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. Authentication Information used in a cookie is predictable and can lead to admin password compromise when captured on the…

  • CVE-2014-6311CriNov 22, 2019
    risk 0.64cvss 9.8epss 0.02

    generate_doygen.pl in ace before 6.2.7+dfsg-2 creates predictable file names in the /tmp directory which allows attackers to gain elevated privileges.

  • CVE-2019-2294CriSep 30, 2019
    risk 0.64cvss 9.8epss 0.01

    Usage of hard-coded magic number for calculating heap guard bytes can allow users to corrupt heap blocks without heap algorithm knowledge in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT,…

  • CVE-2019-15130CriAug 18, 2019
    risk 0.64cvss 9.8epss 0.02

    The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to upload any file type to a candidate's profile picture folder via a crafted recruitment_online/personalData/act_personaltab.cfm multiple-part POST request with a…

  • CVE-2019-7667CriJul 1, 2019
    risk 0.64cvss 9.8epss 0.04

    Prima Systems FlexAir, Versions 2.3.38 and prior. The application generates database backup files with a predictable name, and an attacker can use brute force to identify the database backup file name. A malicious actor can exploit this issue to download the database file and…

  • CVE-2019-9863CriMar 27, 2019
    risk 0.64cvss 9.8epss 0.02

    Due to the use of an insecure algorithm for rolling codes in the ABUS Secvest wireless alarm system FUAA50000 3.01.01 and its remote controls FUBE50014 and FUBE50015, an attacker is able to predict valid future rolling codes, and can thus remotely control the alarm system in an…

  • CVE-2019-9898CriMar 21, 2019
    risk 0.64cvss 9.8epss 0.04

    Potential recycling of random numbers used in cryptography exists within PuTTY before 0.71.

  • CVE-2019-0729CriMar 5, 2019
    risk 0.64cvss 9.8epss 0.03

    An Elevation of Privilege vulnerability exists in the way Azure IoT Java SDK generates symmetric keys for encryption, allowing an attacker to predict the randomness of the key, aka 'Azure IoT Java SDK Elevation of Privilege Vulnerability'.

  • CVE-2018-18602CriDec 31, 2018
    risk 0.64cvss 9.8epss 0.01

    The Cloud API on Guardzilla smart cameras allows user enumeration, with resultant arbitrary camera access and monitoring.

  • CVE-2018-18531CriOct 19, 2018
    risk 0.64cvss 9.8epss 0.01

    text/impl/DefaultTextCreator.java, text/impl/ChineseTextProducer.java, and text/impl/FiveLetterFirstNameTextCreator.java in kaptcha 2.3.2 use the Random (rather than SecureRandom) function for generating CAPTCHA values, which makes it easier for remote attackers to bypass…

  • CVE-2018-18375CriOct 16, 2018
    risk 0.64cvss 9.8epss 0.01

    goform/getProfileList in Orange AirBox Y858_FL_01.16_04 allows attackers to extract APN data (name, number, username, and password) via the rand parameter.