VYPR

CWE-330

Use of Insufficiently Random Values

ClassStableLikelihood: High

Description

The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-112 · CAPEC-485 · CAPEC-59

CVEs mapped to this weakness (398)

page 6 of 20
  • CVE-2008-0087HigApr 8, 2008
    risk 0.51cvss 7.5epss 0.32

    The DNS client in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, and Vista uses predictable DNS transaction IDs, which allows remote attackers to spoof DNS responses.

  • CVE-2026-41505HigMay 7, 2026
    risk 0.50cvss 8.7epss 0.00

    RELATE is a web-based courseware package. Prior to commit 2f68e16, RELATE is vulnerable to predictable token generation in auth.py's make_sign_in_key() function and exam.py's gen_ticket_code() function. This issue has been patched via commit 2f68e16.

  • CVE-2024-51346HigMar 25, 2026
    risk 0.50cvss 7.7epss 0.00

    An issue in Eufy Homebase 2 version 3.3.4.1h allows a local attacker to obtain sensitive information via the cryptographic scheme.

  • CVE-2024-10082HigNov 6, 2024
    risk 0.50cvss 8.7epss 0.00

    CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication method confusion allows logging in as the built-in root user from an external service. The built-in root user up until 6.24.1 is generated in a…

  • CVE-2024-7558HigOct 2, 2024
    risk 0.50cvss 8.7epss 0.01

    JUJU_CONTEXT_ID is a predictable authentication secret. On a Juju machine (non-Kubernetes) or Juju charm container (on Kubernetes), an unprivileged user in the same network namespace can connect to an abstract domain socket and guess the JUJU_CONTEXT_ID value. This gives the…

  • CVE-2017-5242HigJan 12, 2023
    risk 0.50cvss 7.7epss 0.00

    Nexpose and InsightVM virtual appliances downloaded between April 5th, 2017 and May 3rd, 2017 contain identical SSH host keys. Normally, a unique SSH host key should be generated the first time a virtual appliance boots.

  • CVE-2024-56089HigDec 1, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue in Technitium through v13.2.2 enables attackers to conduct a DNS cache poisoning attack and inject fake responses by reviving the birthday attack.

  • CVE-2025-59371HigNov 25, 2025
    risk 0.49cvss epss 0.01

    An authentication bypass vulnerability has been identified in the IFTTT integration feature. A remote, authenticated attacker could leverage this vulnerability to potentially gain unauthorized access to the device. This vulnerability does not affect Wi-Fi 7 series models. Refer…

  • CVE-2024-47188HigOct 16, 2024
    risk 0.49cvss 7.5epss 0.00

    Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.7, missing initialization of the random seed for "thash" leads to byte-range tracking having predictable hash table behavior. This can lead…

  • CVE-2024-47187HigOct 16, 2024
    risk 0.49cvss 7.5epss 0.00

    Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.7, missing initialization of the random seed for "thash" leads to datasets having predictable hash table behavior. This can lead to dataset…

  • CVE-2024-41708HigSep 25, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in AdaCore ada_web_services 20.0 allows an attacker to escalate privileges and steal sessions via the Random_String() function in the src/core/aws-utils.adb module.

  • CVE-2024-6348HigAug 19, 2024
    risk 0.49cvss 7.5epss 0.00

    Predictable seed generation in the security access mechanism of UDS in the Blind Spot Protection Sensor ECU in Nissan Altima (2022) allows attackers to predict the requested seeds and bypass security controls via repeated ECU resets and seed requests.

  • CVE-2024-25943HigJun 29, 2024
    risk 0.49cvss 7.6epss 0.01

    iDRAC9, versions prior to 7.00.00.172 for 14th Generation and 7.10.50.00 for 15th and 16th Generations, contains a session hijacking vulnerability in IPMI. A remote attacker could potentially exploit this vulnerability, leading to arbitrary code execution on the vulnerable…

  • CVE-2020-27213HigOct 10, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Ethernut Nut/OS 5.1. The code that generates Initial Sequence Numbers (ISNs) for TCP connections derives the ISN from an insufficiently random source. As a result, an attacker may be able to determine the ISN of current and future TCP connections and…

  • CVE-2023-29332HigSep 12, 2023
    risk 0.49cvss 7.5epss 0.03

    Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability

  • CVE-2023-34353HigSep 5, 2023
    risk 0.49cvss 7.5epss 0.01

    An authentication bypass vulnerability exists in the OAS Engine authentication functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted network sniffing can lead to decryption of sensitive information. An attacker can sniff network traffic to…

  • CVE-2023-26451HigAug 2, 2023
    risk 0.49cvss 7.5epss 0.01

    Functions with insufficient randomness were used to generate authorization tokens of the integrated oAuth Authorization Service. Authorization codes were predictable for third parties and could be used to intercept and take over the client authorization process. As a result,…

  • CVE-2023-26855HigApr 4, 2023
    risk 0.49cvss 7.5epss 0.01

    The hashing algorithm of ChurchCRM v4.5.3 utilizes a non-random salt value which allows attackers to use precomputed hash tables or dictionary attacks to crack the hashed passwords.

  • CVE-2022-29808HigAug 2, 2022
    risk 0.49cvss 7.5epss 0.01

    In Quest KACE Systems Management Appliance (SMA) through 12.0, predictable token generation occurs when appliance linking is enabled.

  • CVE-2022-26306HigJul 25, 2022
    risk 0.49cvss 7.5epss 0.01

    LibreOffice supports the storage of passwords for web connections in the user’s configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in LibreOffice existed where the required initialization vector for encryption was…