CWE-330
Use of Insufficiently Random Values
Description
The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-112 · CAPEC-485 · CAPEC-59
CVEs mapped to this weakness (398)
page 7 of 20| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-32284 | Hig | 0.49 | 7.5 | 0.03 | Jul 4, 2022 | Use of insufficiently random values vulnerability exists in Vnet/IP communication module VI461 of YOKOGAWA Wide Area Communication Router (WAC Router) AW810D, which may allow a remote attacker to cause denial-of-service (DoS) condition by sending a specially crafted packet. | ||
| CVE-2022-23138 | Hig | 0.49 | 7.5 | 0.01 | Jun 9, 2022 | ZTE's MF297D product has cryptographic issues vulnerability. Due to the use of weak random values, the security of the device is reduced, and it may face the risk of attack. | ||
| CVE-2019-25061 | Hig | 0.49 | 7.5 | 0.02 | May 18, 2022 | The random_password_generator (aka RandomPasswordGenerator) gem through 1.0.0 for Ruby uses Kernel#rand to generate passwords, which, due to its cyclic nature, can facilitate password prediction. | ||
| CVE-2022-30782 | Hig | 0.49 | 7.5 | 0.01 | May 16, 2022 | Openmoney API through 2020-06-29 uses the JavaScript Math.random function, which does not provide cryptographically secure random numbers. | ||
| CVE-2022-22517 | Hig | 0.49 | 7.5 | 0.01 | Apr 7, 2022 | An unauthenticated, remote attacker can disrupt existing communication channels between CODESYS products by guessing a valid channel ID and injecting packets. This results in the communication channel to be closed. | ||
| CVE-2022-28355 | Hig | 0.49 | 7.5 | 0.01 | Apr 2, 2022 | randomUUID in Scala.js before 1.10.0 generates predictable values. | ||
| CVE-2021-20322 | Hig | 0.49 | 7.4 | 0.07 | Feb 18, 2022 | A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Linux kernel functionality was found to allow the ability to quickly scan open UDP ports. This flaw allows an off-path remote user to effectively bypass the source port UDP… | ||
| CVE-2021-24998 | Hig | 0.49 | 7.5 | 0.01 | Dec 27, 2021 | The Simple JWT Login WordPress plugin before 3.3.0 can be used to create new WordPress user accounts with a randomly generated password. The password is generated using the str_shuffle PHP function that "does not generate cryptographically secure values, and should not be used… | ||
| CVE-2021-45488 | Hig | 0.49 | 7.5 | 0.01 | Dec 25, 2021 | In NetBSD through 9.2, there is an information leak in the TCP ISN (ISS) generation algorithm. | ||
| CVE-2021-45487 | Hig | 0.49 | 7.5 | 0.01 | Dec 25, 2021 | In NetBSD through 9.2, the IPv4 ID generation algorithm does not use appropriate cryptographic measures. | ||
| CVE-2021-44151 | Hig | 0.49 | 7.5 | 0.03 | Dec 13, 2021 | An issue was discovered in Reprise RLM 14.2. As the session cookies are small, an attacker can hijack any existing sessions by bruteforcing the 4 hex-character session cookie on the Windows version (the Linux version appears to have 8 characters). An attacker can obtain the… | ||
| CVE-2021-26322 | Hig | 0.49 | 7.5 | 0.01 | Nov 16, 2021 | Persistent platform private key may not be protected with a random IV leading to a potential “two time pad attack”. | ||
| CVE-2021-41829 | Hig | 0.49 | 7.5 | 0.03 | Sep 30, 2021 | Zoho ManageEngine Remote Access Plus before 10.1.2121.1 relies on the application's build number to calculate a certain encryption key. | ||
| CVE-2021-31228 | Hig | 0.49 | 7.5 | 0.01 | Aug 19, 2021 | An issue was discovered in HCC embedded InterNiche 4.0.1. This vulnerability allows the attacker to predict a DNS query's source port in order to send forged DNS response packets that will be accepted as valid answers to the DNS client's requests (without sniffing the specific… | ||
| CVE-2021-0466 | Hig | 0.49 | 7.5 | 0.01 | Jun 11, 2021 | In startIpClient of ClientModeImpl.java, there is a possible identifier which could be used to track a device. This could lead to remote information disclosure to a proximal attacker, with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2021-22309 | Hig | 0.49 | 7.5 | 0.01 | Mar 22, 2021 | There is insecure algorithm vulnerability in Huawei products. A module uses less random input in a secure mechanism. Attackers can exploit this vulnerability by brute forcing to obtain sensitive message. This can lead to information leak. Affected product versions… | ||
| CVE-2020-13860 | Hig | 0.49 | 7.5 | 0.01 | Feb 1, 2021 | An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. The one-time password algorithm for the undocumented system account mofidev generates a predictable six-digit password. | ||
| CVE-2020-26550 | Hig | 0.49 | 7.5 | 0.01 | Nov 17, 2020 | An issue was discovered in Aviatrix Controller before R5.3.1151. An encrypted file containing credentials to unrelated systems is protected by a three-character key. | ||
| CVE-2020-25705 | Hig | 0.49 | 7.4 | 0.07 | Nov 17, 2020 | A flaw in ICMP packets in the Linux kernel may allow an attacker to quickly scan open UDP ports. This flaw allows an off-path remote attacker to effectively bypass source port UDP randomization. Software that relies on UDP source port randomization are indirectly affected as… | ||
| CVE-2020-27180 | Hig | 0.49 | 7.5 | 0.01 | Oct 27, 2020 | konzept-ix publiXone before 2020.015 allows attackers to download files by iterating over the IXCopy fileID parameter. |
- risk 0.49cvss 7.5epss 0.03
Use of insufficiently random values vulnerability exists in Vnet/IP communication module VI461 of YOKOGAWA Wide Area Communication Router (WAC Router) AW810D, which may allow a remote attacker to cause denial-of-service (DoS) condition by sending a specially crafted packet.
- risk 0.49cvss 7.5epss 0.01
ZTE's MF297D product has cryptographic issues vulnerability. Due to the use of weak random values, the security of the device is reduced, and it may face the risk of attack.
- risk 0.49cvss 7.5epss 0.02
The random_password_generator (aka RandomPasswordGenerator) gem through 1.0.0 for Ruby uses Kernel#rand to generate passwords, which, due to its cyclic nature, can facilitate password prediction.
- risk 0.49cvss 7.5epss 0.01
Openmoney API through 2020-06-29 uses the JavaScript Math.random function, which does not provide cryptographically secure random numbers.
- risk 0.49cvss 7.5epss 0.01
An unauthenticated, remote attacker can disrupt existing communication channels between CODESYS products by guessing a valid channel ID and injecting packets. This results in the communication channel to be closed.
- risk 0.49cvss 7.5epss 0.01
randomUUID in Scala.js before 1.10.0 generates predictable values.
- risk 0.49cvss 7.4epss 0.07
A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Linux kernel functionality was found to allow the ability to quickly scan open UDP ports. This flaw allows an off-path remote user to effectively bypass the source port UDP…
- risk 0.49cvss 7.5epss 0.01
The Simple JWT Login WordPress plugin before 3.3.0 can be used to create new WordPress user accounts with a randomly generated password. The password is generated using the str_shuffle PHP function that "does not generate cryptographically secure values, and should not be used…
- risk 0.49cvss 7.5epss 0.01
In NetBSD through 9.2, there is an information leak in the TCP ISN (ISS) generation algorithm.
- risk 0.49cvss 7.5epss 0.01
In NetBSD through 9.2, the IPv4 ID generation algorithm does not use appropriate cryptographic measures.
- risk 0.49cvss 7.5epss 0.03
An issue was discovered in Reprise RLM 14.2. As the session cookies are small, an attacker can hijack any existing sessions by bruteforcing the 4 hex-character session cookie on the Windows version (the Linux version appears to have 8 characters). An attacker can obtain the…
- risk 0.49cvss 7.5epss 0.01
Persistent platform private key may not be protected with a random IV leading to a potential “two time pad attack”.
- risk 0.49cvss 7.5epss 0.03
Zoho ManageEngine Remote Access Plus before 10.1.2121.1 relies on the application's build number to calculate a certain encryption key.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in HCC embedded InterNiche 4.0.1. This vulnerability allows the attacker to predict a DNS query's source port in order to send forged DNS response packets that will be accepted as valid answers to the DNS client's requests (without sniffing the specific…
- risk 0.49cvss 7.5epss 0.01
In startIpClient of ClientModeImpl.java, there is a possible identifier which could be used to track a device. This could lead to remote information disclosure to a proximal attacker, with no additional execution privileges needed. User interaction is not needed for…
- risk 0.49cvss 7.5epss 0.01
There is insecure algorithm vulnerability in Huawei products. A module uses less random input in a secure mechanism. Attackers can exploit this vulnerability by brute forcing to obtain sensitive message. This can lead to information leak. Affected product versions…
- risk 0.49cvss 7.5epss 0.01
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. The one-time password algorithm for the undocumented system account mofidev generates a predictable six-digit password.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in Aviatrix Controller before R5.3.1151. An encrypted file containing credentials to unrelated systems is protected by a three-character key.
- risk 0.49cvss 7.4epss 0.07
A flaw in ICMP packets in the Linux kernel may allow an attacker to quickly scan open UDP ports. This flaw allows an off-path remote attacker to effectively bypass source port UDP randomization. Software that relies on UDP source port randomization are indirectly affected as…
- risk 0.49cvss 7.5epss 0.01
konzept-ix publiXone before 2020.015 allows attackers to download files by iterating over the IXCopy fileID parameter.