VYPR

CWE-331

Insufficient Entropy

BaseDraft

Description

The product uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-59

CVEs mapped to this weakness (138)

page 3 of 7
  • CVE-2025-15629HigAug 3, 2026
    risk 0.49cvss 7.5epss 0.00

    A cryptographic weakness exists in the Omada adoption protocol where session encryption keys used to protect communications between controllers and managed devices may be predictable due to insufficient entropy in session key generation. An attacker who successfully…

  • CVE-2026-46474HigMay 15, 2026
    risk 0.49cvss 7.5epss 0.00

    Trog::TOTP versions before 1.006 for Perl generate secrets using rand. Secrets were generated using Perl's built-in rand function, which is predictable and unsuitable for security usage.

  • CVE-2025-29311HigMar 24, 2025
    risk 0.49cvss 7.5epss 0.00

    Limited secret space in LLDP packets used in onos v2.7.0 allows attackers to obtain the private key via a bruteforce attack. Attackers are able to leverage this vulnerability into creating crafted LLDP packets.

  • CVE-2024-53522HigJan 7, 2025
    risk 0.49cvss 7.5epss 0.01

    Bangkok Medical Software HOSxP XE v4.64.11.3 was discovered to contain a hardcoded IDEA Key-IV pair in the HOSxPXE4.exe and HOS-WIN32.INI components. This allows attackers to access sensitive information.

  • CVE-2018-9426HigDec 2, 2024
    risk 0.49cvss 7.5epss 0.00

    In  RsaKeyPairGenerator::getNumberOfIterations of RSAKeyPairGenerator.java, an incorrect implementation could cause weak RSA key pairs being generated. This could lead to crypto vulnerability with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2024-25407HigFeb 13, 2024
    risk 0.49cvss 7.5epss 0.01

    SteVe v3.6.0 was discovered to use predictable transaction ID's when receiving a StartTransaction request. This vulnerability can allow attackers to cause a Denial of Service (DoS) by using the predicted transaction ID's to terminate other transactions.

  • CVE-2023-31176HigNov 30, 2023
    risk 0.49cvss 7.5epss 0.01

    An Insufficient Entropy vulnerability in the Schweitzer Engineering Laboratories SEL-451 could allow an unauthenticated remote attacker to brute-force session tokens and bypass authentication.  See product Instruction Manual Appendix A dated 20230830 for more details.

  • CVE-2023-31582HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.01

    jose4j before v0.9.3 allows attackers to set a low iteration count of 1000 or less.

  • CVE-2023-20107HigMar 23, 2023
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in the deterministic random bit generator (DRBG), also known as pseudorandom number generator (PRNG), in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software for Cisco ASA 5506-X, ASA 5508-X, and ASA 5516-X Firewalls…

  • CVE-2022-33738HigJul 6, 2022
    risk 0.49cvss 7.5epss 0.01

    OpenVPN Access Server before 2.11 uses a weak random generator used to create user session token for the web portal

  • CVE-2022-33756HigJun 16, 2022
    risk 0.49cvss 7.5epss 0.01

    CA Automic Automation 12.2 and 12.3 contain an entropy weakness vulnerability in the Automic AutomationEngine that could allow a remote attacker to potentially access sensitive data.

  • CVE-2021-36320HigNov 20, 2021
    risk 0.49cvss 7.5epss 0.01

    Dell Networking X-Series firmware versions prior to 3.0.1.8 contain an authentication bypass vulnerability. A remote unauthenticated attacker may potentially hijack a session and access the webserver by forging the session ID.

  • CVE-2020-25926HigAug 18, 2021
    risk 0.49cvss 7.5epss 0.01

    The DNS client in InterNiche NicheStack TCP/IP 4.0.1 is affected by: Insufficient entropy in the DNS transaction id. The impact is: DNS cache poisoning (remote). The component is: dns_query_type(). The attack vector is: a specific DNS response packet.

  • CVE-2020-28924HigNov 19, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Rclone before 1.53.3. Due to the use of a weak random number generator, the password generator has been producing weak passwords with much less entropy than advertised. The suggested passwords depend deterministically on the time the second rclone was…

  • CVE-2020-11957HigJun 9, 2020
    risk 0.49cvss 7.5epss 0.00

    The Bluetooth Low Energy implementation in Cypress PSoC Creator BLE 4.2 component versions before 3.64 generates a random number (Pairing Random) with significantly less entropy than the specified 128 bits during BLE pairing. This is the case for both authenticated and…

  • CVE-2019-10064HigFeb 28, 2020
    risk 0.49cvss 7.5epss 0.04

    hostapd before 2.6, in EAP mode, makes calls to the rand() and random() standard library functions without any preceding srand() or srandom() call, which results in inappropriate use of deterministic values. This was fixed in conjunction with CVE-2016-10743.

  • CVE-2019-15703HigOct 24, 2019
    risk 0.49cvss 7.5epss 0.01

    An Insufficient Entropy in PRNG vulnerability in Fortinet FortiOS 6.2.1, 6.2.0, 6.0.8 and below for device not enable hardware TRNG token and models not support builtin TRNG seed allows attacker to theoretically recover the long term ECDSA secret in a TLS client with a RSA…

  • CVE-2019-15847HigSep 2, 2019
    risk 0.49cvss 7.5epss 0.03

    The POWER9 backend in GNU Compiler Collection (GCC) before version 10 could optimize multiple calls of the __builtin_darn intrinsic into a single call, thus reducing the entropy of the random number generator. This occurred because a volatile operation was not specified. For…

  • CVE-2015-3405HigAug 9, 2017
    risk 0.49cvss 7.5epss 0.05

    ntp-keygen in ntp 4.2.8px before 4.2.8p2-RC2 and 4.3.x before 4.3.12 does not generate MD5 keys with sufficient entropy on big endian machines when the lowest order byte of the temp variable is between 0x20 and 0x7f and not #, which might allow remote attackers to obtain the…

  • CVE-2017-0897HigJun 22, 2017
    risk 0.49cvss 7.5epss 0.04

    ExpressionEngine version 2.x < 2.11.8 and version 3.x < 3.5.5 create an object signing token with weak entropy. Successfully guessing the token can lead to remote code execution.