VYPR

CWE-331

Insufficient Entropy

BaseDraft

Description

The product uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-59

CVEs mapped to this weakness (138)

page 4 of 7
  • CVE-2001-0950HigDec 4, 2001
    risk 0.49cvss 7.5epss 0.02

    ValiCert Enterprise Validation Authority (EVA) Administration Server 3.3 through 4.2.1 uses insufficiently random data to (1) generate session tokens for HSMs using the C rand function, or (2) generate certificates or keys using /dev/urandom instead of another source which…

  • CVE-2020-1773HigMar 27, 2020
    risk 0.48cvss 7.3epss 0.01

    An attacker with the ability to generate session IDs or password reset tokens, either by being able to authenticate or by exploiting OSA-2020-09, may be able to predict other users session IDs, password reset tokens and automatically generated passwords. This issue affects…

  • CVE-2018-10240HigMay 16, 2018
    risk 0.48cvss 7.3epss 0.01

    SolarWinds Serv-U MFT before 15.1.6 HFv1 assigns authenticated users a low-entropy session token that can be included in requests to the application as a URL parameter in lieu of a session cookie. This session token's value can be brute-forced by an attacker to obtain the…

  • CVE-2014-0691HigOct 24, 2017
    risk 0.48cvss 7.3epss 0.01

    Cisco WebEx Meetings Server before 1.1 uses meeting IDs with insufficient entropy, which makes it easier for remote attackers to bypass authentication and join arbitrary meetings without a password, aka Bug ID CSCuc79643.

  • CVE-2026-8700HigMay 15, 2026
    risk 0.47cvss 7.3epss 0.00

    Crypt::DSA versions before 1.20 for Perl generate seeds using rand. Seeds were generated using Perl's built-in rand function, which is predictable and unsuitable for security usage.

  • CVE-2022-31034HigJun 27, 2022
    risk 0.47cvss 8.3epss 0.01

    Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting with v0.11.0 are vulnerable to a variety of attacks when an SSO login is initiated from the Argo CD CLI or UI. The vulnerabilities are due to the use of insufficiently…

  • CVE-2021-42138HigDec 20, 2021
    risk 0.47cvss 7.2epss 0.01

    A user of a machine protected by SafeNet Agent for Windows Logon may leverage weak entropy to access the encrypted credentials of any or all the users on that machine.

  • CVE-2026-34236HigApr 1, 2026
    risk 0.46cvss 8.2epss 0.00

    Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. From version 8.0.0 to before version 8.19.0, in applications built with the Auth0 PHP SDK, cookies are encrypted with insufficient entropy, which may result in threat actors brute-forcing the encryption key and…

  • CVE-2023-3325HigJun 20, 2023
    risk 0.46cvss 8.1epss 0.01

    The CMS Commander plugin for WordPress is vulnerable to authorization bypass due to the use of an insufficiently unique cryptographic signature on the 'cmsc_add_site' function in versions up to, and including, 2.287. This makes it possible for unauthenticated attackers to the…

  • CVE-2022-43755HigFeb 7, 2023
    risk 0.46cvss 7.1epss 0.02

    A Insufficient Entropy vulnerability in SUSE Rancher allows attackers that gained knowledge of the cattle-token to continue abusing this even after the token was renewed. This issue affects: SUSE Rancher Rancher versions prior to 2.6.10; Rancher versions prior to 2.7.1.

  • CVE-2020-29505HigJul 11, 2022
    risk 0.46cvss 7.1epss 0.01

    Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain a Key Management Error Vulnerability.

  • CVE-2026-1814MedFeb 3, 2026
    risk 0.44cvss epss 0.00

    Rapid7 Nexpose versions 6.4.50 and later are vulnerable to an insufficient entropy issue in the CredentialsKeyStorePassword.generateRandomPassword() method. When updating legacy keystore passwords, the application generates a new password with insufficient length (7-12…

  • CVE-2024-20331MedOct 23, 2024
    risk 0.44cvss 6.8epss 0.01

    A vulnerability in the session authentication functionality of the Remote Access SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to prevent users from…

  • CVE-2024-22473MedFeb 21, 2024
    risk 0.44cvss 6.8epss 0.00

    TRNG is used before initialization by ECDSA signing driver when exiting EM2/EM3 on Virtual Secure Vault (VSE) devices. This defect may allow Signature Spoofing by Key Recreation.This issue affects Gecko SDK through v4.4.0.

  • CVE-2026-46473HigMay 21, 2026
    risk 0.42cvss 7.5epss 0.00

    Authen::TOTP versions before 0.1.1 for Perl generate secrets using rand. Secrets were generated using Perl's built-in rand function, which is predictable and unsuitable for security usage.

  • CVE-2026-7210HigMay 11, 2026
    risk 0.42cvss 7.5epss 0.01

    `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying…

  • CVE-2026-2541MedFeb 15, 2026
    risk 0.42cvss epss 0.00

    The Micca KE700 system relies on a 6-bit portion of an identifier for authentication within rolling codes, providing only 64 possible combinations. This low entropy allows an attacker to perform a brute-force attack against one component of the rolling code. Successful…

  • CVE-2026-22698HigJan 10, 2026
    risk 0.42cvss 7.5epss 0.00

    RustCrypto: Elliptic Curves is general purpose Elliptic Curve Cryptography (ECC) support, including types and traits for representing various elliptic curve forms, scalars, points, and public/secret keys composed thereof. In versions 0.14.0-pre.0 and 0.14.0-rc.0, a critical…

  • CVE-2024-56370MedApr 5, 2025
    risk 0.42cvss 6.5epss 0.00

    Net::Xero 0.044 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions. Specifically Net::Xero uses the Data::Random library which specifically states that it is "Useful mostly for test…

  • CVE-2015-3006MedFeb 28, 2020
    risk 0.42cvss 6.5epss 0.01

    On the QFX3500 and QFX3600 platforms, the number of bytes collected from the RANDOM_INTERRUPT entropy source when the device boots up is insufficient, possibly leading to weak or duplicate SSH keys or self-signed SSL/TLS certificates. Entropy increases after the system has been…