VYPR

CWE-331

Insufficient Entropy

BaseDraft

Description

The product uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-59

CVEs mapped to this weakness (147)

page 5 of 8
  • CVE-2026-22698HigJan 10, 2026
    risk 0.42cvss 7.5epss 0.00

    RustCrypto: Elliptic Curves is general purpose Elliptic Curve Cryptography (ECC) support, including types and traits for representing various elliptic curve forms, scalars, points, and public/secret keys composed thereof. In versions 0.14.0-pre.0 and 0.14.0-rc.0, a critical…

  • CVE-2024-56370MedApr 5, 2025
    risk 0.42cvss 6.5epss 0.00

    Net::Xero 0.044 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions. Specifically Net::Xero uses the Data::Random library which specifically states that it is "Useful mostly for test…

  • CVE-2015-3006MedFeb 28, 2020
    risk 0.42cvss 6.5epss 0.01

    On the QFX3500 and QFX3600 platforms, the number of bytes collected from the RANDOM_INTERRUPT entropy source when the device boots up is insufficient, possibly leading to weak or duplicate SSH keys or self-signed SSL/TLS certificates. Entropy increases after the system has been…

  • CVE-2015-8851HigJan 30, 2020
    risk 0.42cvss 7.5epss 0.02

    node-uuid before 1.4.4 uses insufficiently random data to create a GUID, which could make it easier for attackers to have unspecified impact via brute force guessing.

  • CVE-2019-14806HigAug 9, 2019
    risk 0.42cvss 7.5epss 0.02

    Pallets Werkzeug before 0.15.3, when used with Docker, has insufficient debugger PIN randomness because Docker containers share the same machine id.

  • CVE-2015-7764HigAug 9, 2017
    risk 0.42cvss 7.5epss 0.02

    Lemur 0.1.4 does not use sufficient entropy in its IV when encrypting AES in CBC mode.

  • CVE-2017-6030MedJun 30, 2017
    risk 0.42cvss 6.5epss 0.02

    A predictable value range from previous values issue was discovered in Schneider Electric Modicon PLCs Modicon M221, firmware versions prior to Version 1.5.0.0, Modicon M241, firmware versions prior to Version 4.0.5.11, and Modicon M251, firmware versions prior to Version…

  • CVE-2016-2858MedApr 7, 2016
    risk 0.42cvss 6.5epss 0.00

    QEMU, when built with the Pseudo Random Number Generator (PRNG) back-end support, allows local guest OS users to cause a denial of service (process crash) via an entropy request, which triggers arbitrary stack based allocation and memory corruption.

  • CVE-2024-26329MedApr 5, 2024
    risk 0.40cvss 6.2epss 0.00

    Chilkat before v9.5.0.98, allows attackers to obtain sensitive information via predictable PRNG in ChilkatRand::randomBytes function.

  • CVE-2025-14261HigDec 8, 2025
    risk 0.39cvss 7.1epss 0.00

    The Litmus platform uses JWT for authentication and authorization, but the secret being used for signing the JWT is only 6 bytes long at its core, which makes it extremely easy to crack.

  • CVE-2022-43755HigFeb 7, 2023
    risk 0.39cvss 7.1epss 0.02

    A Insufficient Entropy vulnerability in SUSE Rancher allows attackers that gained knowledge of the cattle-token to continue abusing this even after the token was renewed. This issue affects: SUSE Rancher Rancher versions prior to 2.6.10; Rancher versions prior to 2.7.1.

  • CVE-2025-54885MedAug 7, 2025
    risk 0.38cvss —epss 0.00

    Thinbus Javascript Secure Remote Password is a browser SRP6a implementation for zero-knowledge password authentication. In versions 2.0.0 and below, a protocol compliance bug causes the client to generate a fixed 252 bits of entropy instead of the intended bit length of the safe…

  • CVE-2023-38357MedAug 1, 2023
    risk 0.38cvss 5.3epss 0.05

    Session tokens in RWS WorldServer 11.7.3 and earlier have a low entropy and can be enumerated, leading to unauthorized access to user sessions.

  • CVE-2023-36610MedJul 3, 2023
    risk 0.38cvss 5.9epss 0.01

    ​The affected TBox RTUs generate software security tokens using insufficient entropy. The random seed used to generate the software tokens is not initialized correctly, and other parts of the token are generated using predictable time-based values. An attacker with this…

  • CVE-2022-34746MedSep 20, 2022
    risk 0.38cvss 5.9epss 0.00

    An insufficient entropy vulnerability caused by the improper use of randomness sources with low entropy for RSA key pair generation was found in Zyxel GS1900 series firmware versions prior to V2.70. This vulnerability could allow an unauthenticated attacker to retrieve a private…

  • CVE-2016-2564MedApr 23, 2017
    risk 0.38cvss 5.9epss 0.01

    Invision Power Services (IPS) Community Suite before 4.1.9 makes session hijack easier by relying on the PHP uniqid function without the more_entropy flag. Attackers can guess an Invision Power Board session cookie if they can predict the exact time of cookie generation.

  • CVE-2024-52322MedApr 5, 2025
    risk 0.36cvss 5.5epss 0.00

    WebService::Xero 0.11 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions. Specifically WebService::Xero uses the Data::Random library which specifically states that it is "Useful…

  • CVE-2024-58036MedApr 5, 2025
    risk 0.36cvss 5.5epss 0.00

    Net::Dropbox::API 1.9 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions. Specifically Net::Dropbox::API uses the Data::Random library which specifically states that it is "Useful…

  • CVE-2024-57868MedApr 5, 2025
    risk 0.36cvss 5.5epss 0.00

    Web::API 2.8 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions. Specifically Web::API uses the Data::Random library which specifically states that it is "Useful mostly for test…

  • CVE-2021-3505MedApr 19, 2021
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in libtpms in versions before 0.8.0. The TPM 2 implementation returns 2048 bit keys with ~1984 bit strength due to a bug in the TCG specification. The bug is in the key creation algorithm in RsaAdjustPrimeCandidate(), which is called before the prime number…