VYPR

CWE-334

Small Space of Random Values

BaseDraft

Description

The number of possible random values is smaller than needed by the product, making it more susceptible to brute force attacks.

Hierarchy (View 1000)

Parents

Children

CVEs mapped to this weakness (14)

  • CVE-2023-39979CriSep 2, 2023
    risk 0.64cvss 9.8epss 0.01

    There is a vulnerability in MXsecurity versions prior to 1.0.1 that can be exploited to bypass authentication. A remote attacker might access the system if the web service authenticator has insufficient random values.  

  • CVE-2025-3895CriMay 23, 2025
    risk 0.59cvss epss 0.00

    Token used for resetting passwords in MegaBIP software are generated using a small space of random values combined with a queryable value. It allows an unauthenticated attacker who know user login names to brute force these tokens and change account passwords (including these…

  • CVE-2024-6890HigAug 7, 2024
    risk 0.57cvss 8.8epss 0.01

    Password reset tokens are generated using an insecure source of randomness. Attackers who know the username of the Journyx installation user can bruteforce the password reset and change the administrator password.

  • CVE-2022-24402HigOct 19, 2023
    risk 0.57cvss 8.8epss 0.01

    The TETRA TEA1 keystream generator implements a key register initialization function that compresses the 80-bit key to only 32 bits for usage during the keystream generation phase, which is insufficient to safeguard against exhaustive search attacks.

  • CVE-2026-71851CriAug 7, 2026
    risk 0.52cvss 9.0epss 0.00

    crypto-js is a JavaScript library of crypto standards. Versions of crypto-js prior to 4.0.0 generate randomness in CryptoJS.lib.WordArray.random() using a custom variation of the Multiply-With-Carry pseudorandom number generator, seeded from Math.random(), instead of a…

  • CVE-2022-22517HigApr 7, 2022
    risk 0.49cvss 7.5epss 0.01

    An unauthenticated, remote attacker can disrupt existing communication channels between CODESYS products by guessing a valid channel ID and injecting packets. This results in the communication channel to be closed.

  • CVE-2021-21955HigDec 9, 2021
    risk 0.49cvss 7.5epss 0.01

    An authentication bypass vulnerability exists in the get_aes_key_info_by_packetid() function of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h. Generic network sniffing can lead to password recovery. An attacker can sniff network traffic to trigger this vulnerability.

  • CVE-2020-7566HigNov 19, 2020
    risk 0.47cvss 7.3epss 0.00

    A CWE-334: Small Space of Random Values vulnerability exists in Modicon M221 (all references, all versions) that could allow the attacker to break the encryption keys when the attacker has captured the traffic between EcoStruxure Machine - Basic software and Modicon M221…

  • CVE-2023-6951MedApr 2, 2024
    risk 0.43cvss 6.6epss 0.00

    A Use of Weak Credentials vulnerability affecting the Wi-Fi network generated by a set of DJI drones could allow a remote attacker to derive the WPA2 PSK key and authenticate without permission to the drone’s Wi- Fi network. This, in turn, allows the attacker to perform…

  • CVE-2024-52616MedNov 21, 2024
    risk 0.35cvss 5.3epss 0.01

    A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementing them sequentially after that. This predictable behavior facilitates DNS spoofing attacks, allowing attackers to guess transaction IDs.

  • CVE-2022-20941MedNov 15, 2022
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to access sensitive information. This vulnerability is due to missing authorization for certain resources in the web-based…

  • CVE-2022-33707MedJul 12, 2022
    risk 0.35cvss 5.3epss 0.01

    Improper identifier creation logic in Find My Mobile prior to version 7.2.24.12 allows attacker to identify the device.

  • CVE-2024-54017MedMay 12, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V11.0), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 6MD85 (CP300) (All versions >= V7.80 < V11.0), SIPROTEC 5 6MD86 (CP200) (All versions), SIPROTEC 5 6MD86 (CP300) (All versions >= V7.80 <…

  • CVE-2024-51720MedNov 12, 2024
    risk 0.31cvss 4.8epss 0.00

    An insufficient entropy vulnerability in the SecuSUITE Secure Client Authentication (SCA) Server of SecuSUITE versions 5.0.420 and earlier could allow an attacker to potentially enroll an attacker-controlled device to the victim’s account and telephone number.