VYPR

CWE-338

Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)

BaseDraftLikelihood: Medium

Description

The product uses a Pseudo-Random Number Generator (PRNG) in a security context, but the PRNG's algorithm is not cryptographically strong.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (218)

page 9 of 11
  • CVE-2021-23126MedMar 4, 2021
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Joomla! 3.2.0 through 3.9.24. Usage of the insecure rand() function within the process of generating the 2FA secret.

  • CVE-2012-6124MedOct 31, 2019
    risk 0.35cvss 5.3epss 0.01

    A casting error in Chicken before 4.8.0 on 64-bit platform caused the random number generator to return a constant value. NOTE: the vendor states "This function wasn't used for security purposes (and is advertised as being unsuitable)."

  • CVE-2026-9692MedJun 18, 2026
    risk 0.34cvss 5.3epss 0.00

    Mojolicious::Sessions::Storable versions through 0.05 for Perl generate session ids insecurely. The default session id generator returns a SHA-1 hash seeded with the built-in rand function, the epoch time, the heap address of an anonymous hash, and the PID. These are…

  • CVE-2026-6146MedMay 11, 2026
    risk 0.34cvss 5.3epss 0.00

    Amazon::Credentials versions through 1.2.0 for Perl uses rand to generate encryption keys. Amazon::Credentials stores credentials in an obfuscated form to prevent access to the secrets from a data dump of the object. Before version 1.3.0, the secrets were encrypted using a…

  • CVE-2026-5083MedApr 8, 2026
    risk 0.34cvss 5.3epss 0.00

    Ado::Sessions versions through 0.935 for Perl generates insecure session ids. The session id is generated from a SHA-1 hash seeded with the built-in rand function, the epoch time, and the PID. The PID will come from a small set of numbers, and the epoch time may be guessed, if…

  • CVE-2026-5082MedApr 8, 2026
    risk 0.34cvss 5.3epss 0.00

    Amon2::Plugin::Web::CSRFDefender versions from 7.00 through 7.03 for Perl generate an insecure session id. The generate_session_id function will attempt to read bytes from the /dev/urandom device, but if that is unavailable then it generates bytes using SHA-1 hash seeded with…

  • CVE-2025-1805MedApr 2, 2025
    risk 0.34cvss 5.3epss 0.00

    Crypt::Salt for Perl version 0.01 uses insecure rand() function when generating salts for cryptographic purposes.

  • CVE-2025-21617MedJan 6, 2025
    risk 0.34cvss —epss 0.00

    Guzzle OAuth Subscriber signs Guzzle requests using OAuth 1.0. Prior to 0.8.1, Nonce generation does not use sufficient entropy nor a cryptographically secure pseudorandom source. This can leave servers vulnerable to replay attacks when TLS is not used. This vulnerability is…

  • CVE-2024-53702MedDec 5, 2024
    risk 0.34cvss 5.3epss 0.00

    Use of cryptographically weak pseudo-random number generator (PRNG) vulnerability in the SonicWall SMA100 SSLVPN backup code generator that, in certain cases, can be predicted by an attacker, potentially exposing the generated secret.

  • CVE-2023-50059MedApr 30, 2024
    risk 0.34cvss 5.3epss 0.00

    An issue ingalxe.com Galxe platform 1.0 allows a remote attacker to obtain sensitive information via the Web3 authentication process of Galxe, the signed message lacks a nonce (random number)

  • CVE-2022-41210MedOct 11, 2022
    risk 0.34cvss 5.2epss 0.00

    SAP Customer Data Cloud (Gigya mobile app for Android) - version 7.4, uses insecure random number generator program which makes it easy for the attacker to predict future random numbers. This can lead to information disclosure and modification of certain user settings.

  • CVE-2019-19794MedDec 13, 2019
    risk 0.32cvss 5.9epss 0.02

    The miekg Go DNS package before 1.1.25, as used in CoreDNS before 1.6.6 and other products, improperly generates random numbers because math/rand is used. The TXID becomes predictable, leading to response forgeries.

  • CVE-2026-8647MedMay 26, 2026
    risk 0.31cvss 4.8epss 0.00

    Crypt::ScryptKDF versions through 0.010 for Perl uses insecure random number source when no CSPRNG module is available. The random_bytes function fell back to using the built-in rand() function when none of the Perl modules Crypt::PRNG, Crypt::OpenSSL::Random, Net::SSLeay,…

  • CVE-2026-40975MedApr 28, 2026
    risk 0.31cvss 4.8epss 0.00

    Values produced by ${random.value} are not suitable for use as secrets. ${random.uuid} is not affected. ${random.int} and ${random.long} should never be used for secrets as they are numeric values with a predictable range. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6),…

  • CVE-2024-45751MedSep 6, 2024
    risk 0.31cvss 5.9epss 0.01

    tgt (aka Linux target framework) before 1.0.93 attempts to achieve entropy by calling rand without srand. The PRNG seed is always 1, and thus the sequence of challenges is always identical.

  • CVE-2022-23472MedDec 6, 2022
    risk 0.31cvss 5.9epss 0.01

    Passeo is an open source python password generator. Versions prior to 1.0.5 rely on the python `random` library for random value selection. The python `random` library warns that it should not be used for security purposes due to its reliance on a non-cryptographically secure…

  • CVE-2021-3678MedAug 4, 2021
    risk 0.31cvss 5.9epss 0.01

    showdoc is vulnerable to Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)

  • CVE-2021-3692MedAug 10, 2021
    risk 0.28cvss 5.3epss 0.02

    yii2 is vulnerable to Use of Predictable Algorithm in Random Number Generator

  • CVE-2019-8113MedNov 5, 2019
    risk 0.28cvss 5.3epss 0.01

    Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1 uses cryptographically weak random number generator to brute-force the confirmation code for customer registration.

  • CVE-2019-7855MedAug 2, 2019
    risk 0.28cvss 5.3epss 0.01

    A cryptograhic flaw in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 could be abused by an unauthenticated user to discover an invariant used in gift card generation.