← Back
CWE-326

455 CVEs • Abstraction: Class

Inadequate Encryption Strength

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

JSON object

Loading...

CVEs (455)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Arm
Trustedfirmware
2Mbed Tls
Mbed Tls
Jun 17, 2026
Apr 3, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue was discovered in Mbed TLS 3.5.x before 3.6.0. When an SSL context was reset with the mbedtls_ssl_session_reset() API, the maximum TLS version to be negotiated was not restored to the configured one. An attacker...Show more
An issue was discovered in Mbed TLS 3.5.x before 3.6.0. When an SSL context was reset with the mbedtls_ssl_session_reset() API, the maximum TLS version to be negotiated was not restored to the configured one. An attacker was able to prevent an Mbed TLS server from establishing any TLS 1.3 connection, potentially resulting in a Denial of Service or forced version downgrade from TLS 1.3 to TLS 1.2.Show less
1Cilium
1Cilium
Jun 17, 2026
Mar 27, 2024
N/A· v4
6.8 MEDIUM· v3
N/A· v2
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Users of IPsec transparent encryption in Cilium may be vulnerable to cryptographic attacks that render the transparent encryption...Show more
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Users of IPsec transparent encryption in Cilium may be vulnerable to cryptographic attacks that render the transparent encryption ineffective. In particular, Cilium is vulnerable to chosen plaintext, key recovery, replay attacks by a man-in-the-middle attacker. These attacks are possible due to an ESP sequence number collision when multiple nodes are configured with the same key. Fixed versions of Cilium use unique keys for each IPsec tunnel established between nodes, resolving all of the above attacks. This vulnerability is fixed in 1.13.13, 1.14.9, and 1.15.3.Show less
1Ibm
1Security Verify Directory
Jun 17, 2026
Mar 22, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
IBM Security Verify Directory 10.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 228444.
-
-
Jun 17, 2026
Mar 6, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
This vulnerability exists in AppSamvid software due to the usage of a weaker cryptographic algorithm (hash) SHA1 in user login component. An attacker with local administrative privileges could exploit this to obtain the...Show more
This vulnerability exists in AppSamvid software due to the usage of a weaker cryptographic algorithm (hash) SHA1 in user login component. An attacker with local administrative privileges could exploit this to obtain the password of AppSamvid on the targeted system. Successful exploitation of this vulnerability could allow the attacker to take complete control of the application on the targeted system.Show less
-
-
Jun 17, 2026
Mar 6, 2024
N/A· v4
7.1 HIGH· v3
N/A· v2
This vulnerability exists in USB Pratirodh due to the usage of a weaker cryptographic algorithm (hash) SHA1 in user login component. A local attacker with administrative privileges could exploit this vulnerability to obt...Show more
This vulnerability exists in USB Pratirodh due to the usage of a weaker cryptographic algorithm (hash) SHA1 in user login component. A local attacker with administrative privileges could exploit this vulnerability to obtain the password of USB Pratirodh on the targeted system. Successful exploitation of this vulnerability could allow the attacker to take control of the application and modify the access control of registered users or devices on the targeted system. Show less
2Alpha Innotec
Novelan
2Heat Pumps Firmware
Heat Pumps Firmware
Jun 17, 2026
Jan 30, 2024
N/A· v4
6.8 MEDIUM· v3
N/A· v2
An issue fixed in AIT-Deutschland Alpha Innotec Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later and Novelan Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later, allows remote attackers to execut...Show more
An issue fixed in AIT-Deutschland Alpha Innotec Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later and Novelan Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later, allows remote attackers to execute arbitrary code via the password component in the shadow file.Show less
1Linuxfoundation
1Dex
Jun 17, 2026
Jan 25, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Dex is an identity service that uses OpenID Connect to drive authentication for other apps. Dex 2.37.0 serves HTTPS with insecure TLS 1.0 and TLS 1.1. `cmd/dex/serve.go` line 425 seemingly sets TLS 1.2 as minimum version...Show more
Dex is an identity service that uses OpenID Connect to drive authentication for other apps. Dex 2.37.0 serves HTTPS with insecure TLS 1.0 and TLS 1.1. `cmd/dex/serve.go` line 425 seemingly sets TLS 1.2 as minimum version, but the whole `tlsConfig` is ignored after `TLS cert reloader` was introduced in v2.37.0. Configured cipher suites are not respected either. This issue is fixed in Dex 2.38.0.Show less
1Lantronix
1Xport Edge Firmware
Jun 17, 2026
Jan 23, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Lantronix XPort sends weakly encoded credentials within web request headers.
1Microsoft
14Windows 10 1507
Windows 10 1607Windows 10 1809+11 more
Jun 17, 2026
Jan 9, 2024
N/A· v4
5.7 MEDIUM· v3
N/A· v2
Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
1Assaabloy
1Yale Keyless Smart Lock Firmware
Jun 17, 2026
Dec 5, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Weak encryption mechanisms in RFID Tags in Yale Keyless Lock v1.0 allows attackers to create a cloned tag via physical proximity to the original.
1Assaabloy
1Yale Ia 210 Firmware
Jun 17, 2026
Dec 5, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Weak encryption mechanisms in RFID Tags in Yale IA-210 Alarm v1.0 allows attackers to create a cloned tag via physical proximity to the original.
1Assaabloy
1Yale Conexis L1 Firmware
Jun 17, 2026
Dec 5, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Weak encryption mechanisms in RFID Tags in Yale Conexis L1 v1.1.0 allows attackers to create a cloned tag via physical proximity to the original.
1Preh
1Mib3 Firmware
Jun 17, 2026
Dec 1, 2023
N/A· v4
2.4 LOW· v3
N/A· v2
Access to critical Unified Diagnostics Services (UDS) of the Modular Infotainment Platform 3 (MIB3) infotainment is transmitted via Controller Area Network (CAN) bus in a form that can be easily decoded by attackers with...Show more
Access to critical Unified Diagnostics Services (UDS) of the Modular Infotainment Platform 3 (MIB3) infotainment is transmitted via Controller Area Network (CAN) bus in a form that can be easily decoded by attackers with physical access to the vehicle. Vulnerability discovered on Škoda Superb III (3V3) - 2.0 TDI manufactured in 2022. Show less
1Acer
1Sk 9662 Firmware
Jun 17, 2026
Nov 27, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An issue discovered in Acer Wireless Keyboard SK-9662 allows attacker in physical proximity to both decrypt wireless keystrokes and inject arbitrary keystrokes via use of weak encryption.
1Carglglz
1Upydev
Jun 17, 2026
Nov 20, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue in /upydev/keygen.py in upydev v0.4.3 allows attackers to decrypt sensitive information via weak encryption padding.
1Elecom
34Lan W300n/p Firmware
Lan W300n/rs FirmwareLan W301nr Firmware+31 more
Jun 17, 2026
Nov 16, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Inadequate encryption strength vulnerability in multiple routers provided by ELECOM CO.,LTD. and LOGITEC CORPORATION allows a network-adjacent unauthenticated attacker to guess the encryption key used for wireless LAN co...Show more
Inadequate encryption strength vulnerability in multiple routers provided by ELECOM CO.,LTD. and LOGITEC CORPORATION allows a network-adjacent unauthenticated attacker to guess the encryption key used for wireless LAN communication and intercept the communication. As for the affected products/versions, see the information provided by the vendor under [References] section.Show less
1Espressif
1Esptool
Jun 17, 2026
Nov 9, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue discovered in esptool 4.6.2 allows attackers to view sensitive information via weak cryptographic algorithm.
1Linecorp
1Line
Jun 17, 2026
Nov 9, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The leakage of channel access token in DRAGON FAMILY Line 13.6.1 allows remote attackers to send malicious notifications to victims.
1Linecorp
1Line
Jun 17, 2026
Nov 9, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The leakage of channel access token in UPDATESALON C-LOUNGE Line 13.6.1 allows remote attackers to send malicious notifications to victims.
1Linecorp
1Line
Jun 17, 2026
Nov 9, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The leakage of channel access token in bluetrick Line 13.6.1 allows remote attackers to send malicious notifications to victims.