CWE-326
455 CVEs • Abstraction: Class
Inadequate Encryption Strength
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
CVEs (455)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The leakage of channel access token in taketorinoyu Line 13.6.1 allows remote attackers to send malicious notifications to victims. |
The leakage of channel access token in best_training_member Line 13.6.1 allows remote attackers to send malicious notifications. |
The leakage of channel access token in platinum clinic Line 13.6.1 allows remote attackers to send malicious notifications to victims. |
The leakage of channel access token in craft_members Line 13.6.1 allows remote attackers to send malicious notifications to victims. |
The leakage of channel access token in Lil.OFF-PRICE STORE Line 13.6.1 allows remote attackers to send malicious notifications to victims. |
The leakage of channel access token in nagaoka taxi Line 13.6.1 allows remote attackers to send malicious notifications to victims |
The leakage of channel access token in F.B.P members Line 13.6.1 allows remote attackers to send malicious notifications to victims. |
Weak ciphers in Softing smartLink SW-HT before 1.30 are enabled during secure communication (SSL). |
Inadequate encryption strength in mycli 1.27.0 allows attackers to view sensitive information via /mycli/config.py |
An issue discovered in IXP Data EasyInstall 6.6.14907.0 allows attackers to gain escalated privileges via static Cryptographic Key. |
1Eaton 22Easy Box E4 Ac1 Firmware Easy Box E4 Dc1 FirmwareEasy Box E4 Uc1 Firmware+19 moreJun 17, 2026 Oct 17, 2023 N/A· v4 6.6 MEDIUM· v3 N/A· v2 Eaton easyE4 PLC offers a device password protection functionality to facilitate a secure connection and prevent unauthorized access. It was observed that the device password was stored with a weak encoding algorithm in...Show more |
Dell Data Protection Central, version 19.9, contains an Inadequate Encryption Strength Vulnerability. An unauthenticated network attacker could potentially exploit this vulnerability, allowing an attacker to recover pla...Show more |
Vulnerability of 5G messages being sent without being encrypted in a VPN environment in the SMS message module. Successful exploitation of this vulnerability may affect confidentiality. |
An issue was discovered in Stormshield SSL VPN Client before 3.2.0. If multiple address books are used, an attacker may be able to access the other encrypted address book. |
An inadequate encryption strength vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows local network clients to decrypt the data using brute force attacks via...Show more |
1Broadcom 1Raid Controller Web Interface Jun 17, 2026 Aug 15, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Broadcom RAID Controller web interface doesn’t enforce SSL cipher ordering by server |
1Mitsubishielectric 8Gs21 Firmware Gs25 FirmwareGt21 Firmware+5 moreJun 17, 2026 Aug 4, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Weak Encoding for Password vulnerability in Mitsubishi Electric Corporation GOT2000 Series GT27 model versions 01.49.000 and prior, GT25 model versions 01.49.000 and prior, GT23 model versions 01.49.000 and prior, GT21 m...Show more |
The BigFix WebUI uses weak cipher suites.
|
In updatePictureInPictureMode of ActivityRecord.java, there is a possible bypass of background launch restrictions due to a logic error in the code. This could lead to local escalation of privilege with no additional exe...Show more |
In openMmapStream of AudioFlinger.cpp, there is a possible way to record audio without displaying the microphone privacy indicator due to a logic error in the code. This could lead to local escalation of privilege with n...Show more |