CWE-326
467 CVEs • Abstraction: Class
Inadequate Encryption Strength
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
CVEs (467)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Inadequate encryption strength in mycli 1.27.0 allows attackers to view sensitive information via /mycli/config.py |
An issue discovered in IXP Data EasyInstall 6.6.14907.0 allows attackers to gain escalated privileges via static Cryptographic Key. |
1Eaton 22Easy Box E4 Ac1 Firmware Easy Box E4 Dc1 FirmwareEasy Box E4 Uc1 Firmware+19 moreJun 17, 2026 Oct 17, 2023 N/A· v4 6.6 MEDIUM· v3 N/A· v2 Eaton easyE4 PLC offers a device password protection functionality to facilitate a secure connection and prevent unauthorized access. It was observed that the device password was stored with a weak encoding algorithm in...Show more |
Dell Data Protection Central, version 19.9, contains an Inadequate Encryption Strength Vulnerability. An unauthenticated network attacker could potentially exploit this vulnerability, allowing an attacker to recover pla...Show more |
Vulnerability of 5G messages being sent without being encrypted in a VPN environment in the SMS message module. Successful exploitation of this vulnerability may affect confidentiality. |
An issue was discovered in Stormshield SSL VPN Client before 3.2.0. If multiple address books are used, an attacker may be able to access the other encrypted address book. |
An inadequate encryption strength vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows local network clients to decrypt the data using brute force attacks via...Show more |
1Broadcom 1Raid Controller Web Interface Jun 17, 2026 Aug 15, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Broadcom RAID Controller web interface doesn’t enforce SSL cipher ordering by server |
1Mitsubishielectric 8Gs21 Firmware Gs25 FirmwareGt21 Firmware+5 moreJun 17, 2026 Aug 4, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Weak Encoding for Password vulnerability in Mitsubishi Electric Corporation GOT2000 Series GT27 model versions 01.49.000 and prior, GT25 model versions 01.49.000 and prior, GT23 model versions 01.49.000 and prior, GT21 m...Show more |
The BigFix WebUI uses weak cipher suites.
|
In updatePictureInPictureMode of ActivityRecord.java, there is a possible bypass of background launch restrictions due to a logic error in the code. This could lead to local escalation of privilege with no additional exe...Show more |
In openMmapStream of AudioFlinger.cpp, there is a possible way to record audio without displaying the microphone privacy indicator due to a logic error in the code. This could lead to local escalation of privilege with n...Show more |
A vulnerability in the Cisco ACI Multi-Site CloudSec encryption feature of Cisco Nexus 9000 Series Fabric Switches in ACI mode could allow an unauthenticated, remote attacker to read or modify intersite encrypted traffic...Show more |
1Microsoft 12Windows 10 1507 Windows 10 1607Windows 10 1809+9 moreJun 17, 2026 Jul 11, 2023 N/A· v4 6.8 MEDIUM· v3 N/A· v2 Windows Remote Desktop Protocol Security Feature Bypass |
1Siemens 11Ruggedcom Rox Mx5000 Firmware Ruggedcom Rox Mx5000re FirmwareRuggedcom Rox Rx1400 Firmware+8 moreJun 17, 2026 Jul 11, 2023 N/A· v4 6.8 MEDIUM· v3 N/A· v2 A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V...Show more |
AMI SPx contains a vulnerability in the BMC where a user may cause an inadequate encryption strength by hash-based message authentication code (HMAC). A successful exploit of this vulnerability may lead to a loss of con...Show more |
An issue was discovered in SubmitEntityAction in Wikibase in MediaWiki through 1.39.3. Because it doesn't use EditEntity for undo and restore, the intended interaction with AbuseFilter does not occur. |
1Zoom 9Meetings Poly Ccx 600 FirmwarePoly Ccx 700 Firmware+6 moreJun 17, 2026 Jun 30, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Exposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information. |
1Honeywell 1Alerton Bcm Web Firmware Jun 17, 2026 Jun 28, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 ** UNSUPPORTED WHEN ASSIGNED ** [An attacker can capture an authenticating hash and utilize it to create new sessions. The hash is also a poorly salted MD5 hash, which could result in a successful brute force password a...Show more |
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.4. An app may be able to break out of its sandbox. |