CWE-326
455 CVEs • Abstraction: Class
Inadequate Encryption Strength
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
CVEs (455)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Improper usage of symmetric encryption in UI Desktop for Windows (Version 0.59.1.71 and earlier) could allow users with access to UI Desktop configuration files to decrypt their content.This vulnerability is fixed in Ver...Show more |
1Electra Air 1Central Ac Unit Firmware Jun 17, 2026 Apr 17, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Electra Central AC unit – The unit opens an AP with an easily calculated password. |
1Siemens 13Scalance X200 4p Irt Firmware Scalance X201 3p Irt FirmwareScalance X201 3p Irt Pro Firmware+10 moreJun 17, 2026 Apr 11, 2023 N/A· v4 7.4 HIGH· v3 N/A· v2 A vulnerability has been identified in SCALANCE X200-4P IRT (All versions < V5.5.2), SCALANCE X201-3P IRT (All versions < V5.5.2), SCALANCE X201-3P IRT PRO (All versions < V5.5.2), SCALANCE X202-2IRT (All versions < V5.5...Show more |
1Contec 19Cps Mc341 A1 111 Firmware Cps Mc341 Adsc1 111 FirmwareCps Mc341 Adsc1 931 Firmware+16 moreJun 17, 2026 Apr 11, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2 Inadequate encryption strength vulnerability in CONPROSYS IoT Gateway products allows a remote authenticated attacker with an administrative privilege to apply a specially crafted Firmware update file, alter the informat...Show more |
In Apache Linkis <=1.3.1, due to the default token generated by Linkis Gateway deployment being too simple, it is easy for attackers to obtain the default token for the attack. Generation rules should add random values....Show more |
1Adobe 2Experience Manager Experience Manager Cloud ServiceJun 17, 2026 Mar 22, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Experience Manager versions 6.5.15.0 (and earlier) are affected by a Weak Cryptography for Passwords vulnerability that can lead to a security feature bypass. A low-privileged attacker can exploit this in order to decryp...Show more |
An improper access control vulnerability exists prior to v6 that could allow an attacker to break the E2E encryption of a chat room by a user changing the group key of a chat room. |
Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was disclosed by Microsoft on Nov 8 2022 and per RFC8429 it is assumed that rc4-hmac is weak, Vulnerable Samba Active Directory DCs will issue rc4-...Show more |
1Dell 2Supportassist For Business Pcs Supportassist For Home PcsJun 17, 2026 Feb 11, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain cryptographic weakness vulnerability. An authenticated non-admin user could potentially exploit...Show more |
Improper cryptographic implementation in Samsung Flow for PC 4.9.14.0 allows adjacent attackers to decrypt encrypted messages or inject commands. |
Improper cryptographic implementation in Samsung Flow for Android prior to version 4.9.04 allows adjacent attackers to decrypt encrypted messages or inject commands. |
1Ibm 1App Connect Enterprise Certified Container Jun 17, 2026 Feb 1, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 IBM App Connect Enterprise Certified Container 4.1, 4.2, 5.0, 5.1, 5.2, 6.0, 6.1, and 6.2 could disclose sensitive information to an attacker due to a weak hash of an API Key in the configuration. IBM X-Force ID: 24158...Show more |
DES cipher, which has inadequate encryption strength, is used Hitachi Energy FOXMAN-UN to encrypt user credentials used to access the Network Elements. Successful exploitation allows sensitive information to be decrypted...Show more |
1Amazon 1Aws Software Development Kit Jun 17, 2026 Dec 27, 2022 N/A· v4 4.3 MEDIUM· v3 N/A· v2 The AWS S3 Crypto SDK sends an unencrypted hash of the plaintext alongside the ciphertext as a metadata field. This hash can be used to brute force the plaintext, if the hash is readable to the attacker. AWS now blocks t...Show more |
1Ge 8Inet 900 Firmware Inet Ii 900 FirmwareSd1 Firmware+5 moreJun 17, 2026 Dec 26, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Certain General Electric Renewable Energy products have inadequate encryption strength. This affects iNET and iNET II before 8.3.0. |
IO FinNet tss-lib before 2.0.0 allows a collision of hash values. |
In specific scenarios, on Windows the operator credentials may be encrypted in a manner that is not completely machine-dependent.
|
In JetBrains IntelliJ IDEA before 2022.3 the built-in web server leaked information about open projects. |
The Config-files of Horner Automation’s RCC 972 with firmware version 15.40 are encrypted with weak XOR encryption vulnerable to reverse engineering. This could allow an attacker to obtain credentials to run services suc...Show more |
1Dwbooster 1Appointment Hour Booking Jun 17, 2026 Nov 29, 2022 N/A· v4 5.3 MEDIUM· v3 N/A· v2 The Appointment Hour Booking plugin for WordPress is vulnerable to CAPTCHA bypass in versions up to, and including, 1.3.72. This is due to the use of insufficiently strong hashing algorithm on the CAPTCHA secret that is...Show more |