CWE-326
455 CVEs • Abstraction: Class
Inadequate Encryption Strength
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
CVEs (455)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Jenkins Script Security Plugin 1189.vb_a_b_7c8fd5fde and earlier stores whole-script approvals as the SHA-1 hash of the script, making it vulnerable to collision attacks. |
The application was signed using a key length less than or equal to 1024 bits, making it potentially vulnerable to forged digital signatures. An attacker could forge the same digital signature of the app after maliciousl...Show more |
SAP Customer Data Cloud (Gigya mobile app for Android) - version 7.4, uses encryption method which lacks proper diffusion and does not hide the patterns well. This can lead to information disclosure. In certain scenarios...Show more |
1Solarwinds 1Network Configuration Manager Jun 17, 2026 Oct 10, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 An entity in Network Configuration Manager product is misconfigured and exposing password field to Solarwinds Information Service (SWIS). Exposed credentials are encrypted and require authenticated access with an NCM rol...Show more |
The aeson library is not safe to use to consume untrusted JSON input. A remote user could abuse this flaw to produce a hash collision in the underlying unordered-containers library by sending specially crafted JSON data,...Show more |
Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a4. |
WD Discovery software executable files were signed with an unsafe SHA-1 hashing algorithm. An attacker could use this weakness to create forged certificate signatures due to the use of a hashing algorithm that is not col...Show more |
Nextcloud Password Policy is an app that enables a Nextcloud server admin to define certain rules for passwords. Prior to versions 22.2.10, 23.0.7, and 24.0.3 the random password generator may, in very rare cases, genera...Show more |
1Ls Electric 235Gm7 Firmware Gm7u FirmwareK120s Firmware+232 moreJun 17, 2026 Aug 31, 2022 N/A· v4 5.9 MEDIUM· v3 N/A· v2 Passwords are not adequately encrypted during the communication process between all versions of LS Industrial Systems (LSIS) Co. Ltd LS Electric XG5000 software prior to V4.0 and LS Electric PLCs: all versions of XGK-CPU...Show more |
Hytec Inter HWL-2511-SS v1.05 and below implements a SHA512crypt hash for the root account which can be easily cracked via a brute-force attack. |
1Intel 9Proset Wi Fi 6e Ax210 Firmware Wi Fi 6 Ax200 FirmwareWi Fi 6 Ax201 Firmware+6 moreJun 17, 2026 Aug 18, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 Inadequate encryption strength for some Intel(R) PROSet/Wireless WiFi products may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access. |
1Quest 1Kace Systems Management Appliance Jun 17, 2026 Aug 2, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 In Quest KACE Systems Management Appliance (SMA) through 12.0, a hash collision is possible during authentication. This may allow authentication with invalid credentials. |
2Debian Libreoffice2Debian Linux LibreofficeJun 17, 2026 Jul 25, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 LibreOffice supports the storage of passwords for web connections in the user’s configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in LibreOffice existed wher...Show more |
2Debian Libreoffice2Debian Linux LibreofficeJun 17, 2026 Jul 25, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 LibreOffice supports the storage of passwords for web connections in the user’s configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in LibreOffice existed wher...Show more |
IBM Security Verify Identity Manager 10.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 224919. |
IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 22...Show more |
1Owllabs 1Meeting Owl Pro Firmware Jun 17, 2026 Jun 2, 2022 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 Owl Labs Meeting Owl 5.2.0.15 allows attackers to retrieve the passcode hash via a certain c 10 value over Bluetooth. |
JavaEZ is a library that adds new functions to make Java easier. A weakness in JavaEZ 1.6 allows force decryption of locked text by unauthorized actors. The issue is NOT critical for non-secure applications, however may...Show more |
1Emerson 1Openenterprise Scada Server Jun 17, 2026 May 19, 2022 N/A· v4 6.5 MEDIUM· v3 2.1 LOW· v2 Inadequate encryption may allow the credentials used by Emerson OpenEnterprise, up through version 3.3.5, to access field devices and external systems to be obtained. |
Weak web transport security (Weak TLS): An attacker may be able to decrypt the data using attacks |