CWE-326
467 CVEs • Abstraction: Class
Inadequate Encryption Strength
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
CVEs (467)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ls Electric 235Gm7 Firmware Gm7u FirmwareK120s Firmware+232 moreJun 17, 2026 Aug 31, 2022 N/A· v4 5.9 MEDIUM· v3 N/A· v2 Passwords are not adequately encrypted during the communication process between all versions of LS Industrial Systems (LSIS) Co. Ltd LS Electric XG5000 software prior to V4.0 and LS Electric PLCs: all versions of XGK-CPU...Show more |
Hytec Inter HWL-2511-SS v1.05 and below implements a SHA512crypt hash for the root account which can be easily cracked via a brute-force attack. |
1Intel 9Proset Wi Fi 6e Ax210 Firmware Wi Fi 6 Ax200 FirmwareWi Fi 6 Ax201 Firmware+6 moreJun 17, 2026 Aug 18, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 Inadequate encryption strength for some Intel(R) PROSet/Wireless WiFi products may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access. |
1Quest 1Kace Systems Management Appliance Jun 17, 2026 Aug 2, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 In Quest KACE Systems Management Appliance (SMA) through 12.0, a hash collision is possible during authentication. This may allow authentication with invalid credentials. |
2Debian Libreoffice2Debian Linux LibreofficeJun 17, 2026 Jul 25, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 LibreOffice supports the storage of passwords for web connections in the user’s configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in LibreOffice existed wher...Show more |
2Debian Libreoffice2Debian Linux LibreofficeJun 17, 2026 Jul 25, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 LibreOffice supports the storage of passwords for web connections in the user’s configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in LibreOffice existed wher...Show more |
IBM Security Verify Identity Manager 10.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 224919. |
IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 22...Show more |
1Owllabs 1Meeting Owl Pro Firmware Jun 17, 2026 Jun 2, 2022 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 Owl Labs Meeting Owl 5.2.0.15 allows attackers to retrieve the passcode hash via a certain c 10 value over Bluetooth. |
JavaEZ is a library that adds new functions to make Java easier. A weakness in JavaEZ 1.6 allows force decryption of locked text by unauthorized actors. The issue is NOT critical for non-secure applications, however may...Show more |
1Emerson 1Openenterprise Scada Server Jun 17, 2026 May 19, 2022 N/A· v4 6.5 MEDIUM· v3 2.1 LOW· v2 Inadequate encryption may allow the credentials used by Emerson OpenEnterprise, up through version 3.3.5, to access field devices and external systems to be obtained. |
Weak web transport security (Weak TLS): An attacker may be able to decrypt the data using attacks |
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The XWiki Crypto API will generate X509 certificates signed by default using SHA1 with RSA, which is not considered...Show more |
1Secomea 14Gatemanager 4250 Firmware Gatemanager 4260 FirmwareGatemanager 8250 Firmware+11 moreJun 17, 2026 May 4, 2022 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Inadequate Encryption Strength vulnerability in TLS stack of Secomea SiteManager, LinkManager, GateManager may facilitate man in the middle attacks. This issue affects: Secomea SiteManager All versions prior to 9.7. Seco...Show more |
IBM Spectrum Scale 5.1.0 through 5.1.3.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 221012. |
1Bulletproofs Project 1Bulletproofs Jun 17, 2026 Apr 21, 2022 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 The Bulletproofs 2017/1066 paper mishandles Fiat-Shamir generation because the hash computation fails to include all of the public values from the Zero Knowledge proof statement as well as all of the public values comput...Show more |
Hills ComNav version 3002-19 suffers from a weak communication channel. Traffic across the local network for the configuration pages can be viewed by a malicious actor. The size of certain communications packets are pred...Show more |
Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code...Show more |
1Mitsubishielectric 16Fx5uc 32mr/ds Ts Firmware Fx5uc 32mt/d FirmwareFx5uc 32mt/ds Ts Firmware+13 moreJun 17, 2026 Apr 1, 2022 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Use of Weak Hash vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U(C) CPU all versions, Mitsubishi Electric MELSEC iQ-F series FX5UJ CPU all versions, Mitsubishi Electric MELSEC iQ-R series R00/01/02CPU all ve...Show more |
1Auvesy Mdt 2Autosave Autosave For System PlatformJun 17, 2026 Apr 1, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An attacker could decipher the encryption and gain access to MDT AutoSave versions prior to v6.02.06. |