CWE-326
467 CVEs • Abstraction: Class
Inadequate Encryption Strength
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
CVEs (467)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
IBM Data Risk Manager (iDNA) 2.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 207980. |
IBM Sterling B2B Integrator Standard Edition 5.2.0. 0 through 6.1.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 210171. |
1Bosch 2Rexroth Indramotion Mlc Firmware Rexroth Indramotion Xlc FirmwareJun 17, 2026 Oct 4, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The user and password data base is exposed by an unprotected web server resource. Passwords are hashed with a weak hashing algorithm and therefore allow an attacker to determine the password by using rainbow tables. |
In SapphireIMS 4097_1, the password in the database is stored in Base64 format. |
1Meow Hash Project 1Meow Hash Jun 17, 2026 Jul 30, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Meow hash 0.5/calico does not sufficiently thwart key recovery by an attacker who can query whether there's a collision in the bottom bits of the hashes of two messages, as demonstrated by an attack against a long-runnin...Show more |
1Open Xchange 1Open Xchange Documents Jun 17, 2026 Jul 30, 2021 N/A· v4 4.8 MEDIUM· v3 5.8 MEDIUM· v2 OX Documents before 7.10.5-rev5 has Incorrect Access Control for documents that contain XML structures because hash collisions can occur, due to use of CRC32. |
1Open Xchange 1Open Xchange Documents Jun 17, 2026 Jul 30, 2021 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 OX Documents before 7.10.5-rev7 has Incorrect Access Control for converted documents because hash collisions can occur, due to use of CRC32. |
1Open Xchange 1Open Xchange Documents Jun 17, 2026 Jul 30, 2021 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 OX Documents before 7.10.5-rev5 has Incorrect Access Control of converted images because hash collisions can occur, due to use of Adler32. |
1Ibm 1Cloud Pak For Applications Jun 17, 2026 Jul 13, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 IBM Cloud Pak for Applications 4.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 195361. |
1Ibm 1Cloud Pak For Applications Jun 17, 2026 Jul 13, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IBM Cloud Pak for Applications 4.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 195031. |
Eclipse TinyDTLS through 0.9-rc1 relies on the rand function in the C library, which makes it easier for remote attackers to compute the master key and then decrypt DTLS traffic. |
SICK Visionary-S CX up version 5.21.2.29154R are vulnerable to an Inadequate Encryption Strength vulnerability concerning the internal SSH interface solely used by SICK for recovering returned devices. The use of weak ci...Show more |
Improper protection of backup path configuration in Samsung Dex prior to SMR MAY-2021 Release 1 allows local attackers to get sensitive information via changing the path. |
1Broadcom 2Brocade Sannav Fabric Operating SystemJun 17, 2026 Jun 9, 2021 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 The host SSH servers of Brocade Fabric OS before Brocade Fabric OS v7.4.2h, v8.2.1c, v8.2.2, v9.0.0, and Brocade SANnav before v2.1.1 utilize keys of less than 2048 bits, which may be vulnerable to man-in-the-middle atta...Show more |
1Versa Networks 1Versa Operating System Nov 21, 2024 May 26, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 In VOS compromised, an attacker at network endpoints can possibly view communications between an unsuspecting user and the service using man-in-the-middle attacks. Usage of unapproved SSH encryption protocols or cipher s...Show more |
2Nitrokey Solokeys3Fido2 Firmware Solo FirmwareSomu FirmwareJun 17, 2026 May 21, 2021 N/A· v4 6.8 MEDIUM· v3 4.6 MEDIUM· v2 The flash read-out protection (RDP) level is not enforced during the device initialization phase of the SoloKeys Solo 4.0.0 & Somu and the Nitrokey FIDO2 token. This allows an adversary to downgrade the RDP level and acc...Show more |
Weak Encoding for Password in DoraCMS v2.1.1 and earlier allows attackers to obtain sensitive information as it does not use a random salt or IV for its AES-CBC encryption, causes password encrypted for users to be susce...Show more |
1Emerson 4X Stream Enhanced Xefd Firmware X Stream Enhanced Xegk FirmwareX Stream Enhanced Xegp Firmware+1 moreJun 17, 2026 May 20, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected products utilize a weak encryption algorithm for storage of sensitive data, which may allow an attacker to mor...Show more |
Password generator feature in Kaspersky Password Manager was not completely cryptographically strong and potentially allowed an attacker to predict generated passwords in some cases. An attacker would need to know some a...Show more |
1Dell 11R1 2210 Firmware R1 2401 FirmwareX1008 Firmware+8 moreJun 17, 2026 Apr 30, 2021 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Dell EMC Networking X-Series firmware versions prior to 3.0.1.8 and Dell EMC PowerEdge VRTX Switch Module firmware versions prior to 2.0.0.82 contain a Weak Password Encryption Vulnerability. A remote unauthenticated att...Show more |