CWE-326
467 CVEs • Abstraction: Class
Inadequate Encryption Strength
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
CVEs (467)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Dell 1Emc Powerscale Onefs Jun 17, 2026 Apr 20, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Dell PowerScale OneFS 8.1.0 - 9.1.0 contains an LDAP Provider inability to connect over TLSv1.2 vulnerability. It may make it easier to eavesdrop and decrypt such traffic for a malicious actor. Note: This does not affect...Show more |
1Mozilla 3Firefox Firefox EsrThunderbirdJun 17, 2026 Mar 31, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Using techniques that built on the slipstream research, a malicious webpage could have scanned both an internal network's hosts as well as services running on the user's local machine utilizing WebRTC connections. This v...Show more |
SSH server configuration file does not implement some best practices. This could lead to a weakening of the SSH protocol strength, which could lead to additional misconfiguration or be leveraged as part of a larger attac...Show more |
Wrongthink peer-to-peer, end-to-end encrypted messenger with PeerJS and Axolotl ratchet. In wrongthink from version 2.0.0 and before 2.3.0 there was a set of vulnerabilities causing inadequate encryption strength. Part o...Show more |
1Netgear 2Gs116e Firmware Jgs516pe FirmwareJun 17, 2026 Mar 10, 2021 N/A· v4 8.8 HIGH· v3 3.3 LOW· v2 The hashing algorithm implemented for NSDP password authentication on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices was found to be insecure, allowing attackers (with access to a network capture) to quickly generate multip...Show more |
1Ibm 1Security Verify Information Queue Jun 17, 2026 Feb 12, 2021 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 IBM Security Verify Information Queue 1.0.6 and 1.0.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 196184. |
SAP HANA Database, versions - 1.0, 2.0, accepts SAML tokens with MD5 digest, an attacker who manages to obtain an MD5-digest signed SAML Assertion issued for an SAP HANA instance might be able to tamper with it and alter...Show more |
An issue was discovered in Psyprax beforee 3.2.2. Passwords used to encrypt the data are stored in the database in an obfuscated format, which can be easily reverted. For example, the password AAAAAAAA is stored in the d...Show more |
An issue was discovered in New Media Smarty before 9.10. Passwords are stored in the database in an obfuscated format that can be easily reversed. The file data.mdb contains these obfuscated passwords in the second colum...Show more |
In JetBrains Ktor before 1.5.0, a birthday attack on SessionStorage key was possible. |
4Arista DebianFedoraproject+1 more4Debian Linux DnsmasqEos+1 moreJun 17, 2026 Jan 20, 2021 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmasq checks in forward.c:reply_query(), which is the forwarded query that matches the reply, by only using a weak hash of t...Show more |
1Ibm 1Security Guardium Data Encryption Jun 17, 2026 Jan 13, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IBM Security Guardium Data Encryption (GDE) 3.0.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 158577. |
The Web server in 1C:Enterprise 8 before 8.3.17.1851 sends base64 encoded credentials in the creds URL parameter. |
1Aes Encryption Project 1Aes Encryption Nov 21, 2024 Jan 1, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The AES encryption project 7.x and 8.x for Drupal does not sufficiently prevent attackers from decrypting data, aka SA-CONTRIB-2017-027. NOTE: This project is not covered by Drupal's security advisory policy. |
1Tlslite Ng Project 1Tlslite Ng Jun 17, 2026 Dec 21, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 tlslite-ng is an open source python library that implements SSL and TLS cryptographic protocols. In tlslite-ng before versions 0.7.6 and 0.8.0-alpha39, the code that performs decryption and padding check in RSA PKCS#1 v1...Show more |
1Schneider Electric 1Modicon M221 Firmware Jun 17, 2026 Nov 19, 2020 N/A· v4 7.3 HIGH· v3 4.3 MEDIUM· v2 A CWE-326: Inadequate Encryption Strength vulnerability exists in Modicon M221 (all references, all versions) that could allow the attacker to break the encryption key when the attacker has captured the traffic between E...Show more |
1Untangle 1Untangle Firewall Ng Jun 17, 2026 Nov 12, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Untangle Firewall NG before 16.0 uses MD5 for passwords. |
1Intel 1Converged Security And Manageability Engine Jun 17, 2026 Nov 12, 2020 N/A· v4 4.6 MEDIUM· v3 2.1 LOW· v2 Inadequate encryption strength in subsystem for Intel(R) CSME versions before 13.0.40 and 13.30.10 may allow an unauthenticated user to potentially enable information disclosure via physical access. |
FusionCompute versions 8.0.0 have an insecure encryption algorithm vulnerability. Attackers with high permissions can exploit this vulnerability to cause information leak. |
1F5 14Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+11 moreJun 17, 2026 Oct 29, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 On BIG-IP 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, when negotiating IPSec tunnels with configured, authenticated peers, the peer may negotiate a different key length than the BIG-IP configuration would othe...Show more |