CWE-326
455 CVEs • Abstraction: Class
Inadequate Encryption Strength
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
CVEs (455)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The Web server in 1C:Enterprise 8 before 8.3.17.1851 sends base64 encoded credentials in the creds URL parameter. |
1Aes Encryption Project 1Aes Encryption Nov 21, 2024 Jan 1, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The AES encryption project 7.x and 8.x for Drupal does not sufficiently prevent attackers from decrypting data, aka SA-CONTRIB-2017-027. NOTE: This project is not covered by Drupal's security advisory policy. |
1Tlslite Ng Project 1Tlslite Ng Jun 17, 2026 Dec 21, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 tlslite-ng is an open source python library that implements SSL and TLS cryptographic protocols. In tlslite-ng before versions 0.7.6 and 0.8.0-alpha39, the code that performs decryption and padding check in RSA PKCS#1 v1...Show more |
1Schneider Electric 1Modicon M221 Firmware Jun 17, 2026 Nov 19, 2020 N/A· v4 7.3 HIGH· v3 4.3 MEDIUM· v2 A CWE-326: Inadequate Encryption Strength vulnerability exists in Modicon M221 (all references, all versions) that could allow the attacker to break the encryption key when the attacker has captured the traffic between E...Show more |
1Untangle 1Untangle Firewall Ng Jun 17, 2026 Nov 12, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Untangle Firewall NG before 16.0 uses MD5 for passwords. |
1Intel 1Converged Security And Manageability Engine Jun 17, 2026 Nov 12, 2020 N/A· v4 4.6 MEDIUM· v3 2.1 LOW· v2 Inadequate encryption strength in subsystem for Intel(R) CSME versions before 13.0.40 and 13.30.10 may allow an unauthenticated user to potentially enable information disclosure via physical access. |
FusionCompute versions 8.0.0 have an insecure encryption algorithm vulnerability. Attackers with high permissions can exploit this vulnerability to cause information leak. |
1F5 14Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+11 moreJun 17, 2026 Oct 29, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 On BIG-IP 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, when negotiating IPSec tunnels with configured, authenticated peers, the peer may negotiate a different key length than the BIG-IP configuration would othe...Show more |
1Cisco 2Firepower Threat Defense Secure Firewall Management CenterJun 17, 2026 Oct 21, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 A vulnerability in the sftunnel functionality of Cisco Firepower Management Center (FMC) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to obtain the device reg...Show more |
8Canonical DebianFedoraproject+5 more8Clustered Data Ontap Communications Diameter Signaling RouterDebian Linux+5 moreJun 17, 2026 Oct 2, 2020 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when AES-CCM mode is used with openssl_encrypt() function with 12 bytes IV, only first 7 bytes of the IV is actually used. This can lead to b...Show more |
Protocol encryption can be easily broken for CodeMeter (All versions prior to 6.90 are affected, including Version 6.90 or newer only if CodeMeter Runtime is running as server) and the server accepts external connections...Show more |
1F5 12Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+9 moreJun 17, 2026 Aug 26, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 In BIG-IP versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.2 and BIG-IQ versions 5.2.0-7.0.0, the host OpenSSH servers utilize keys of less than 2048 bits wh...Show more |
NCR SelfServ ATMs running APTRA XFS 04.02.01 and 05.01.00 implement 512-bit RSA certificates to validate bunch note acceptor (BNA) software updates, which can be broken by an attacker with physical access in a sufficient...Show more |
1Grandstream 6Ht801 Firmware Ht802 FirmwareHt812 Firmware+3 moreJun 17, 2026 Jul 29, 2020 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 Grandstream HT800 series firmware version 1.0.17.5 and below contain a backdoor in the SSH service. An authenticated remote attacker can obtain a root shell by correctly answering a challenge prompt. |
1Automationdirect 1C More Hmi Ea9 Firmware Jun 17, 2026 Jul 23, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 This vulnerability allows remote attackers to disclose sensitive information on affected installations of C-MORE HMI EA9 Firmware version 6.52 touch screen panels. Authentication is not required to exploit this vulnerabi...Show more |
Certain communication between PAN-OS and cloud-delivered services inadvertently use TLS 1.0, which is known to be a cryptographically weak protocol. These cloud services include Cortex Data Lake, the Customer Support Por...Show more |
"A vulnerability in the TLS protocol implementation of the Domino server could allow an unauthenticated, remote attacker to access sensitive information, aka a Return of Bleichenbacher's Oracle Threat (ROBOT) attack. An...Show more |
3Easyrobotics Mobile Industrial RobotsUvd Robots10Er Flex Firmware Er Lite FirmwareEr One Firmware+7 moreJun 17, 2026 Jun 24, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The access tokens for the REST API are directly derived from the publicly available default credentials for the web interface. Given a USERNAME and a PASSWORD, the token string is generated directly with base64(USERNAME:...Show more |
1Intel 1Converged Security Management Engine Firmware Jun 17, 2026 Jun 15, 2020 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 Reversible one-way hash in Intel(R) CSME versions before 11.8.76, 11.12.77 and 11.22.77 may allow a privileged user to potentially enable escalation of privilege, denial of service or information disclosure via local acc...Show more |
1Usavisionsys 5Geovision Gv As1010 Firmware Geovision Gv As210 FirmwareGeovision Gv As410 Firmware+2 moreJun 17, 2026 Jun 12, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 GeoVision Door Access Control device family employs shared cryptographic private keys for SSH and HTTPS. Attackers may conduct MITM attack with the derived keys and plaintext recover of encrypted messages. |