← Back
CWE-326

455 CVEs • Abstraction: Class

Inadequate Encryption Strength

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

JSON object

Loading...

CVEs (455)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mobileiron
2Sentry
Virtual Smartphone Platform
Nov 21, 2024
Feb 13, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
MobileIron VSP < 5.9.1 and Sentry < 5.0 has an insecure encryption scheme.
1Att
2Mobileiron Sentry
Mobileiron Virtual Smartphone Platform
Nov 21, 2024
Feb 12, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
MobileIron VSP < 5.9.1 and Sentry < 5.0 has a weak password obfuscation algorithm
1Fujitsu
40Celsius Firmware
Gp7000f FirmwareGps Firmware+37 more
Jun 17, 2026
Feb 7, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The Fujitsu TLS library allows a man-in-the-middle attack. This affects Interstage Application Development Cycle Manager V10 and other versions, Interstage Application Server V12 and other versions, Interstage Business A...Show more
The Fujitsu TLS library allows a man-in-the-middle attack. This affects Interstage Application Development Cycle Manager V10 and other versions, Interstage Application Server V12 and other versions, Interstage Business Application Manager V2 and other versions, Interstage Information Integrator V11 and other versions, Interstage Job Workload Server V8, Interstage List Works V10 and other versions, Interstage Studio V12 and other versions, Interstage Web Server Express V11, Linkexpress V5, Safeauthor V3, ServerView Resource Orchestrator V3, Systemwalker Cloud Business Service Management V1, Systemwalker Desktop Keeper V15, Systemwalker Desktop Patrol V15, Systemwalker IT Change Manager V14, Systemwalker Operation Manager V16 and other versions, Systemwalker Runbook Automation V15 and other versions, Systemwalker Security Control V1, and Systemwalker Software Configuration Manager V15.Show less
1Joomla
1Joomla
Nov 21, 2024
Feb 4, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Joomla! core 1.7.1 allows information disclosure due to weak encryption
1Django User Sessions Project
1Django User Sessions
Jun 17, 2026
Jan 24, 2020
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
In Django User Sessions (django-user-sessions) before 1.7.1, the views provided allow users to terminate specific sessions. The session key is used to identify sessions, and thus included in the rendered HTML. In itself...Show more
In Django User Sessions (django-user-sessions) before 1.7.1, the views provided allow users to terminate specific sessions. The session key is used to identify sessions, and thus included in the rendered HTML. In itself this is not a problem. However if the website has an XSS vulnerability, the session key could be extracted by the attacker and a session takeover could happen.Show less
1Gehealthcare
6Apexpro Telemetry Server Firmware
Carescape Central Station Mai700 FirmwareCarescape Central Station Mas700 Firmware+3 more
Jun 17, 2026
Jan 24, 2020
N/A· v4
10.0 CRITICAL· v3
10.0 HIGH· v2
In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X, the affected products ut...Show more
In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X, the affected products utilize a weak encryption scheme for remote desktop control, which may allow an attacker to obtain remote code execution of devices on the network.Show less
1Philips
3Endura Firmware
Pulsera FirmwareVeradius Unity Firmware
Jun 17, 2026
Dec 20, 2019
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
An issue was found in Philips Veradius Unity, Pulsera, and Endura Dual WAN Router, Veradius Unity (718132) with wireless option (shipped between 2016-August 2018), Veradius Unity (718132) with ViewForum option (shipped b...Show more
An issue was found in Philips Veradius Unity, Pulsera, and Endura Dual WAN Router, Veradius Unity (718132) with wireless option (shipped between 2016-August 2018), Veradius Unity (718132) with ViewForum option (shipped between 2016-August 2018), Pulsera (718095) and Endura (718075) with wireless option (shipped between 26-June-2017 through 07-August 2018), Pulsera (718095) and Endura (718075) with ViewForum option (shipped between 26-June-2017 through 07-August 2018). The router software uses an encryption scheme that is not strong enough for the level of protection required.Show less
4Debian
FedoraprojectOpenstack+1 more
4Debian Linux
FedoraOpenstack+1 more
Nov 21, 2024
Dec 10, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass
3Debian
FedoraprojectPolarssl
3Debian Linux
FedoraPolarssl
Nov 21, 2024
Dec 6, 2019
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
A Security Bypass vulnerability exists in PolarSSL 0.99pre4 through 1.1.1 due to a weak encryption error when generating Diffie-Hellman values and RSA keys.
1Zabbix
1Zabbix
Nov 21, 2024
Nov 30, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Zabbix before 5.0 represents passwords in the users table with unsalted MD5.
1Ruby Lang
1Ruby
Nov 21, 2024
Nov 26, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The OpenSSL extension of Ruby (Git trunk) versions after 2011-09-01 up to 2011-11-03 always generated an exponent value of '1' to be used for private RSA key generation. A remote attacker could use this flaw to bypass or...Show more
The OpenSSL extension of Ruby (Git trunk) versions after 2011-09-01 up to 2011-11-03 always generated an exponent value of '1' to be used for private RSA key generation. A remote attacker could use this flaw to bypass or corrupt integrity of services, depending on strong private RSA keys generation mechanism.Show less
1Philips
2Intellibridge Ec40 Firmware
Intellibridge Ec80 Firmware
Jun 17, 2026
Nov 26, 2019
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
In Philips IntelliBridge EC40 and EC80, IntelliBridge EC40 Hub all versions, and IntelliBridge EC80 Hub all versions, the SSH server running on the affected products is configured to allow weak ciphers. This could enable...Show more
In Philips IntelliBridge EC40 and EC80, IntelliBridge EC40 Hub all versions, and IntelliBridge EC80 Hub all versions, the SSH server running on the affected products is configured to allow weak ciphers. This could enable an unauthorized attacker with access to the network to capture and replay the session and gain unauthorized access to the EC40/80 hub.Show less
1Medtronic
3Valleylab Exchange Client
Valleylab Ft10 Energy Platform FirmwareValleylab Fx8 Energy Platform Firmware
Jun 17, 2026
Nov 8, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Medtronic Valleylab Exchange Client version 3.4 and below, Valleylab FT10 Energy Platform (VLFT10GEN) software version 4.0.0 and below, and Valleylab FX8 Energy Platform (VLFX8GEN) software version 1.1.0 and below use th...Show more
Medtronic Valleylab Exchange Client version 3.4 and below, Valleylab FT10 Energy Platform (VLFT10GEN) software version 4.0.0 and below, and Valleylab FX8 Energy Platform (VLFX8GEN) software version 1.1.0 and below use the descrypt algorithm for OS password hashing. While interactive, network-based logons are disabled, and attackers can use the other vulnerabilities within this report to obtain local shell access and access these hashes.Show less
1Typo3
1Typo3
Nov 21, 2024
Nov 5, 2019
N/A· v4
4.8 MEDIUM· v3
5.8 MEDIUM· v2
TYPO3 before 4.3.4 and 4.4.x before 4.4.1 contains insecure randomness during generation of a hash with the "forgot password" function.
1Lightbend
1Play Framework
Jun 17, 2026
Nov 5, 2019
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
An issue was discovered in Lightbend Play Framework 2.5.x through 2.6.23. When configured to make requests using an authenticated HTTP proxy, play-ws may sometimes, typically under high load, when connecting to a target...Show more
An issue was discovered in Lightbend Play Framework 2.5.x through 2.6.23. When configured to make requests using an authenticated HTTP proxy, play-ws may sometimes, typically under high load, when connecting to a target host using https, expose the proxy credentials to the target host.Show less
1Cryptocat Project
1Cryptocat
Nov 21, 2024
Nov 4, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Cryptocat before 2.0.22 has weak encryption in the Socialist Millionnaire Protocol
1Ibm
1Security Guardium Big Data Intelligence
Jun 17, 2026
Oct 29, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM Security Guardium Big Data Intelligence (SonarG) 4.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 161418.
1Supermicro
321A1sa2 2750f Firmware
A1sai 2550f FirmwareA1sai 2750f Firmware+318 more
Jun 17, 2026
Sep 21, 2019
N/A· v4
10.0 CRITICAL· v3
5.0 MEDIUM· v2
On Supermicro H11, H12, M11, X9, X10, and X11 products, a combination of encryption and authentication problems in the virtual media service allows capture of BMC credentials and data transferred over virtual media devic...Show more
On Supermicro H11, H12, M11, X9, X10, and X11 products, a combination of encryption and authentication problems in the virtual media service allows capture of BMC credentials and data transferred over virtual media devices. Attackers can use captured credentials to connect virtual USB devices to the server managed by the BMC.Show less
1Ibm
1Cognos Controller
Jun 17, 2026
Sep 17, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM Cognos Controller 10.3.0, 10.3.1, 10.4.0, and 10.4.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 158880.
1Commscope
1Tr4400 Firmware
Jun 17, 2026
Aug 29, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
CommScope ARRIS TR4400 devices with firmware through A1.00.004-180301 are vulnerable to an authentication bypass to the administrative interface because they include the current base64 encoded password within http://192....Show more
CommScope ARRIS TR4400 devices with firmware through A1.00.004-180301 are vulnerable to an authentication bypass to the administrative interface because they include the current base64 encoded password within http://192.168.1.1/basic_sett.html. Any user connected to the Wi-Fi can exploit this.Show less