CWE-326
455 CVEs • Abstraction: Class
Inadequate Encryption Strength
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
CVEs (455)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Mobileiron 2Sentry Virtual Smartphone PlatformNov 21, 2024 Feb 13, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 MobileIron VSP < 5.9.1 and Sentry < 5.0 has an insecure encryption scheme. |
1Att 2Mobileiron Sentry Mobileiron Virtual Smartphone PlatformNov 21, 2024 Feb 12, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 MobileIron VSP < 5.9.1 and Sentry < 5.0 has a weak password obfuscation algorithm |
1Fujitsu 40Celsius Firmware Gp7000f FirmwareGps Firmware+37 moreJun 17, 2026 Feb 7, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The Fujitsu TLS library allows a man-in-the-middle attack. This affects Interstage Application Development Cycle Manager V10 and other versions, Interstage Application Server V12 and other versions, Interstage Business A...Show more |
Joomla! core 1.7.1 allows information disclosure due to weak encryption |
1Django User Sessions Project 1Django User Sessions Jun 17, 2026 Jan 24, 2020 N/A· v4 8.8 HIGH· v3 4.0 MEDIUM· v2 In Django User Sessions (django-user-sessions) before 1.7.1, the views provided allow users to terminate specific sessions. The session key is used to identify sessions, and thus included in the rendered HTML. In itself...Show more |
1Gehealthcare 6Apexpro Telemetry Server Firmware Carescape Central Station Mai700 FirmwareCarescape Central Station Mas700 Firmware+3 moreJun 17, 2026 Jan 24, 2020 N/A· v4 10.0 CRITICAL· v3 10.0 HIGH· v2 In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X, the affected products ut...Show more |
1Philips 3Endura Firmware Pulsera FirmwareVeradius Unity FirmwareJun 17, 2026 Dec 20, 2019 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 An issue was found in Philips Veradius Unity, Pulsera, and Endura Dual WAN Router, Veradius Unity (718132) with wireless option (shipped between 2016-August 2018), Veradius Unity (718132) with ViewForum option (shipped b...Show more |
4Debian FedoraprojectOpenstack+1 more4Debian Linux FedoraOpenstack+1 moreNov 21, 2024 Dec 10, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass |
3Debian FedoraprojectPolarssl3Debian Linux FedoraPolarsslNov 21, 2024 Dec 6, 2019 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 A Security Bypass vulnerability exists in PolarSSL 0.99pre4 through 1.1.1 due to a weak encryption error when generating Diffie-Hellman values and RSA keys. |
Zabbix before 5.0 represents passwords in the users table with unsalted MD5. |
The OpenSSL extension of Ruby (Git trunk) versions after 2011-09-01 up to 2011-11-03 always generated an exponent value of '1' to be used for private RSA key generation. A remote attacker could use this flaw to bypass or...Show more |
1Philips 2Intellibridge Ec40 Firmware Intellibridge Ec80 FirmwareJun 17, 2026 Nov 26, 2019 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 In Philips IntelliBridge EC40 and EC80, IntelliBridge EC40 Hub all versions, and IntelliBridge EC80 Hub all versions, the SSH server running on the affected products is configured to allow weak ciphers. This could enable...Show more |
1Medtronic 3Valleylab Exchange Client Valleylab Ft10 Energy Platform FirmwareValleylab Fx8 Energy Platform FirmwareJun 17, 2026 Nov 8, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Medtronic Valleylab Exchange Client version 3.4 and below, Valleylab FT10 Energy Platform (VLFT10GEN) software version 4.0.0 and below, and Valleylab FX8 Energy Platform (VLFX8GEN) software version 1.1.0 and below use th...Show more |
TYPO3 before 4.3.4 and 4.4.x before 4.4.1 contains insecure randomness during generation of a hash with the "forgot password" function. |
An issue was discovered in Lightbend Play Framework 2.5.x through 2.6.23. When configured to make requests using an authenticated HTTP proxy, play-ws may sometimes, typically under high load, when connecting to a target...Show more |
Cryptocat before 2.0.22 has weak encryption in the Socialist Millionnaire Protocol |
1Ibm 1Security Guardium Big Data Intelligence Jun 17, 2026 Oct 29, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IBM Security Guardium Big Data Intelligence (SonarG) 4.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 161418. |
1Supermicro 321A1sa2 2750f Firmware A1sai 2550f FirmwareA1sai 2750f Firmware+318 moreJun 17, 2026 Sep 21, 2019 N/A· v4 10.0 CRITICAL· v3 5.0 MEDIUM· v2 On Supermicro H11, H12, M11, X9, X10, and X11 products, a combination of encryption and authentication problems in the virtual media service allows capture of BMC credentials and data transferred over virtual media devic...Show more |
IBM Cognos Controller 10.3.0, 10.3.1, 10.4.0, and 10.4.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 158880. |
CommScope ARRIS TR4400 devices with firmware through A1.00.004-180301 are vulnerable to an authentication bypass to the administrative interface because they include the current base64 encoded password within http://192....Show more |