← Back
CWE-326

467 CVEs • Abstraction: Class

Inadequate Encryption Strength

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

JSON object

Loading...

CVEs (467)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Debian
FedoraprojectPolarssl
3Debian Linux
FedoraPolarssl
Nov 21, 2024
Dec 6, 2019
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
A Security Bypass vulnerability exists in PolarSSL 0.99pre4 through 1.1.1 due to a weak encryption error when generating Diffie-Hellman values and RSA keys.
1Zabbix
1Zabbix
Nov 21, 2024
Nov 30, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Zabbix before 5.0 represents passwords in the users table with unsalted MD5.
1Ruby Lang
1Ruby
Nov 21, 2024
Nov 26, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The OpenSSL extension of Ruby (Git trunk) versions after 2011-09-01 up to 2011-11-03 always generated an exponent value of '1' to be used for private RSA key generation. A remote attacker could use this flaw to bypass or...Show more
The OpenSSL extension of Ruby (Git trunk) versions after 2011-09-01 up to 2011-11-03 always generated an exponent value of '1' to be used for private RSA key generation. A remote attacker could use this flaw to bypass or corrupt integrity of services, depending on strong private RSA keys generation mechanism.Show less
1Philips
2Intellibridge Ec40 Firmware
Intellibridge Ec80 Firmware
Jun 17, 2026
Nov 26, 2019
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
In Philips IntelliBridge EC40 and EC80, IntelliBridge EC40 Hub all versions, and IntelliBridge EC80 Hub all versions, the SSH server running on the affected products is configured to allow weak ciphers. This could enable...Show more
In Philips IntelliBridge EC40 and EC80, IntelliBridge EC40 Hub all versions, and IntelliBridge EC80 Hub all versions, the SSH server running on the affected products is configured to allow weak ciphers. This could enable an unauthorized attacker with access to the network to capture and replay the session and gain unauthorized access to the EC40/80 hub.Show less
1Medtronic
3Valleylab Exchange Client
Valleylab Ft10 Energy Platform FirmwareValleylab Fx8 Energy Platform Firmware
Jun 17, 2026
Nov 8, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Medtronic Valleylab Exchange Client version 3.4 and below, Valleylab FT10 Energy Platform (VLFT10GEN) software version 4.0.0 and below, and Valleylab FX8 Energy Platform (VLFX8GEN) software version 1.1.0 and below use th...Show more
Medtronic Valleylab Exchange Client version 3.4 and below, Valleylab FT10 Energy Platform (VLFT10GEN) software version 4.0.0 and below, and Valleylab FX8 Energy Platform (VLFX8GEN) software version 1.1.0 and below use the descrypt algorithm for OS password hashing. While interactive, network-based logons are disabled, and attackers can use the other vulnerabilities within this report to obtain local shell access and access these hashes.Show less
1Typo3
1Typo3
Nov 21, 2024
Nov 5, 2019
N/A· v4
4.8 MEDIUM· v3
5.8 MEDIUM· v2
TYPO3 before 4.3.4 and 4.4.x before 4.4.1 contains insecure randomness during generation of a hash with the "forgot password" function.
1Lightbend
1Play Framework
Jun 17, 2026
Nov 5, 2019
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
An issue was discovered in Lightbend Play Framework 2.5.x through 2.6.23. When configured to make requests using an authenticated HTTP proxy, play-ws may sometimes, typically under high load, when connecting to a target...Show more
An issue was discovered in Lightbend Play Framework 2.5.x through 2.6.23. When configured to make requests using an authenticated HTTP proxy, play-ws may sometimes, typically under high load, when connecting to a target host using https, expose the proxy credentials to the target host.Show less
1Cryptocat Project
1Cryptocat
Nov 21, 2024
Nov 4, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Cryptocat before 2.0.22 has weak encryption in the Socialist Millionnaire Protocol
1Ibm
1Security Guardium Big Data Intelligence
Jun 17, 2026
Oct 29, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM Security Guardium Big Data Intelligence (SonarG) 4.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 161418.
1Supermicro
321A1sa2 2750f Firmware
A1sai 2550f FirmwareA1sai 2750f Firmware+318 more
Jun 17, 2026
Sep 21, 2019
N/A· v4
10.0 CRITICAL· v3
5.0 MEDIUM· v2
On Supermicro H11, H12, M11, X9, X10, and X11 products, a combination of encryption and authentication problems in the virtual media service allows capture of BMC credentials and data transferred over virtual media devic...Show more
On Supermicro H11, H12, M11, X9, X10, and X11 products, a combination of encryption and authentication problems in the virtual media service allows capture of BMC credentials and data transferred over virtual media devices. Attackers can use captured credentials to connect virtual USB devices to the server managed by the BMC.Show less
1Ibm
1Cognos Controller
Jun 17, 2026
Sep 17, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM Cognos Controller 10.3.0, 10.3.1, 10.4.0, and 10.4.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 158880.
1Commscope
1Tr4400 Firmware
Jun 17, 2026
Aug 29, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
CommScope ARRIS TR4400 devices with firmware through A1.00.004-180301 are vulnerable to an authentication bypass to the administrative interface because they include the current base64 encoded password within http://192....Show more
CommScope ARRIS TR4400 devices with firmware through A1.00.004-180301 are vulnerable to an authentication bypass to the administrative interface because they include the current base64 encoded password within http://192.168.1.1/basic_sett.html. Any user connected to the Wi-Fi can exploit this.Show less
1Commscope
1Tr4400 Firmware
Jun 17, 2026
Aug 29, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
CommScope ARRIS TR4400 devices with firmware through A1.00.004-180301 are vulnerable to an authentication bypass to the administrative interface because they include the current base64 encoded password within http://192....Show more
CommScope ARRIS TR4400 devices with firmware through A1.00.004-180301 are vulnerable to an authentication bypass to the administrative interface because they include the current base64 encoded password within http://192.168.1.1/login.html. Any user connected to the Wi-Fi can exploit this.Show less
1Dlink
26600 Ap Firmware
Dwl 3600ap Firmware
Jun 17, 2026
Aug 1, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
An issue was discovered on D-Link 6600-AP and DWL-3600AP Ax 4.2.0.14 21/03/2019 devices. There is use of weak ciphers for SSH such as diffie-hellman-group1-sha1.
1Linux
1Linux Kernel
Jun 17, 2026
Jul 5, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Linux kernel 4.x (starting from 4.1) and 5.x before 5.0.8 allows Information Exposure (partial kernel address disclosure), leading to a KASLR bypass. Specifically, it is possible to extract the KASLR kernel image off...Show more
The Linux kernel 4.x (starting from 4.1) and 5.x before 5.0.8 allows Information Exposure (partial kernel address disclosure), leading to a KASLR bypass. Specifically, it is possible to extract the KASLR kernel image offset using the IP ID values the kernel produces for connection-less protocols (e.g., UDP and ICMP). When such traffic is sent to multiple destination IP addresses, it is possible to obtain hash collisions (of indices to the counter array) and thereby obtain the hashing key (via enumeration). This key contains enough bits from a kernel address (of a static variable) so when the key is extracted (via enumeration), the offset of the kernel image is exposed. This attack can be carried out remotely, by the attacker forcing the target device to send UDP or ICMP (or certain other) traffic to attacker-controlled IP addresses. Forcing a server to send UDP traffic is trivial if the server is a DNS server. ICMP traffic is trivial if the server answers ICMP Echo requests (ping). For client targets, if the target visits the attacker's web page, then WebRTC or gQUIC can be used to force UDP traffic to attacker-controlled IP addresses. NOTE: this attack against KASLR became viable in 4.1 because IP ID generation was changed to have a dependency on an address associated with a network namespace.Show less
1Linux
1Linux Kernel
Jun 17, 2026
Jul 5, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In the Linux kernel before 5.1.7, a device can be tracked by an attacker using the IP ID values the kernel produces for connection-less protocols (e.g., UDP and ICMP). When such traffic is sent to multiple destination IP...Show more
In the Linux kernel before 5.1.7, a device can be tracked by an attacker using the IP ID values the kernel produces for connection-less protocols (e.g., UDP and ICMP). When such traffic is sent to multiple destination IP addresses, it is possible to obtain hash collisions (of indices to the counter array) and thereby obtain the hashing key (via enumeration). An attack may be conducted by hosting a crafted web page that uses WebRTC or gQUIC to force UDP traffic to attacker-controlled IP addresses.Show less
1Dnnsoftware
1Dotnetnuke
Nov 7, 2025
Jul 3, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue exists because of an incomplete fix for CVE-2018-15811.
1Dnnsoftware
1Dotnetnuke
Nov 7, 2025
Jul 3, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters.
1Ibm
1Db2
Jun 17, 2026
Jul 1, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-F...Show more
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 158092.Show less
2Ivanti
Pulsesecure
2Connect Secure
Pulse Policy Secure
Nov 21, 2024
Jun 28, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Session data between cluster nodes during cluster synchronization is not properly encrypted in Pulse Secure Pulse Connect Secure (PCS) 8.3RX before 8.3R2 and Pulse Policy Secure (PPS) 5.4RX before 5.4R2. This is not appl...Show more
Session data between cluster nodes during cluster synchronization is not properly encrypted in Pulse Secure Pulse Connect Secure (PCS) 8.3RX before 8.3R2 and Pulse Policy Secure (PPS) 5.4RX before 5.4R2. This is not applicable to PCS 8.1RX, PPS 5.2RX, or stand-alone devices.Show less