← Back
CWE-326

455 CVEs • Abstraction: Class

Inadequate Encryption Strength

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

JSON object

Loading...

CVEs (455)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Commscope
1Tr4400 Firmware
Jun 17, 2026
Aug 29, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
CommScope ARRIS TR4400 devices with firmware through A1.00.004-180301 are vulnerable to an authentication bypass to the administrative interface because they include the current base64 encoded password within http://192....Show more
CommScope ARRIS TR4400 devices with firmware through A1.00.004-180301 are vulnerable to an authentication bypass to the administrative interface because they include the current base64 encoded password within http://192.168.1.1/login.html. Any user connected to the Wi-Fi can exploit this.Show less
1Dlink
26600 Ap Firmware
Dwl 3600ap Firmware
Jun 17, 2026
Aug 1, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
An issue was discovered on D-Link 6600-AP and DWL-3600AP Ax 4.2.0.14 21/03/2019 devices. There is use of weak ciphers for SSH such as diffie-hellman-group1-sha1.
1Linux
1Linux Kernel
Jun 17, 2026
Jul 5, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Linux kernel 4.x (starting from 4.1) and 5.x before 5.0.8 allows Information Exposure (partial kernel address disclosure), leading to a KASLR bypass. Specifically, it is possible to extract the KASLR kernel image off...Show more
The Linux kernel 4.x (starting from 4.1) and 5.x before 5.0.8 allows Information Exposure (partial kernel address disclosure), leading to a KASLR bypass. Specifically, it is possible to extract the KASLR kernel image offset using the IP ID values the kernel produces for connection-less protocols (e.g., UDP and ICMP). When such traffic is sent to multiple destination IP addresses, it is possible to obtain hash collisions (of indices to the counter array) and thereby obtain the hashing key (via enumeration). This key contains enough bits from a kernel address (of a static variable) so when the key is extracted (via enumeration), the offset of the kernel image is exposed. This attack can be carried out remotely, by the attacker forcing the target device to send UDP or ICMP (or certain other) traffic to attacker-controlled IP addresses. Forcing a server to send UDP traffic is trivial if the server is a DNS server. ICMP traffic is trivial if the server answers ICMP Echo requests (ping). For client targets, if the target visits the attacker's web page, then WebRTC or gQUIC can be used to force UDP traffic to attacker-controlled IP addresses. NOTE: this attack against KASLR became viable in 4.1 because IP ID generation was changed to have a dependency on an address associated with a network namespace.Show less
1Linux
1Linux Kernel
Jun 17, 2026
Jul 5, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In the Linux kernel before 5.1.7, a device can be tracked by an attacker using the IP ID values the kernel produces for connection-less protocols (e.g., UDP and ICMP). When such traffic is sent to multiple destination IP...Show more
In the Linux kernel before 5.1.7, a device can be tracked by an attacker using the IP ID values the kernel produces for connection-less protocols (e.g., UDP and ICMP). When such traffic is sent to multiple destination IP addresses, it is possible to obtain hash collisions (of indices to the counter array) and thereby obtain the hashing key (via enumeration). An attack may be conducted by hosting a crafted web page that uses WebRTC or gQUIC to force UDP traffic to attacker-controlled IP addresses.Show less
1Dnnsoftware
1Dotnetnuke
Nov 7, 2025
Jul 3, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue exists because of an incomplete fix for CVE-2018-15811.
1Dnnsoftware
1Dotnetnuke
Nov 7, 2025
Jul 3, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters.
1Ibm
1Db2
Jun 17, 2026
Jul 1, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-F...Show more
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 158092.Show less
2Ivanti
Pulsesecure
2Connect Secure
Pulse Policy Secure
Nov 21, 2024
Jun 28, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Session data between cluster nodes during cluster synchronization is not properly encrypted in Pulse Secure Pulse Connect Secure (PCS) 8.3RX before 8.3R2 and Pulse Policy Secure (PPS) 5.4RX before 5.4R2. This is not appl...Show more
Session data between cluster nodes during cluster synchronization is not properly encrypted in Pulse Secure Pulse Connect Secure (PCS) 8.3RX before 8.3R2 and Pulse Policy Secure (PPS) 5.4RX before 5.4R2. This is not applicable to PCS 8.1RX, PPS 5.2RX, or stand-alone devices.Show less
1Ibm
1Security Access Manager
Jun 17, 2026
Jun 25, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
IBM Security Access Manager 9.0.1 through 9.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 158512.
1Tp Link
1Tl Wr1043nd Firmware
Jun 17, 2026
Jun 19, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered on TP-Link TL-WR1043ND V2 devices. The credentials can be easily decoded and cracked by brute-force, WordList, or Rainbow Table attacks. Specifically, credentials in the "Authorization" cookie are...Show more
An issue was discovered on TP-Link TL-WR1043ND V2 devices. The credentials can be easily decoded and cracked by brute-force, WordList, or Rainbow Table attacks. Specifically, credentials in the "Authorization" cookie are encoded with URL encoding and base64, leading to easy decoding. Also, the username is cleartext, and the password is hashed with the MD5 algorithm (after decoding of the URL encoded string with base64).Show less
1Ibm
1Api Connect
Jun 17, 2026
May 29, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM API Connect 5.0.0.0 through 5.0.8.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 159944.
1Computrols
1Computrols Building Automation Software
Jun 17, 2026
May 23, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Computrols CBAS 18.0.0 mishandles password hashes. The approach is MD5 with a pw prefix, e.g., if the password is admin, it will calculate the MD5 hash of pwadmin and store it in a MySQL database.
1Gitlab
1Gitlab
Jun 17, 2026
May 16, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. The construction of the HMAC key was insecurely derived.
1Ibm
1Rational Engineering Lifecycle Manager
Nov 21, 2024
May 1, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM Rational Engineering Lifecycle Manager 6.0 through 6.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 143798.
1Ibm
1Api Connect
Nov 21, 2024
Apr 29, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM API Connect 2018.1 and 2018.4.1.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 155078.
1Ibm
1Websphere Mq
Nov 21, 2024
Apr 15, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
IBM WebShere MQ 9.1.0.0, 9.1.0.1, 9.1.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 152925.
1Airsonic Project
1Airsonic
Jun 17, 2026
Apr 7, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Airsonic 10.2.1 uses Spring's default remember-me mechanism based on MD5, with a fixed key of airsonic in GlobalSecurityConfig.java. An attacker able to capture cookies might be able to trivially bruteforce offline the p...Show more
Airsonic 10.2.1 uses Spring's default remember-me mechanism based on MD5, with a fixed key of airsonic in GlobalSecurityConfig.java. An attacker able to capture cookies might be able to trivially bruteforce offline the passwords of associated users.Show less
1Ibm
1Infosphere Streams
Nov 21, 2024
Mar 21, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
IBM InfoSphere Streams 4.2.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 134632.
1Ibm
1Security Identity Governance And Intelligence
Nov 21, 2024
Feb 21, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance supports interaction between multiple actors and allows those actors to negotiate which algorithm should be used as a protection mec...Show more
IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance supports interaction between multiple actors and allows those actors to negotiate which algorithm should be used as a protection mechanism such as encryption or authentication, but it does not select the strongest algorithm that is available to both parties. IBM X-Force ID: 153388.Show less
1Seafile
1Seafile
Nov 21, 2024
Feb 21, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Seafile through 6.2.11 always uses the same Initialization Vector (IV) with Cipher Block Chaining (CBC) Mode to encrypt private data, making it easier to conduct chosen-plaintext attacks or dictionary attacks.