CWE-326
455 CVEs • Abstraction: Class
Inadequate Encryption Strength
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
CVEs (455)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Broadcom 1Privileged Access Manager Jun 17, 2026 Jun 18, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Weak cryptography used for passwords in CA Privileged Access Manager 2.x reduces the complexity for password cracking. |
4Canonical DebianMozilla+1 more11Debian Linux Enterprise LinuxEnterprise Linux Desktop+8 moreNov 21, 2024 Jun 11, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Using remote content in encrypted messages can lead to the disclosure of plaintext. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8. |
Jenkins before versions 2.44, 2.32.2 uses AES ECB block cipher mode without IV for encrypting secrets which makes Jenkins and the stored secrets vulnerable to unnecessary risks (SECURITY-304). |
1Schneider Electric 1Ampla Manufacturing Execution System Nov 21, 2024 May 18, 2018 N/A· v4 3.9 LOW· v3 1.9 LOW· v2 Schneider Electric Ampla MES 6.4 provides capability to configure users and their privileges. When Ampla MES users are configured to use Simple Security, a weakness in the password hashing algorithm could be exploited to...Show more |
1Ibm 8San Volume Controller Firmware Spectrum VirtualizeSpectrum Virtualize For Public Cloud+5 moreNov 21, 2024 May 17, 2018 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products (6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) use weaker than expected cry...Show more |
IBM Security Guardium 10.0, 10.0.1, and 10.1 through 10.1.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 124675. |
1Tibco 1Datasynapse Gridserver Manager Nov 21, 2024 May 1, 2018 N/A· v4 6.8 MEDIUM· v3 4.3 MEDIUM· v2 The GridServer Broker, GridServer Driver, and GridServer Engine components of TIBCO Software Inc. TIBCO DataSynapse GridServer Manager contain vulnerabilities related to both the improper use of encryption mechanisms and...Show more |
IBM Rational Focal Point 6.4.0, 6.4.1, 6.5.1, 6.5.2, and 6.6.0 use a weak algorithm to hash passwords, which makes it easier for context-dependent attackers to obtain cleartext values via a brute-force attack. IBM X-Forc...Show more |
1Fortinet 2Forticlient Forticlient Sslvpn ClientNov 21, 2024 Apr 26, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Users' VPN authentication credentials are unsafely encrypted in Fortinet FortiClient for Windows 5.6.0 and below versions, FortiClient for Mac OSX 5.6.0 and below versions and FortiClient SSLVPN Client for Linux 4.4.2335...Show more |
1Ibm 2Rational Collaborative Lifecycle Management Rational Team ConcertNov 21, 2024 Apr 23, 2018 N/A· v4 8.8 HIGH· v3 4.0 MEDIUM· v2 IBM Team Concert (RTC) 5.0, 5.0.1, 5.0.2, 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, and 6.0.5 stores credentials for users using a weak encryption algorithm, which could allow an authenticated user to obtain highly sensitive info...Show more |
1Ibm 3Security Access Manager Firmware Security Access Manager For MobileSecurity Access Manager For Web FirmwareNov 21, 2024 Apr 23, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IBM Security Access Manager Appliance 8.0.0 through 8.0.1.6 and 9.0.0 through 9.0.3.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force I...Show more |
1Schneider Electric 57140cpu31110 Firmware 140cpu31110c Firmware140cpu43412u Firmware+54 moreJun 17, 2026 Apr 18, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Vulnerable hash algorithms exists in Schneider Electric's Modicon Premium, Modicon Quantum, Modicon M340, and BMXNOR0200 controllers in all versions of the communication modules. The algorithm used to encrypt the passwor...Show more |
1Mcafee 1Network Security Manager Nov 21, 2024 Apr 4, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Cryptanalysis vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows attackers to view confidential information via insecure use of RC4 encryption cyphers. |
IBM BigFix Remote Control before Interim Fix pack 9.1.2-TIV-IBRC912-IF0001 makes it easier for man-in-the-middle attackers to decrypt traffic by leveraging a weakness in its encryption protocol. IBM X-Force ID: 105197. |
1Ibm 8Rational Collaborative Lifecycle Management Rational Doors Next GenerationRational Engineering Lifecycle Manager+5 moreNov 21, 2024 Mar 20, 2018 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 IBM Rational Collaborative Lifecycle Management (CLM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, 6.0.x before 6.0.1 iFix5, and 6.0.2 before iFix2; Rational Quality Manager (RQM) 4.0.x before 4.0.7 iFix10, 5.0....Show more |
1Siemens 9Digsi 4 En100 Ethernet Module Dnp3 FirmwareEn100 Ethernet Module Iec 104 Firmware+6 moreNov 21, 2024 Mar 8, 2018 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 A vulnerability has been identified in DIGSI 4 (All versions < V4.92), EN100 Ethernet module DNP3 variant (All versions < V1.05.00), EN100 Ethernet module IEC 104 variant (All versions), EN100 Ethernet module IEC 61850 v...Show more |
1Belden 134Hirschmann M1 8mm Sc Hirschmann M1 8sfpHirschmann M1 8sm Sc+131 moreJun 17, 2026 Mar 6, 2018 N/A· v4 6.5 MEDIUM· v3 5.8 MEDIUM· v2 An Inadequate Encryption Strength issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, and OCTOPUS Classic Platform Switches. An inadequate encryption strength vulnerability in the web...Show more |
2Google Nvidia2Android Shield Tv FirmwareNov 21, 2024 Mar 6, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 NVIDIA Security Engine contains a vulnerability in the Deterministic Random Bit Generator (DRBG) where the DRBG does not properly initialize and store or transmits sensitive data using a weakened encryption scheme that i...Show more |
comforte SWAP 1049 through 1069 and 20.0.0 through 21.5.3 (as used in SSLOBJ on HPE NonStop SSL T0910, and in the comforte SecurCS, SecurFTP, SecurLib/SSL-AT, and SecurTN products), after executing the RELOAD CERTIFICATE...Show more |
1Ibm 1Security Guardium Big Data Intelligence Nov 21, 2024 Feb 27, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 IBM Security Guardium Big Data Intelligence (SonarG) 3.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 139003. |