CWE-326
467 CVEs • Abstraction: Class
Inadequate Encryption Strength
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
CVEs (467)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Fortinet 2Forticlient Forticlient Sslvpn ClientNov 21, 2024 Apr 26, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Users' VPN authentication credentials are unsafely encrypted in Fortinet FortiClient for Windows 5.6.0 and below versions, FortiClient for Mac OSX 5.6.0 and below versions and FortiClient SSLVPN Client for Linux 4.4.2335...Show more |
1Ibm 2Rational Collaborative Lifecycle Management Rational Team ConcertNov 21, 2024 Apr 23, 2018 N/A· v4 8.8 HIGH· v3 4.0 MEDIUM· v2 IBM Team Concert (RTC) 5.0, 5.0.1, 5.0.2, 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, and 6.0.5 stores credentials for users using a weak encryption algorithm, which could allow an authenticated user to obtain highly sensitive info...Show more |
1Ibm 3Security Access Manager Firmware Security Access Manager For MobileSecurity Access Manager For Web FirmwareNov 21, 2024 Apr 23, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IBM Security Access Manager Appliance 8.0.0 through 8.0.1.6 and 9.0.0 through 9.0.3.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force I...Show more |
1Schneider Electric 57140cpu31110 Firmware 140cpu31110c Firmware140cpu43412u Firmware+54 moreJun 17, 2026 Apr 18, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Vulnerable hash algorithms exists in Schneider Electric's Modicon Premium, Modicon Quantum, Modicon M340, and BMXNOR0200 controllers in all versions of the communication modules. The algorithm used to encrypt the passwor...Show more |
1Mcafee 1Network Security Manager Nov 21, 2024 Apr 4, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Cryptanalysis vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows attackers to view confidential information via insecure use of RC4 encryption cyphers. |
IBM BigFix Remote Control before Interim Fix pack 9.1.2-TIV-IBRC912-IF0001 makes it easier for man-in-the-middle attackers to decrypt traffic by leveraging a weakness in its encryption protocol. IBM X-Force ID: 105197. |
1Ibm 8Rational Collaborative Lifecycle Management Rational Doors Next GenerationRational Engineering Lifecycle Manager+5 moreNov 21, 2024 Mar 20, 2018 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 IBM Rational Collaborative Lifecycle Management (CLM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, 6.0.x before 6.0.1 iFix5, and 6.0.2 before iFix2; Rational Quality Manager (RQM) 4.0.x before 4.0.7 iFix10, 5.0....Show more |
1Siemens 9Digsi 4 En100 Ethernet Module Dnp3 FirmwareEn100 Ethernet Module Iec 104 Firmware+6 moreNov 21, 2024 Mar 8, 2018 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 A vulnerability has been identified in DIGSI 4 (All versions < V4.92), EN100 Ethernet module DNP3 variant (All versions < V1.05.00), EN100 Ethernet module IEC 104 variant (All versions), EN100 Ethernet module IEC 61850 v...Show more |
1Belden 134Hirschmann M1 8mm Sc Hirschmann M1 8sfpHirschmann M1 8sm Sc+131 moreJun 17, 2026 Mar 6, 2018 N/A· v4 6.5 MEDIUM· v3 5.8 MEDIUM· v2 An Inadequate Encryption Strength issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, and OCTOPUS Classic Platform Switches. An inadequate encryption strength vulnerability in the web...Show more |
2Google Nvidia2Android Shield Tv FirmwareNov 21, 2024 Mar 6, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 NVIDIA Security Engine contains a vulnerability in the Deterministic Random Bit Generator (DRBG) where the DRBG does not properly initialize and store or transmits sensitive data using a weakened encryption scheme that i...Show more |
comforte SWAP 1049 through 1069 and 20.0.0 through 21.5.3 (as used in SSLOBJ on HPE NonStop SSL T0910, and in the comforte SecurCS, SecurFTP, SecurLib/SSL-AT, and SecurTN products), after executing the RELOAD CERTIFICATE...Show more |
1Ibm 1Security Guardium Big Data Intelligence Nov 21, 2024 Feb 27, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 IBM Security Guardium Big Data Intelligence (SonarG) 3.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 139003. |
System Manager in Avaya Aura before 7.1.2 does not properly use SSL in conjunction with authentication, which allows remote attackers to bypass intended Remote Method Invocation (RMI) restrictions, aka SMGR-26896. |
3Canonical DebianDlitz3Debian Linux PycryptoUbuntu LinuxJun 17, 2026 Feb 3, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 lib/Crypto/PublicKey/ElGamal.py in PyCrypto through 2.6.1 generates weak ElGamal key parameters, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not have semantic security...Show more |
In the Procter & Gamble "Oral-B App" (aka com.pg.oralb.oralbapp) application 5.0.0 for Android, AES encryption with static parameters is used to secure the locally stored shared preferences. An attacker can gain access t...Show more |
2Debian Ibm2Debian Linux Security Key Lifecycle ManagerNov 21, 2024 Jan 4, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 133559. |
1Ibm 1Security Key Lifecycle Manager Nov 21, 2024 Jan 4, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 133557. |
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution |
A vulnerability in Trend Micro ScanMail for Exchange 12.0 exists in which some communications to the update servers are not encrypted. |
IBM Security Guardium 9.0, 9.1, and 9.5 supports interaction between multiple actors and allows those actors to negotiate which algorithm should be used as a protection mechanism such as encryption or authentication, but...Show more |