CWE-326
455 CVEs • Abstraction: Class
Inadequate Encryption Strength
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
CVEs (455)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
System Manager in Avaya Aura before 7.1.2 does not properly use SSL in conjunction with authentication, which allows remote attackers to bypass intended Remote Method Invocation (RMI) restrictions, aka SMGR-26896. |
3Canonical DebianDlitz3Debian Linux PycryptoUbuntu LinuxJun 17, 2026 Feb 3, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 lib/Crypto/PublicKey/ElGamal.py in PyCrypto through 2.6.1 generates weak ElGamal key parameters, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not have semantic security...Show more |
In the Procter & Gamble "Oral-B App" (aka com.pg.oralb.oralbapp) application 5.0.0 for Android, AES encryption with static parameters is used to secure the locally stored shared preferences. An attacker can gain access t...Show more |
2Debian Ibm2Debian Linux Security Key Lifecycle ManagerNov 21, 2024 Jan 4, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 133559. |
1Ibm 1Security Key Lifecycle Manager Nov 21, 2024 Jan 4, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 133557. |
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution |
A vulnerability in Trend Micro ScanMail for Exchange 12.0 exists in which some communications to the update servers are not encrypted. |
IBM Security Guardium 9.0, 9.1, and 9.5 supports interaction between multiple actors and allows those actors to negotiate which algorithm should be used as a protection mechanism such as encryption or authentication, but...Show more |
An issue was discovered in the software on Vaultek Gun Safe VT20i products. There is no encryption of the session between the Android application and the safe. The website and marketing materials advertise that this comm...Show more |
An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. The password encryption method can be retrieved from the firmware. This encryption method is based on a chall value that is sent in cleartext as a POS...Show more |
1Huawei 2Secospace Usg6300 Firmware Secospace Usg6600 FirmwareMay 13, 2026 Nov 22, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Huawei USG6300 V100R001C30SPC300 and USG6600 with software of V100R001C30SPC500,V100R001C30SPC600,V100R001C30SPC700,V100R001C30SPC800 have a weak algorithm vulnerability. Attackers may exploit the weak algorithm vulnerab...Show more |
1Ibm 1Storwize Unified V7000 Software May 13, 2026 Oct 24, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IBM System Storage Storwize V7000 Unified (V7000U) 1.5 and 1.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 126868. |
WordPress through 4.8.2 uses a weak MD5-based password hashing algorithm, which makes it easier for attackers to determine cleartext values by leveraging access to the hash values. NOTE: the approach to changing this may...Show more |
1Philips 1Hue Bridge Bsb002 Firmware May 13, 2026 Oct 1, 2017 N/A· v4 7.5 HIGH· v3 7.9 HIGH· v2 Lack of Transport Encryption in the public API in Philips Hue Bridge BSB002 SW 1707040932 allows remote attackers to read API keys (and consequently bypass the pushlink protection mechanism, and obtain complete control o...Show more |
1Mirion 8Dmc 3000 Transmitter Firmware Drm 1/2 FirmwareDrm 2 Firmware+5 moreMay 13, 2026 Sep 20, 2017 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 An Inadequate Encryption Strength issue was discovered in Mirion Technologies DMC 3000 Transmitter Module, iPam Transmitter f/DMC 2000, RDS-31 iTX and variants (including RSD31-AM Package), DRM-1/2 and variants (includin...Show more |
1Samsung 4Srn 1000 Firmware Srn 1670d FirmwareSrn 470d Firmware+1 moreMay 13, 2026 Sep 11, 2017 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 On Samsung NVR devices, remote attackers can read the MD5 password hash of the 'admin' account via certain szUserName JSON data to cgi-bin/main-cgi, and login to the device with that hash in the szUserPasswd parameter. |
1Simplesamlphp 1Simplesamlphp May 13, 2026 Sep 1, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The aesEncrypt method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.x through 1.14.11 makes it easier for context-dependent attackers to bypass the encryption protection mechanism by leveraging use of the firs...Show more |
1Telerik 1Ui For Asp.net Ajax Apr 21, 2026 Aug 23, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload encryption, which allows remote attackers to perform arbitrary file uploads or execute arbitrary co...Show more |
In all Qualcomm products with Android releases from CAF using the Linux kernel, insecure ciphersuites were included in the default configuration. |
In all Qualcomm products with Android releases from CAF using the Linux kernel, a rollback vulnerability potentially exists in Full Disk Encryption. |