CWE-326
467 CVEs • Abstraction: Class
Inadequate Encryption Strength
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
CVEs (467)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An issue was discovered in the software on Vaultek Gun Safe VT20i products. There is no encryption of the session between the Android application and the safe. The website and marketing materials advertise that this comm...Show more |
An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. The password encryption method can be retrieved from the firmware. This encryption method is based on a chall value that is sent in cleartext as a POS...Show more |
1Huawei 2Secospace Usg6300 Firmware Secospace Usg6600 FirmwareMay 13, 2026 Nov 22, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Huawei USG6300 V100R001C30SPC300 and USG6600 with software of V100R001C30SPC500,V100R001C30SPC600,V100R001C30SPC700,V100R001C30SPC800 have a weak algorithm vulnerability. Attackers may exploit the weak algorithm vulnerab...Show more |
1Ibm 1Storwize Unified V7000 Software May 13, 2026 Oct 24, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IBM System Storage Storwize V7000 Unified (V7000U) 1.5 and 1.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 126868. |
WordPress through 4.8.2 uses a weak MD5-based password hashing algorithm, which makes it easier for attackers to determine cleartext values by leveraging access to the hash values. NOTE: the approach to changing this may...Show more |
1Philips 1Hue Bridge Bsb002 Firmware May 13, 2026 Oct 1, 2017 N/A· v4 7.5 HIGH· v3 7.9 HIGH· v2 Lack of Transport Encryption in the public API in Philips Hue Bridge BSB002 SW 1707040932 allows remote attackers to read API keys (and consequently bypass the pushlink protection mechanism, and obtain complete control o...Show more |
1Mirion 8Dmc 3000 Transmitter Firmware Drm 1/2 FirmwareDrm 2 Firmware+5 moreMay 13, 2026 Sep 20, 2017 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 An Inadequate Encryption Strength issue was discovered in Mirion Technologies DMC 3000 Transmitter Module, iPam Transmitter f/DMC 2000, RDS-31 iTX and variants (including RSD31-AM Package), DRM-1/2 and variants (includin...Show more |
1Samsung 4Srn 1000 Firmware Srn 1670d FirmwareSrn 470d Firmware+1 moreMay 13, 2026 Sep 11, 2017 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 On Samsung NVR devices, remote attackers can read the MD5 password hash of the 'admin' account via certain szUserName JSON data to cgi-bin/main-cgi, and login to the device with that hash in the szUserPasswd parameter. |
1Simplesamlphp 1Simplesamlphp May 13, 2026 Sep 1, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The aesEncrypt method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.x through 1.14.11 makes it easier for context-dependent attackers to bypass the encryption protection mechanism by leveraging use of the firs...Show more |
1Telerik 1Ui For Asp.net Ajax Apr 21, 2026 Aug 23, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload encryption, which allows remote attackers to perform arbitrary file uploads or execute arbitrary co...Show more |
In all Qualcomm products with Android releases from CAF using the Linux kernel, insecure ciphersuites were included in the default configuration. |
In all Qualcomm products with Android releases from CAF using the Linux kernel, a rollback vulnerability potentially exists in Full Disk Encryption. |
IBM Tivoli Endpoint Manager uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 123903. |
Apache OpenMeetings 1.0.0 uses not very strong cryptographic storage, captcha is not used in registration and forget password dialogs and auth forms missing brute force protection. |
1Ge 10Multilin Sr 369 Motor Protection Relay Firmware Multilin Sr 469 Motor Protection Relay FirmwareMultilin Sr 489 Generator Protection Relay Firmware+7 moreMay 13, 2026 Jun 30, 2017 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 A Weak Cryptography for Passwords issue was discovered in General Electric (GE) Multilin SR 750 Feeder Protection Relay, firmware versions prior to Version 7.47; SR 760 Feeder Protection Relay, firmware versions prior to...Show more |
1Rockwellautomation 201763 L16awa Series A 1763 L16awa Series B1763 L16bbb Series A+17 moreJun 3, 2026 Jun 30, 2017 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 A Weak Password Requirements issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-logic controllers 1763-L16AWA, Series A and B, Version 16.00 and prior versions; 1763-L16BBB, Series A a...Show more |
1Ibm 1Tivoli Federated Identity Manager May 13, 2026 Jun 8, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IBM Tivoli Federated Identity Manager 6.2 is affected by a vulnerability due to a missing secure attribute in encrypted session (SSL) cookie. IBM X-Force ID: 125731. |
1Ibm 1Bigfix Security Compliance Analytics May 13, 2026 Jun 8, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 IBM BigFix Compliance Analytics 1.9.79 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 123431. |
1Ibm 1Security Access Manager 9.0 Firmware May 13, 2026 Jun 7, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 IBM Security Access Manager for Web 9.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 114462. |
1Dolibarr 1Dolibarr Erp/crm May 13, 2026 May 10, 2017 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Dolibarr ERP/CRM 4.0.4 stores passwords with the MD5 algorithm, which makes brute-force attacks easier. |