CWE-326
467 CVEs • Abstraction: Class
Inadequate Encryption Strength
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
CVEs (467)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Vaultive 1Office 365 Security May 13, 2026 May 3, 2017 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 PGP/MIME encrypted messages injected into a Vaultive O365 (before 4.5.21) frontend via IMAP or SMTP have their Content-Type changed from 'Content-Type: multipart/encrypted; protocol="application/pgp-encrypted"; boundary=...Show more |
On the TP-Link TL-SG108E 1.0, admin network communications are RC4 encoded, even though RC4 is deprecated. This affects the 1.1.2 Build 20141017 Rel.50749 firmware. |
1Aveva 1Wonderware Intouch Access Anywhere May 13, 2026 Apr 20, 2017 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 An Inadequate Encryption Strength issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. The software will connect via Transport Layer Security without verifying the peer...Show more |
OSRAM SYLVANIA Osram Lightify Pro before 2016-07-26 uses only 8 hex digits for a PSK. |
An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves the "Pasteboard" component. It allows physically proximate attackers to read the pasteboard by leveraging the use of an e...Show more |
An issue was discovered in certain Apple products. Pages before 6.1, Numbers before 4.1, and Keynote before 7.1 on macOS and Pages before 3.1, Numbers before 3.1, and Keynote before 3.1 on iOS are affected. The issue inv...Show more |
An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves the Simple Certificate Enrollment Protocol (SCEP) implementation in the "Profiles" component. It allows remote attacke...Show more |
The Mxit protocol uses weak encryption when encrypting user passwords, which might allow attackers to (1) decrypt hashed passwords by leveraging knowledge of client registration codes or (2) gain login access by eavesdro...Show more |
go-jose before 1.0.4 suffers from an invalid curve attack for the ECDH-ES algorithm. When deriving a shared key using ECDH-ES for an encrypted message, go-jose neglected to check that the received public key on a message...Show more |
1Eviewgps 1Ev 07s Gps Tracker Firmware May 13, 2026 Mar 27, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Due to a lack of standard encryption when transmitting sensitive information over the internet to a centralized monitoring service, the Eview EV-07S GPS Tracker discloses personally identifying information, such as GPS d...Show more |
3Fedoraproject OpensusePercona3Fedora LeapXtrabackupMay 13, 2026 Mar 23, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 xbcrypt in Percona XtraBackup before 2.3.6 and 2.4.x before 2.4.5 does not properly set the initialization vector (IV) for encryption, which makes it easier for context-dependent attackers to obtain sensitive information...Show more |
An issue was discovered in sysPass 2.x before 2.1, in which an algorithm was never sufficiently reviewed by cryptographers. The fact that inc/SP/Core/Crypt.class is using the MCRYPT_RIJNDAEL_256() function (the 256-bit b...Show more |
1Ibm 1Qradar Security Information And Event Manager May 13, 2026 Mar 1, 2017 N/A· v4 7.8 HIGH· v3 2.1 LOW· v2 IBM QRadar 7.2 uses outdated hashing algorithms to hash certain passwords, which could allow a local user to obtain and decrypt user credentials. IBM Reference #: 1997341. |
1Apple 3Iphone Os Mac Os XWatchosMay 13, 2026 Feb 20, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "Security" component, which makes it easier for a...Show more |
An issue was discovered in certain Apple products. iOS before 10.1 is affected. The issue involves the "iTunes Backup" component, which improperly hashes passwords, making it easier to decrypt files. |
1Ibm 4Security Access Manager 9.0 Firmware Security Access Manager For MobileSecurity Access Manager For Web 7.0 Firmware+1 moreMay 13, 2026 Feb 16, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IBM Security Access Manager for Web 7.0.0, 8.0.0, and 9.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM Reference #: 1996868. |
IBM AppScan Source uses a one-way hash without salt to encrypt highly sensitive information, which could allow a local attacker to decrypt information more easily. |
2Debian Ruby Lang2Debian Linux OpensslMay 13, 2026 Jan 30, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The openssl gem for Ruby uses the same initialization vector (IV) in GCM Mode (aes-*-gcm) when the IV is set before the key, which makes it easier for context-dependent attackers to bypass the encryption protection mecha...Show more |
Information Disclosure can occur in sshProfiles.jsd in Hitek Software's Automize because of the Read attribute being set for Users. This allows an attacker to recover encrypted passwords for SSH/SFTP profiles. Verified i...Show more |
Information Disclosure can occur in encryptionProfiles.jsd in Hitek Software's Automize because of the Read attribute being set for Users. This allows an attacker to recover encrypted passwords for GPG Encryption profile...Show more |