← Back
CWE-326

455 CVEs • Abstraction: Class

Inadequate Encryption Strength

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

JSON object

Loading...

CVEs (455)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Qradar Security Information And Event Manager
May 13, 2026
Mar 1, 2017
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
IBM QRadar 7.2 uses outdated hashing algorithms to hash certain passwords, which could allow a local user to obtain and decrypt user credentials. IBM Reference #: 1997341.
1Apple
3Iphone Os
Mac Os XWatchos
May 13, 2026
Feb 20, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "Security" component, which makes it easier for a...Show more
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "Security" component, which makes it easier for attackers to bypass cryptographic protection mechanisms by leveraging use of the 3DES cipher.Show less
1Apple
1Iphone Os
May 13, 2026
Feb 20, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in certain Apple products. iOS before 10.1 is affected. The issue involves the "iTunes Backup" component, which improperly hashes passwords, making it easier to decrypt files.
1Ibm
4Security Access Manager 9.0 Firmware
Security Access Manager For MobileSecurity Access Manager For Web 7.0 Firmware+1 more
May 13, 2026
Feb 16, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM Security Access Manager for Web 7.0.0, 8.0.0, and 9.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM Reference #: 1996868.
1Ibm
1Security Appscan Source
May 13, 2026
Feb 1, 2017
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
IBM AppScan Source uses a one-way hash without salt to encrypt highly sensitive information, which could allow a local attacker to decrypt information more easily.
2Debian
Ruby Lang
2Debian Linux
Openssl
May 13, 2026
Jan 30, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The openssl gem for Ruby uses the same initialization vector (IV) in GCM Mode (aes-*-gcm) when the IV is set before the key, which makes it easier for context-dependent attackers to bypass the encryption protection mecha...Show more
The openssl gem for Ruby uses the same initialization vector (IV) in GCM Mode (aes-*-gcm) when the IV is set before the key, which makes it easier for context-dependent attackers to bypass the encryption protection mechanism.Show less
1Hiteksoftware
1Automize
May 13, 2026
Jan 23, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Information Disclosure can occur in sshProfiles.jsd in Hitek Software's Automize because of the Read attribute being set for Users. This allows an attacker to recover encrypted passwords for SSH/SFTP profiles. Verified i...Show more
Information Disclosure can occur in sshProfiles.jsd in Hitek Software's Automize because of the Read attribute being set for Users. This allows an attacker to recover encrypted passwords for SSH/SFTP profiles. Verified in all 10.x versions up to and including 10.25, and all 11.x versions up to and including 11.14.Show less
1Hiteksoftware
1Automize
May 13, 2026
Jan 23, 2017
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
Information Disclosure can occur in encryptionProfiles.jsd in Hitek Software's Automize because of the Read attribute being set for Users. This allows an attacker to recover encrypted passwords for GPG Encryption profile...Show more
Information Disclosure can occur in encryptionProfiles.jsd in Hitek Software's Automize because of the Read attribute being set for Users. This allows an attacker to recover encrypted passwords for GPG Encryption profiles. Verified in all 10.x versions up to and including 10.25, and all 11.x versions up to and including 11.14.Show less
1Hiteksoftware
1Automize
May 13, 2026
Jan 23, 2017
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
hitek.jar in Hitek Software's Automize uses weak encryption when encrypting SSH/SFTP and Encryption profile passwords. This allows an attacker to retrieve the encrypted passwords from sshProfiles.jsd and encryptionProfil...Show more
hitek.jar in Hitek Software's Automize uses weak encryption when encrypting SSH/SFTP and Encryption profile passwords. This allows an attacker to retrieve the encrypted passwords from sshProfiles.jsd and encryptionProfiles.jsd and decrypt them to recover cleartext passwords. All 10.x up to and including 10.25 and all 11.x up to and including 11.14 are verified to be affected.Show less
1Hiteksoftware
1Automize
May 13, 2026
Jan 23, 2017
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
Information Disclosure can occur in Hitek Software's Automize 10.x and 11.x passManager.jsd. Users have the Read attribute, which allows an attacker to recover the encrypted password to access the Password Manager.
1Google
1Chrome
May 6, 2026
Oct 14, 2016
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
SHA-1 is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of SHA-1 in TLS 1.2. NOTE: this CVE exists to provide a common i...Show more
SHA-1 is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of SHA-1 in TLS 1.2. NOTE: this CVE exists to provide a common identifier for referencing this SHA-1 issue; the existence of an identifier is not, by itself, a technology recommendation.Show less
1Huawei
7Ar Firmware
Quidway S5300 FirmwareQuidway S9300 Firmware+4 more
May 6, 2026
Oct 3, 2016
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Huawei AR routers with software before V200R007C00SPC100; Quidway S9300 routers with software before V200R009C00; S12700 routers with software before V200R008C00SPC500; S9300, Quidway S5300, and S5300 routers with softwa...Show more
Huawei AR routers with software before V200R007C00SPC100; Quidway S9300 routers with software before V200R009C00; S12700 routers with software before V200R008C00SPC500; S9300, Quidway S5300, and S5300 routers with software before V200R007C00; and S5700 routers with software before V200R007C00SPC500 makes it easier for remote authenticated administrators to obtain encryption keys and ciphertext passwords via vectors related to key storage.Show less
1Huawei
7Ar Firmware
Quidway S5300 FirmwareQuidway S9300 Firmware+4 more
May 6, 2026
Oct 3, 2016
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Huawei AR routers with software before V200R007C00SPC100; Quidway S9300 routers with software before V200R009C00; S12700 routers with software before V200R008C00SPC500; S9300, Quidway S5300, and S5300 routers with softwa...Show more
Huawei AR routers with software before V200R007C00SPC100; Quidway S9300 routers with software before V200R009C00; S12700 routers with software before V200R008C00SPC500; S9300, Quidway S5300, and S5300 routers with software before V200R007C00; and S5700 routers with software before V200R007C00SPC500 make it easier for remote authenticated administrators to obtain and decrypt passwords by leveraging selection of a reversible encryption algorithm.Show less
1Moxa
5Mgate Mb3170 Firmware
Mgate Mb3180 FirmwareMgate Mb3270 Firmware+2 more
May 6, 2026
Jul 15, 2016
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Moxa MGate MB3180 before 1.8, MGate MB3280 before 2.7, MGate MB3480 before 2.6, MGate MB3170 before 2.5, and MGate MB3270 before 2.7 use weak encryption, which allows remote attackers to bypass authentication via a brute...Show more
Moxa MGate MB3180 before 1.8, MGate MB3280 before 2.7, MGate MB3480 before 2.6, MGate MB3170 before 2.5, and MGate MB3270 before 2.7 use weak encryption, which allows remote attackers to bypass authentication via a brute-force series of guesses for a parameter value.Show less
1Clorius Controls A/s
1Java Web Client
May 6, 2026
Jan 17, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Clorius Controls Java web client before 01.00.0009g allows remote attackers to discover credentials by sniffing the network for cleartext-equivalent traffic.
1Invensys
1Wonderware Information Server
May 6, 2026
Aug 28, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 uses weak encryption, which allows local users to obtain sensitive information by reading a credential file.
1Invensys
1Wonderware Information Server
May 6, 2026
Aug 28, 2014
N/A· v4
N/A· v3
7.8 HIGH· v2
Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 uses weak encryption, which allows remote attackers to obtain sensitive information by reading a credential file.
9Fedoraproject
Filezilla ProjectMariadb+6 more
16Application Processing Engine Firmware
Cp1543 1 FirmwareEnterprise Linux+13 more
May 6, 2026
Jun 5, 2014
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key...Show more
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive information, via a crafted TLS handshake, aka the "CCS Injection" vulnerability.Show less
7Canonical
DebianFedoraproject+4 more
13Debian Linux
Enterprise Manager Ops CenterFedora+10 more
Apr 29, 2026
Feb 6, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, does not properly restrict...Show more
Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, does not properly restrict public values in Diffie-Hellman key exchanges, which makes it easier for remote attackers to bypass cryptographic protection mechanisms in ticket handling by leveraging use of a certain value.Show less
3Debian
LighttpdOpensuse
3Debian Linux
LighttpdOpensuse
Apr 29, 2026
Nov 8, 2013
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
lighttpd before 1.4.34, when SNI is enabled, configures weak SSL ciphers, which makes it easier for remote attackers to hijack sessions by inserting packets into the client-server data stream or obtain sensitive informat...Show more
lighttpd before 1.4.34, when SNI is enabled, configures weak SSL ciphers, which makes it easier for remote attackers to hijack sessions by inserting packets into the client-server data stream or obtain sensitive information by sniffing the network.Show less