← Back
CWE-326

467 CVEs • Abstraction: Class

Inadequate Encryption Strength

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

JSON object

Loading...

CVEs (467)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hiteksoftware
1Automize
May 13, 2026
Jan 23, 2017
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
hitek.jar in Hitek Software's Automize uses weak encryption when encrypting SSH/SFTP and Encryption profile passwords. This allows an attacker to retrieve the encrypted passwords from sshProfiles.jsd and encryptionProfil...Show more
hitek.jar in Hitek Software's Automize uses weak encryption when encrypting SSH/SFTP and Encryption profile passwords. This allows an attacker to retrieve the encrypted passwords from sshProfiles.jsd and encryptionProfiles.jsd and decrypt them to recover cleartext passwords. All 10.x up to and including 10.25 and all 11.x up to and including 11.14 are verified to be affected.Show less
1Hiteksoftware
1Automize
May 13, 2026
Jan 23, 2017
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
Information Disclosure can occur in Hitek Software's Automize 10.x and 11.x passManager.jsd. Users have the Read attribute, which allows an attacker to recover the encrypted password to access the Password Manager.
1Google
1Chrome
May 6, 2026
Oct 14, 2016
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
SHA-1 is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of SHA-1 in TLS 1.2. NOTE: this CVE exists to provide a common i...Show more
SHA-1 is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of SHA-1 in TLS 1.2. NOTE: this CVE exists to provide a common identifier for referencing this SHA-1 issue; the existence of an identifier is not, by itself, a technology recommendation.Show less
1Huawei
7Ar Firmware
Quidway S5300 FirmwareQuidway S9300 Firmware+4 more
May 6, 2026
Oct 3, 2016
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Huawei AR routers with software before V200R007C00SPC100; Quidway S9300 routers with software before V200R009C00; S12700 routers with software before V200R008C00SPC500; S9300, Quidway S5300, and S5300 routers with softwa...Show more
Huawei AR routers with software before V200R007C00SPC100; Quidway S9300 routers with software before V200R009C00; S12700 routers with software before V200R008C00SPC500; S9300, Quidway S5300, and S5300 routers with software before V200R007C00; and S5700 routers with software before V200R007C00SPC500 makes it easier for remote authenticated administrators to obtain encryption keys and ciphertext passwords via vectors related to key storage.Show less
1Huawei
7Ar Firmware
Quidway S5300 FirmwareQuidway S9300 Firmware+4 more
May 6, 2026
Oct 3, 2016
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Huawei AR routers with software before V200R007C00SPC100; Quidway S9300 routers with software before V200R009C00; S12700 routers with software before V200R008C00SPC500; S9300, Quidway S5300, and S5300 routers with softwa...Show more
Huawei AR routers with software before V200R007C00SPC100; Quidway S9300 routers with software before V200R009C00; S12700 routers with software before V200R008C00SPC500; S9300, Quidway S5300, and S5300 routers with software before V200R007C00; and S5700 routers with software before V200R007C00SPC500 make it easier for remote authenticated administrators to obtain and decrypt passwords by leveraging selection of a reversible encryption algorithm.Show less
1Moxa
5Mgate Mb3170 Firmware
Mgate Mb3180 FirmwareMgate Mb3270 Firmware+2 more
May 6, 2026
Jul 15, 2016
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Moxa MGate MB3180 before 1.8, MGate MB3280 before 2.7, MGate MB3480 before 2.6, MGate MB3170 before 2.5, and MGate MB3270 before 2.7 use weak encryption, which allows remote attackers to bypass authentication via a brute...Show more
Moxa MGate MB3180 before 1.8, MGate MB3280 before 2.7, MGate MB3480 before 2.6, MGate MB3170 before 2.5, and MGate MB3270 before 2.7 use weak encryption, which allows remote attackers to bypass authentication via a brute-force series of guesses for a parameter value.Show less
1Clorius Controls A/s
1Java Web Client
May 6, 2026
Jan 17, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Clorius Controls Java web client before 01.00.0009g allows remote attackers to discover credentials by sniffing the network for cleartext-equivalent traffic.
1Invensys
1Wonderware Information Server
May 6, 2026
Aug 28, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 uses weak encryption, which allows local users to obtain sensitive information by reading a credential file.
1Invensys
1Wonderware Information Server
May 6, 2026
Aug 28, 2014
N/A· v4
N/A· v3
7.8 HIGH· v2
Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 uses weak encryption, which allows remote attackers to obtain sensitive information by reading a credential file.
9Fedoraproject
Filezilla ProjectMariadb+6 more
16Application Processing Engine Firmware
Cp1543 1 FirmwareEnterprise Linux+13 more
May 6, 2026
Jun 5, 2014
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key...Show more
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive information, via a crafted TLS handshake, aka the "CCS Injection" vulnerability.Show less
7Canonical
DebianFedoraproject+4 more
13Debian Linux
Enterprise Manager Ops CenterFedora+10 more
Apr 29, 2026
Feb 6, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, does not properly restrict...Show more
Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, does not properly restrict public values in Diffie-Hellman key exchanges, which makes it easier for remote attackers to bypass cryptographic protection mechanisms in ticket handling by leveraging use of a certain value.Show less
3Debian
LighttpdOpensuse
3Debian Linux
LighttpdOpensuse
Apr 29, 2026
Nov 8, 2013
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
lighttpd before 1.4.34, when SNI is enabled, configures weak SSL ciphers, which makes it easier for remote attackers to hijack sessions by inserting packets into the client-server data stream or obtain sensitive informat...Show more
lighttpd before 1.4.34, when SNI is enabled, configures weak SSL ciphers, which makes it easier for remote attackers to hijack sessions by inserting packets into the client-server data stream or obtain sensitive information by sniffing the network.Show less
4Canonical
FujitsuMozilla+1 more
16Communications Application Session Controller
FirefoxHttp Server+13 more
Apr 29, 2026
Mar 15, 2013
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct plaintext-recovery attacks via statistical analysis of ciphertext in a l...Show more
The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct plaintext-recovery attacks via statistical analysis of ciphertext in a large number of sessions that use the same plaintext.Show less
4Canonical
MozillaOpensuse+1 more
9Firefox
Linux Enterprise DesktopLinux Enterprise Server+6 more
Apr 29, 2026
Jan 13, 2013
N/A· v4
N/A· v3
9.3 HIGH· v2
The nsSOCKSSocketInfo::ConnectToProxy function in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 17.x before 17.0.2, and SeaMonkey before 2.15 does not ensure thre...Show more
The nsSOCKSSocketInfo::ConnectToProxy function in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 17.x before 17.0.2, and SeaMonkey before 2.15 does not ensure thread safety for SSL sessions, which allows remote attackers to execute arbitrary code via crafted data, as demonstrated by e-mail message data.Show less
9Canonical
DebianGoogle+6 more
15Chrome
CurlDebian Linux+12 more
Apr 29, 2026
Sep 6, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initializa...Show more
The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a "BEAST" attack.Show less
4Apple
CanonicalFedoraproject+1 more
4Fedora
Mac Os XNeon+1 more
Apr 23, 2026
Aug 21, 2009
N/A· v4
N/A· v3
5.8 MEDIUM· v2
neon before 0.28.6, when OpenSSL or GnuTLS is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to...Show more
neon before 0.28.6, when OpenSSL or GnuTLS is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.Show less
1Juvare
1Webeoc
Apr 16, 2026
Jul 18, 2005
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
WebEOC before 6.0.2 uses a weak encryption scheme for passwords, which makes it easier for attackers to crack passwords.
1Gnupg
1Gnupg
Apr 16, 2026
May 2, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The integrity check feature in OpenPGP, when handling a message that was encrypted using cipher feedback (CFB) mode, allows remote attackers to recover part of the plaintext via a chosen-ciphertext attack when the first...Show more
The integrity check feature in OpenPGP, when handling a message that was encrypted using cipher feedback (CFB) mode, allows remote attackers to recover part of the plaintext via a chosen-ciphertext attack when the first 2 bytes of a message block are known, and an oracle or other mechanism is available to determine whether an integrity check failed.Show less
1Netsourcecommerce
1Productcart
Apr 16, 2026
Dec 31, 2004
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
EarlyImpact ProductCart uses a weak encryption scheme to encrypt passwords, which allows remote attackers to obtain the password via a chosen plaintext attack.
1Sharp
2Zaurus Sl 5000d Firmware
Zaurus Sl 5500 Firmware
Apr 16, 2026
Dec 31, 2002
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Sharp Zaurus PDA SL-5000D and SL-5500 uses a salt of "A0" to encrypt the screen-locking password as stored in the Security.conf file, which makes it easier for local users to guess the password via brute force methods.