CWE-326
455 CVEs • Abstraction: Class
Inadequate Encryption Strength
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
CVEs (455)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A vulnerability exists in Algo Edge up to 2.1.1 - a previously used (legacy) component of navify® Algorithm Suite. The vulnerability impacts the authentication mechanism of this component and could allow an attacker wit...Show more |
Inadequate Encryption Strength vulnerability in Apache Answer. This issue affects Apache Answer: through 1.4.0. The ids generated using the UUID v1 version are to some extent not secure enough. It can cause the generat...Show more |
Incorrect object recycling and reuse vulnerability in Apache Tomcat. This issue affects Apache Tomcat: 11.0.0, 10.1.31, 9.0.96. Users are recommended to upgrade to version 11.0.1, 10.1.32 or 9.0.97, which fixes the iss...Show more |
Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the request and response used by HTTP/2 requests could lead to request and/or response mix-up between users. This issue affe...Show more |
Snowflake JDBC driver versions >= 3.2.6 and <= 3.19.1 have an Incorrect Security Setting that can result in data being uploaded to an encrypted stage without the additional layer of protection provided by client side enc...Show more |
Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Privilege Escalation.This issue affects LiteSpeed Cache: from n/a through <= 6.5.1. |
1Gl Inet 21A1300 Firmware Ar300m16 FirmwareAr300m Firmware+18 moreJun 17, 2026 Oct 24, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. By intercepting an HTTP request and changing the filename property in the download interface, any file on t...Show more |
Nokia SR OS bof.cfg file encryption is vulnerable to a brute force attack. This weakness allows an attacker in possession of the encrypted file to decrypt the bof.cfg file and obtain the BOF configuration content. |
2Helmholz Mbconnectline15Mbconnect24 Mbnet.mini FirmwareMbnet.rokey Firmware+12 moreJun 17, 2026 Oct 15, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used. |
1Draytek 24Vigor1000b Firmware Vigor165 FirmwareVigor166 Firmware+21 moreJun 17, 2026 Oct 3, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 An issue in DrayTek Vigor310 devices through 4.3.2.6 allows an attacker to obtain sensitive information because the httpd server of the Vigor management UI uses a static string for seeding the PRNG of OpenSSL. |
Portainer before 2.20.2 improperly uses an encryption algorithm in the AesEncrypt function. |
1Planet 3Gs 4210 24p2s Firmware Gs 4210 24pl4c FirmwareIgs 5225 4up1t2s FirmwareJun 17, 2026 Sep 30, 2024 N/A· v4 5.9 MEDIUM· v3 N/A· v2 The swctrl service is used to detect and remotely manage PLANET Technology devices. For certain switch models, the authentication tokens used during communication with this service are encoded user passwords. Due to insu...Show more |
Dozzle is a realtime log viewer for docker containers. Before version 8.5.3, the app uses sha-256 as the hash for passwords, which leaves users susceptible to rainbow table attacks. The app switches to bcrypt, a more app...Show more |
OpenSlides 4.0.15 was discovered to be using a weak hashing algorithm to store passwords. |
Inadequate Encryption Strength vulnerability in Apache Answer. This issue affects Apache Answer: through 1.3.5. Using the MD5 value of a user's email to access Gravatar is insecure and can lead to the leakage of user e...Show more |
In Apache Linkis <= 1.5.0, a Random string security vulnerability in Spark EngineConn, random string generated by the Token when starting Py4j uses the Commons Lang's RandomStringUtils. Users are recommended to upgrade t...Show more |
Authenticator is a browser extension that generates two-step verification codes. In versions 7.0.0 and below, encryption keys for user data were stored encrypted at-rest using only AES-256 and the EVP_BytesToKey KDF. The...Show more |
1Microfocus 1Netiq Advanced Authentication Jun 17, 2026 Aug 28, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 Insufficient or weak TLS protocol version identified in Advance authentication client server communication when specific service is accessed between devices. This issue affects NetIQ Advance Authentication versions befo...Show more |
Inadequate encryption strength for some BMRA software before version 22.08 may allow an authenticated user to potentially enable escalation of privilege via local access. |
1Siemens 1Location Intelligence Jun 17, 2026 Aug 13, 2024 6.0 MEDIUM· v4 7.5 HIGH· v3 N/A· v2 A vulnerability has been identified in Location Intelligence family (All versions < V4.4). The web server of affected products is configured to support weak ciphers by default. This could allow an unauthenticated attack...Show more |