← Back
CWE-326

455 CVEs • Abstraction: Class

Inadequate Encryption Strength

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

JSON object

Loading...

CVEs (455)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Jun 17, 2026
Jan 17, 2025
6.1 MEDIUM· v4
N/A· v3
N/A· v2
A vulnerability exists in Algo Edge up to 2.1.1 - a previously used (legacy) component of navify® Algorithm Suite. The vulnerability impacts the authentication mechanism of this component and could allow an attacker wit...Show more
A vulnerability exists in Algo Edge up to 2.1.1 - a previously used (legacy) component of navify® Algorithm Suite. The vulnerability impacts the authentication mechanism of this component and could allow an attacker with adjacent access to the laboratory network and the Algo Edge system to craft valid authentication tokens and access the component. Other components of navify® Algorithm Suite are not affected.Show less
1Apache
1Answer
Jun 17, 2026
Nov 22, 2024
N/A· v4
2.6 LOW· v3
N/A· v2
Inadequate Encryption Strength vulnerability in Apache Answer. This issue affects Apache Answer: through 1.4.0. The ids generated using the UUID v1 version are to some extent not secure enough. It can cause the generat...Show more
Inadequate Encryption Strength vulnerability in Apache Answer. This issue affects Apache Answer: through 1.4.0. The ids generated using the UUID v1 version are to some extent not secure enough. It can cause the generated token to be predictable. Users are recommended to upgrade to version 1.4.1, which fixes the issue.Show less
1Apache
1Tomcat
Jun 17, 2026
Nov 18, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Incorrect object recycling and reuse vulnerability in Apache Tomcat. This issue affects Apache Tomcat: 11.0.0, 10.1.31, 9.0.96. Users are recommended to upgrade to version 11.0.1, 10.1.32 or 9.0.97, which fixes the iss...Show more
Incorrect object recycling and reuse vulnerability in Apache Tomcat. This issue affects Apache Tomcat: 11.0.0, 10.1.31, 9.0.96. Users are recommended to upgrade to version 11.0.1, 10.1.32 or 9.0.97, which fixes the issue.Show less
1Apache
1Tomcat
Jun 17, 2026
Nov 18, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the request and response used by HTTP/2 requests could lead to request and/or response mix-up between users. This issue affe...Show more
Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the request and response used by HTTP/2 requests could lead to request and/or response mix-up between users. This issue affects Apache Tomcat: from 11.0.0-M23 through 11.0.0-M26, from 10.1.27 through 10.1.30, from 9.0.92 through 9.0.95. Users are recommended to upgrade to version 11.0.0, 10.1.31 or 9.0.96, which fixes the issue.Show less
1Snowflake
1Snowflake Jdbc
Jun 17, 2026
Oct 30, 2024
N/A· v4
5.9 MEDIUM· v3
N/A· v2
Snowflake JDBC driver versions >= 3.2.6 and <= 3.19.1 have an Incorrect Security Setting that can result in data being uploaded to an encrypted stage without the additional layer of protection provided by client side enc...Show more
Snowflake JDBC driver versions >= 3.2.6 and <= 3.19.1 have an Incorrect Security Setting that can result in data being uploaded to an encrypted stage without the additional layer of protection provided by client side encryption.Show less
1Litespeedtech
1Litespeed Cache
Jun 17, 2026
Oct 29, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Privilege Escalation.This issue affects LiteSpeed Cache: from n/a through <= 6.5.1.
1Gl Inet
21A1300 Firmware
Ar300m16 FirmwareAr300m Firmware+18 more
Jun 17, 2026
Oct 24, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. By intercepting an HTTP request and changing the filename property in the download interface, any file on t...Show more
An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. By intercepting an HTTP request and changing the filename property in the download interface, any file on the device can be deleted.Show less
-
-
Jun 17, 2026
Oct 17, 2024
N/A· v4
3.3 LOW· v3
N/A· v2
Nokia SR OS bof.cfg file encryption is vulnerable to a brute force attack. This weakness allows an attacker in possession of the encrypted file to decrypt the bof.cfg file and obtain the BOF configuration content.
2Helmholz
Mbconnectline
15Mbconnect24
Mbnet.mini FirmwareMbnet.rokey Firmware+12 more
Jun 17, 2026
Oct 15, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used.
1Draytek
24Vigor1000b Firmware
Vigor165 FirmwareVigor166 Firmware+21 more
Jun 17, 2026
Oct 3, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue in DrayTek Vigor310 devices through 4.3.2.6 allows an attacker to obtain sensitive information because the httpd server of the Vigor management UI uses a static string for seeding the PRNG of OpenSSL.
1Portainer
1Portainer
Jun 17, 2026
Oct 2, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Portainer before 2.20.2 improperly uses an encryption algorithm in the AesEncrypt function.
1Planet
3Gs 4210 24p2s Firmware
Gs 4210 24pl4c FirmwareIgs 5225 4up1t2s Firmware
Jun 17, 2026
Sep 30, 2024
N/A· v4
5.9 MEDIUM· v3
N/A· v2
The swctrl service is used to detect and remotely manage PLANET Technology devices. For certain switch models, the authentication tokens used during communication with this service are encoded user passwords. Due to insu...Show more
The swctrl service is used to detect and remotely manage PLANET Technology devices. For certain switch models, the authentication tokens used during communication with this service are encoded user passwords. Due to insufficient strength, unauthorized remote attackers who intercept the packets can directly crack them to obtain plaintext passwords.Show less
1Amirraminfar
1Dozzle
Jun 17, 2026
Sep 27, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Dozzle is a realtime log viewer for docker containers. Before version 8.5.3, the app uses sha-256 as the hash for passwords, which leaves users susceptible to rainbow table attacks. The app switches to bcrypt, a more app...Show more
Dozzle is a realtime log viewer for docker containers. Before version 8.5.3, the app uses sha-256 as the hash for passwords, which leaves users susceptible to rainbow table attacks. The app switches to bcrypt, a more appropriate hash for passwords, in version 8.5.3.Show less
1Openslides
1Openslides
Jun 17, 2026
Sep 25, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
OpenSlides 4.0.15 was discovered to be using a weak hashing algorithm to store passwords.
1Apache
1Answer
Jun 17, 2026
Sep 25, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Inadequate Encryption Strength vulnerability in Apache Answer. This issue affects Apache Answer: through 1.3.5. Using the MD5 value of a user's email to access Gravatar is insecure and can lead to the leakage of user e...Show more
Inadequate Encryption Strength vulnerability in Apache Answer. This issue affects Apache Answer: through 1.3.5. Using the MD5 value of a user's email to access Gravatar is insecure and can lead to the leakage of user email. The official recommendation is to use SHA256 instead. Users are recommended to upgrade to version 1.4.0, which fixes the issue.Show less
1Apache
1Linkis
Jun 17, 2026
Sep 25, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
In Apache Linkis <= 1.5.0, a Random string security vulnerability in Spark EngineConn, random string generated by the Token when starting Py4j uses the Commons Lang's RandomStringUtils. Users are recommended to upgrade t...Show more
In Apache Linkis <= 1.5.0, a Random string security vulnerability in Spark EngineConn, random string generated by the Token when starting Py4j uses the Commons Lang's RandomStringUtils. Users are recommended to upgrade to version 1.6.0, which fixes this issue.Show less
1Authenticator
1Authenticator
Jun 17, 2026
Sep 3, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Authenticator is a browser extension that generates two-step verification codes. In versions 7.0.0 and below, encryption keys for user data were stored encrypted at-rest using only AES-256 and the EVP_BytesToKey KDF. The...Show more
Authenticator is a browser extension that generates two-step verification codes. In versions 7.0.0 and below, encryption keys for user data were stored encrypted at-rest using only AES-256 and the EVP_BytesToKey KDF. Therefore, attackers with a copy of a user's data are able to brute-force the user's encryption key. Users on version 8.0.0 and above are automatically migrated away from the weak encoding on first login. Users should destroy encrypted backups made with versions prior to 8.0.0.Show less
1Microfocus
1Netiq Advanced Authentication
Jun 17, 2026
Aug 28, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Insufficient or weak TLS protocol version identified in Advance authentication client server communication when specific service is accessed between devices.  This issue affects NetIQ Advance Authentication versions befo...Show more
Insufficient or weak TLS protocol version identified in Advance authentication client server communication when specific service is accessed between devices.  This issue affects NetIQ Advance Authentication versions before 6.3.5.1Show less
-
-
Jun 17, 2026
Aug 14, 2024
7.1 HIGH· v4
6.4 MEDIUM· v3
N/A· v2
Inadequate encryption strength for some BMRA software before version 22.08 may allow an authenticated user to potentially enable escalation of privilege via local access.
1Siemens
1Location Intelligence
Jun 17, 2026
Aug 13, 2024
6.0 MEDIUM· v4
7.5 HIGH· v3
N/A· v2
A vulnerability has been identified in Location Intelligence family (All versions < V4.4). The web server of affected products is configured to support weak ciphers by default. This could allow an unauthenticated attack...Show more
A vulnerability has been identified in Location Intelligence family (All versions < V4.4). The web server of affected products is configured to support weak ciphers by default. This could allow an unauthenticated attacker in an on-path position to to read and modify any data passed over the connection between legitimate clients and the affected device.Show less