← Back
CWE-327

685 CVEs • Abstraction: Class • Likelihood of Exploit: High

Use of a Broken or Risky Cryptographic Algorithm

The product uses a broken or risky cryptographic algorithm or protocol.

JSON object

Loading...

CVEs (685)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dell
1Policy Manager For Secure Connect Gateway
Jun 17, 2026
Sep 21, 2023
N/A· v4
5.9 MEDIUM· v3
N/A· v2
Dell SCG Policy Manager 5.16.00.14 contains a broken cryptographic algorithm vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by performing MitM attacks and let attackers obta...Show more
Dell SCG Policy Manager 5.16.00.14 contains a broken cryptographic algorithm vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by performing MitM attacks and let attackers obtain sensitive information. Show less
1Linuxfoundation
1Edge Virtualization Engine
Jun 17, 2026
Sep 20, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Vault Key Sealed With SHA1 PCRs The measured boot solution implemented in EVE OS leans on a PCR locking mechanism. Different parts of the system update different PCR values in the TPM, resulting in a unique value...Show more
Vault Key Sealed With SHA1 PCRs The measured boot solution implemented in EVE OS leans on a PCR locking mechanism. Different parts of the system update different PCR values in the TPM, resulting in a unique value for each PCR entry. These PCRs are then used in order to seal/unseal a key from the TPM which is used to encrypt/decrypt the “vault” directory. This “vault” directory is the most sensitive point in the system and as such, its content should be protected. This mechanism is noted in Zededa’s documentation as the “measured boot” mechanism, designed to protect said “vault”. The code that’s responsible for generating and fetching the key from the TPM assumes that SHA256 PCRs are used in order to seal/unseal the key, and as such their presence is being checked. The issue here is that the key is not sealed using SHA256 PCRs, but using SHA1 PCRs. This leads to several issues: • Machines that have their SHA256 PCRs enabled but SHA1 PCRs disabled, as well as not sealing their keys at all, meaning the “vault” is not protected from an attacker. • SHA1 is considered insecure and reduces the complexity level required to unseal the key in machines which have their SHA1 PCRs enabled. An attacker can very easily retrieve the contents of the “vault”, which will effectively render the “measured boot” mechanism meaningless. Show less
1Vmware
1Aria Operations For Networks
Jun 17, 2026
Aug 29, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key generation. A malicious actor with network access to Aria Operations for Networks could bypass SSH au...Show more
Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key generation. A malicious actor with network access to Aria Operations for Networks could bypass SSH authentication to gain access to the Aria Operations for Networks CLI.Show less
1Bishopfox
1Sliver
Jun 17, 2026
Aug 28, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
Sliver from v1.5.x to v1.5.39 has an improper cryptographic implementation, which allows attackers to execute a man-in-the-middle attack via intercepted and crafted responses.
1Ibm
1Storage Copy Data Management
Jun 17, 2026
Aug 27, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
IBM Storage Copy Data Management 2.2.0.0 through 2.2.19.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 262268.
1Ibm
2Aix
Vios
Jun 17, 2026
Aug 24, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
IBM AIX 7.2, 7.3, VIOS 3.1's OpenSSH implementation could allow a non-privileged local user to access files outside of those allowed due to improper access controls. IBM X-Force ID: 263476.
1Broadcom
1Raid Controller Web Interface
Jun 17, 2026
Aug 15, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Broadcom RAID Controller web interface is vulnerable has an insecure default TLS configuration that support obsolete and vulnerable TLS protocols
1Broadcom
1Raid Controller Web Interface
Jun 17, 2026
Aug 15, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Broadcom RAID Controller web interface is vulnerable has an insecure default TLS configuration that supports obsolete SHA1-based ciphersuites
1Hcltech
1Dryice Iautomate
Jun 17, 2026
Aug 9, 2023
N/A· v4
7.1 HIGH· v3
N/A· v2
HCL DRYiCE iAutomate is affected by the use of a broken cryptographic algorithm. An attacker can potentially compromise the confidentiality and integrity of sensitive information.
1Hcltech
1Dryice Mycloud
Jun 17, 2026
Aug 9, 2023
N/A· v4
7.1 HIGH· v3
N/A· v2
HCL DRYiCE MyCloud is affected by the use of a broken cryptographic algorithm. An attacker can potentially compromise the confidentiality and integrity of sensitive information.
1Sap
1Powerdesigner
Jun 17, 2026
Aug 8, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
SAP PowerDesigner - version 16.7, queries all password hashes in the backend database and compares it with the user provided one during login attempt, which might allow an attacker to access password hashes from the clie...Show more
SAP PowerDesigner - version 16.7, queries all password hashes in the backend database and compares it with the user provided one during login attempt, which might allow an attacker to access password hashes from the client's memory.Show less
1Ibm
1Sterling Connect\
Jun 17, 2026
Jul 19, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
IBM Sterling Connect:Direct for UNIX 1.5 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 210574.
1Cisco
1Cjose
Jun 17, 2026
Jul 14, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). The AES GCM decryption routine incorrectly uses the Tag length from the actual Authentication Tag provided in the JWE. The sp...Show more
OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). The AES GCM decryption routine incorrectly uses the Tag length from the actual Authentication Tag provided in the JWE. The spec says that a fixed length of 16 octets must be applied. Therefore this bug allows an attacker to provide a truncated Authentication Tag and to modify the JWE accordingly. Users should upgrade to a version >= 0.6.2.2. Users unable to upgrade should avoid using AES GCM encryption and replace it with another encryption algorithm (e.g. AES CBC).Show less
1Sonicwall
2Analytics
Global Management System
Jun 17, 2026
Jul 13, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SonicWall GMS and Analytics use outdated Tiny Encryption Algorithm (TEA) with a hardcoded key to encrypt sensitive data. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions....Show more
SonicWall GMS and Analytics use outdated Tiny Encryption Algorithm (TEA) with a hardcoded key to encrypt sensitive data. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions. Show less
1Google
1Android
Jun 17, 2026
Jul 13, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
there is a possible way to bypass cryptographic assurances due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed...Show more
there is a possible way to bypass cryptographic assurances due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Show less
1Microsoft
12Windows 10 1507
Windows 10 1607Windows 10 1809+9 more
Jun 17, 2026
Jul 11, 2023
N/A· v4
6.8 MEDIUM· v3
N/A· v2
Windows Remote Desktop Security Feature Bypass Vulnerability
1Siemens
11Ruggedcom Rox Mx5000 Firmware
Ruggedcom Rox Mx5000re FirmwareRuggedcom Rox Rx1400 Firmware+8 more
Jun 17, 2026
Jul 11, 2023
N/A· v4
7.4 HIGH· v3
N/A· v2
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V...Show more
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V2.16.0), RUGGEDCOM ROX RX1501 (All versions < V2.16.0), RUGGEDCOM ROX RX1510 (All versions < V2.16.0), RUGGEDCOM ROX RX1511 (All versions < V2.16.0), RUGGEDCOM ROX RX1512 (All versions < V2.16.0), RUGGEDCOM ROX RX1524 (All versions < V2.16.0), RUGGEDCOM ROX RX1536 (All versions < V2.16.0), RUGGEDCOM ROX RX5000 (All versions < V2.16.0). The webserver of the affected devices support insecure TLS 1.0 protocol. An attacker could achieve a man-in-the-middle attack and compromise confidentiality and integrity of data.Show less
1Ibm
1Websphere Application Server
Jun 17, 2026
Jul 7, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security, caused by the improper encoding in a local configuration file. IBM X-Force ID: 258637.
1Ovarro
5Tbox Lt2 Firmware
Tbox Ms Cpu32 S2 FirmwareTbox Ms Cpu32 Firmware+2 more
Jun 17, 2026
Jul 3, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The affected TBox RTUs store hashed passwords using MD5 encryption, which is an insecure encryption algorithm.
1Ibm
1Qradar Security Information And Event Manager
Jun 17, 2026
Jun 27, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
IBM QRadar SIEM 7.5.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 248147.