← Back
CWE-327

685 CVEs • Abstraction: Class • Likelihood of Exploit: High

Use of a Broken or Risky Cryptographic Algorithm

The product uses a broken or risky cryptographic algorithm or protocol.

JSON object

Loading...

CVEs (685)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hcltech
1Bigfix Osd Bare Metal Server
Jun 17, 2026
Jun 22, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
The OSD Bare Metal Server uses a cryptographic algorithm that is no longer considered sufficiently secure.
1Google
1Android
Jun 17, 2026
Jun 15, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
In btm_sec_encrypt_change of btm_sec.cc, there is a possible way to downgrade the link key type due to improperly used crypto. This could lead to paired device escalation of privilege with no additional execution privile...Show more
In btm_sec_encrypt_change of btm_sec.cc, there is a possible way to downgrade the link key type due to improperly used crypto. This could lead to paired device escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12LAndroid ID: A-258834033Show less
1Fortinet
1Fortisiem
Jun 17, 2026
Jun 13, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
A use of a broken or risky cryptographic algorithm [CWE-327] in Fortinet FortiSIEM before 6.7.1 allows a remote unauthenticated attacker to perform brute force attacks on GUI endpoints via taking advantage of outdated h...Show more
A use of a broken or risky cryptographic algorithm [CWE-327] in Fortinet FortiSIEM before 6.7.1 allows a remote unauthenticated attacker to perform brute force attacks on GUI endpoints via taking advantage of outdated hashing methods.Show less
1Dell
1Secure Connect Gateway
Jun 17, 2026
Jun 1, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Dell SCG 5.14 contains an information disclosure vulnerability during the SRS to SCG upgrade path. A remote low privileged malicious user could potentially exploit this vulnerability to retrieve the plain text.
1Nfine Rapid Development Platform Project
1Nfine Rapid Development Platform
Jun 17, 2026
May 25, 2023
N/A· v4
7.5 HIGH· v3
2.6 LOW· v2
A vulnerability was found in NFine Rapid Development Platform 20230511. It has been classified as problematic. Affected is an unknown function of the file /Login/CheckLogin. The manipulation leads to use of weak hash. It...Show more
A vulnerability was found in NFine Rapid Development Platform 20230511. It has been classified as problematic. Affected is an unknown function of the file /Login/CheckLogin. The manipulation leads to use of weak hash. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. VDB-229974 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Dell
1Cloudlink
Jun 17, 2026
May 16, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
CloudLink 7.1.2 and all prior versions contain a broken or risky cryptographic algorithm vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability leading to some information disclos...Show more
CloudLink 7.1.2 and all prior versions contain a broken or risky cryptographic algorithm vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability leading to some information disclosure. Show less
1Facebook
1Hhvm
Jun 17, 2026
May 10, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
HHVM 4.172.0 and all prior versions use TLS 1.0 for secure connections when handling tls:// URLs in the stream extension. TLS1.0 has numerous published vulnerabilities and is deprecated. HHVM 4.153.4, 4.168.2, 4.169.2, 4...Show more
HHVM 4.172.0 and all prior versions use TLS 1.0 for secure connections when handling tls:// URLs in the stream extension. TLS1.0 has numerous published vulnerabilities and is deprecated. HHVM 4.153.4, 4.168.2, 4.169.2, 4.170.2, 4.171.1, 4.172.1, 4.173.0 replaces TLS1.0 with TLS1.3. Applications that call stream_socket_server or stream_socket_client functions with a URL starting with tls:// are affected.Show less
1Ibm
1Qradar Data Synchronization
Jun 17, 2026
May 6, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
IBM QRadar Data Synchronization App 1.0 through 3.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 217370.
1Fortinet
1Fortinac
Jun 17, 2026
May 3, 2023
N/A· v4
7.4 HIGH· v3
N/A· v2
A use of a weak cryptographic algorithm vulnerability [CWE-327] in FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.0 all versions, 8.8.0 all versions, 8.7.0 all versions may increase the chances of an attacker to have acc...Show more
A use of a weak cryptographic algorithm vulnerability [CWE-327] in FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.0 all versions, 8.8.0 all versions, 8.7.0 all versions may increase the chances of an attacker to have access to sensitive information or to perform man-in-the-middle attacks.Show less
1Ibm
4Infosphere Information Server
JavaWebsphere Application Server+1 more
Jun 17, 2026
Apr 29, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
IBM Runtime Environment, Java Technology Edition IBMJCEPlus and JSSE 8.0.7.0 through 8.0.7.11 components could expose sensitive information using a combination of flaws and configurations. IBM X-Force ID: 253188.
1Ibm
1Safer Payments
Jun 17, 2026
Apr 28, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
IBM Counter Fraud Management for Safer Payments 6.1.0.00 through 6.1.1.02, 6.2.0.00 through 6.2.2.02, 6.3.0.00 through 6.3.1.02, 6.4.0.00 through 6.4.2.01, and 6.5.0.00 uses weaker than expected cryptographic algorithms...Show more
IBM Counter Fraud Management for Safer Payments 6.1.0.00 through 6.1.1.02, 6.2.0.00 through 6.2.2.02, 6.3.0.00 through 6.3.1.02, 6.4.0.00 through 6.4.2.01, and 6.5.0.00 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 249192.Show less
1Pingidentity
3Pingfederate
Pingid Adapter For PingfederatePingid Integration Kit
Jun 17, 2026
Apr 25, 2023
N/A· v4
5.8 MEDIUM· v3
N/A· v2
A misconfiguration of RSA padding implemented in the PingID Adapter for PingFederate to support Offline MFA with PingID mobile authenticators is vulnerable to pre-computed dictionary attacks, leading to a bypass of offli...Show more
A misconfiguration of RSA padding implemented in the PingID Adapter for PingFederate to support Offline MFA with PingID mobile authenticators is vulnerable to pre-computed dictionary attacks, leading to a bypass of offline MFA.Show less
1Liveboxcloud
1Vdesk
Jun 17, 2026
Apr 14, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Cryptographic Issue can occur under the /api/v1/vencrypt/decrypt/file endpoint. A malicious user, logged into a victim's account, is able to decipher...Show more
An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Cryptographic Issue can occur under the /api/v1/vencrypt/decrypt/file endpoint. A malicious user, logged into a victim's account, is able to decipher a file without knowing the key set by the user.Show less
1Microsoft
5Windows Server 2008
Windows Server 2012Windows Server 2016+2 more
Jun 17, 2026
Apr 11, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
Windows Kerberos Elevation of Privilege Vulnerability
1Rocketsoftware
2Unidata
Universe
Jun 17, 2026
Mar 29, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 use weak encryption for packet-level security and passwords transferred on the wire.
1Westerndigital
1Sandisk Privateaccess
Jun 17, 2026
Mar 24, 2023
N/A· v4
7.4 HIGH· v3
N/A· v2
SanDisk PrivateAccess versions prior to 6.4.9 support insecure TLS 1.0 and TLS 1.1 protocols which are susceptible to man-in-the-middle attacks thereby compromising confidentiality and integrity of data.
1Tp Link
1Tl Wr940n Firmware
Jun 17, 2026
Feb 22, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
TP-Link router TL-WR940N V6 3.19.1 Build 180119 uses a deprecated MD5 algorithm to hash the admin password used for basic authentication.
1Dell
1Secure Connect Gateway
Jun 17, 2026
Feb 17, 2023
N/A· v4
5.9 MEDIUM· v3
N/A· v2
Dell Secure Connect Gateway (SCG) version 5.14.00.12 contains a broken cryptographic algorithm vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by performing MitM attacks and...Show more
Dell Secure Connect Gateway (SCG) version 5.14.00.12 contains a broken cryptographic algorithm vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by performing MitM attacks and let attackers obtain sensitive information. Show less
1Dell
3Emc Unity Operating Environment
Emc Unity Xt Operating EnvironmentEmc Unityvsa Operating Environment
Jun 17, 2026
Feb 14, 2023
N/A· v4
5.9 MEDIUM· v3
N/A· v2
Dell EMC Unity versions before 5.2.0.0.5.173 , use(es) broken cryptographic algorithm. A remote unauthenticated attacker could potentially exploit this vulnerability by performing MitM attacks and let attackers obtain se...Show more
Dell EMC Unity versions before 5.2.0.0.5.173 , use(es) broken cryptographic algorithm. A remote unauthenticated attacker could potentially exploit this vulnerability by performing MitM attacks and let attackers obtain sensitive information. Show less
1Dell
1Powerscale Onefs
Jun 17, 2026
Feb 11, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Dell PowerScale OneFS, versions 9.2.0.x through 9.4.0.x contain an information vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to cause data leak.