CWE-327
685 CVEs • Abstraction: Class • Likelihood of Exploit: High
Use of a Broken or Risky Cryptographic Algorithm
The product uses a broken or risky cryptographic algorithm or protocol.
CVEs (685)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ibm 2Sterling External Authentication Server Sterling Secure ProxyJun 17, 2026 Feb 8, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 IBM Sterling External Authentication Server 6.1.0 and IBM Sterling Secure Proxy 6.0.3 uses weaker than expected cryptographic algorithms during installation that could allow a local attacker to decrypt sensitive informat...Show more |
Econolite EOS versions prior to 3.2.23 use a weak hash algorithm for encrypting privileged user credentials. A configuration file that is accessible without authentication uses MD5 hashes for encrypting credentials, incl...Show more |
IBM WebSphere Application Server 8.5 and 9.0 traditional container uses weaker than expected cryptographic keys that could allow an attacker to decrypt sensitive information. This affects only the containerized version...Show more |
IBM Security Verify Governance, Identity Manager virtual appliance component 10.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID...Show more |
The Birthday attack against 64-bit block ciphers flaw (CVE-2016-2183) was reported for the health checks port (9979) on etcd grpc-proxy component. Even though the CVE-2016-2183 has been fixed in the etcd components, to e...Show more |
2Arm Trustedfirmware2Mbed Tls Mbed TlsJun 17, 2026 Jan 17, 2023 N/A· v4 4.7 MEDIUM· v3 N/A· v2 Use of a Broken or Risky Cryptographic Algorithm in the function mbedtls_mpi_exp_mod() in lignum.c in Mbed TLS Mbed TLS all versions before 3.0.0, 2.27.0 or 2.16.11 allows attackers with access to precise enough timing a...Show more |
Versions `<=8.5.1` of `jsonwebtoken` library could be misconfigured so that legacy, insecure key types are used for signature verification. For example, DSA keys could be used with the RS256 algorithm. You are affected i...Show more |
IBM Security Verify Governance, Identity Manager 10.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 225007.
|
IBM Spectrum Control 5.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 233982.
|
A vulnerability, which was classified as problematic, has been found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome. Affected by this issue is some unknown functionality. The manipulation leads...Show more |
1Sick 7Rfu650 10100 Firmware Rfu650 10101 FirmwareRfu650 10102 Firmware+4 moreJun 17, 2026 Dec 13, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Use of a Broken or Risky Cryptographic Algorithm in SICK RFU65x firmware version < v2.21 allows a low-privileged remote attacker to decrypt the encrypted data if the user requested weak cipher suites to be used for encry...Show more |
1Sick 24Rfu630 04100 Firmware Rfu630 04100s01 FirmwareRfu630 04101 Firmware+21 moreJun 17, 2026 Dec 13, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Use of a Broken or Risky Cryptographic Algorithm in SICK RFU63x firmware version < v2.21 allows a low-privileged remote attacker to decrypt the encrypted data if the user requested weak cipher suites to be used for encry...Show more |
1Sick 21Rfu620 10100 Firmware Rfu620 10101 FirmwareRfu620 10102 Firmware+18 moreJun 17, 2026 Dec 13, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Use of a Broken or Risky Cryptographic Algorithm in SICK RFU62x firmware version < 2.21 allows a low-privileged remote attacker to decrypt the encrypted data if the user requested weak cipher suites to be used for encryp...Show more |
1Siemens 101Ruggedcom Rm1224 Lte(4g) Eu Firmware Ruggedcom Rm1224 Lte(4g) Nam FirmwareScalance M804pb Firmware+98 moreJun 17, 2026 Dec 13, 2022 7.1 HIGH· v4 6.5 MEDIUM· v3 N/A· v2 Affected devices use a weak encryption scheme to encrypt the debug zip file. This could allow an authenticated attacker to decrypt the contents of the file and retrieve debug information about the system. |
1Sick 12Rfu610 10600 Firmware Rfu610 10601 FirmwareRfu610 10603 Firmware+9 moreJun 17, 2026 Dec 13, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Use of a Broken or Risky Cryptographic Algorithm in SICK RFU61x firmware version <v2.25 allows a low-privileged remote attacker to decrypt the encrypted data if the user requested weak cipher suites to be used for encryp...Show more |
IBM Sterling Secure Proxy 6.0.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 230522.
|
IBM CICS TX 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 229464.
|
IBM CICS TX 11.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 229463. |
SimpleXMQ before 3.4.0, as used in SimpleX Chat before 4.2, does not apply a key derivation function to intended data, which can interfere with forward secrecy and can have other impacts if there is a compromise of a sin...Show more |
The provided HCL Launch Container images contain non-unique HTTPS certificates and a database encryption key. The fix provides directions and tools to replace the non-unique keys and certificates. This does not affect th...Show more |