CWE-327
685 CVEs • Abstraction: Class • Likelihood of Exploit: High
Use of a Broken or Risky Cryptographic Algorithm
The product uses a broken or risky cryptographic algorithm or protocol.
CVEs (685)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Sensitive information disclosure and weak encryption in Pyrescom Termod4 time management devices before 10.04k allows remote attackers to read a session-file and obtain plain-text user credentials. |
1Ibm 1Security Identity Governance And Intelligence Jun 17, 2026 Jan 21, 2021 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 IBM Security Identity Governance and Intelligence 5.2.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 192427. |
2Ietf St21Public Key Cryptography Standards #1 Stm32cubef0Stm32cubef1+18 moreJul 9, 2026 Jan 20, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in STM32 cryptographic firmware library software expansion for STM32Cube (UM1924). The vulnerability can allow one to use Bleichenbacher's oracle attack to decrypt...Show more |
2Ietf Microchip2Microchip Libraries For Applications Public Key Cryptography Standards #1Jul 9, 2026 Jan 19, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in Microchip Libraries for Applications 2018-11-26 All up to 2018-11-26. The vulnerability can allow one to use Bleichenbacher's oracle attack to decrypt an encrypt...Show more |
1Canonical 1Remote Login Service Nov 21, 2024 Jan 13, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 In crypt.c of remote-login-service, the cryptographic algorithm used to cache usernames and passwords is insecure. An attacker could use this vulnerability to recover usernames and passwords from the file. This issue aff...Show more |
1Ibm 1Security Guardium Insights Jun 17, 2026 Jan 13, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IBM Security Guardium Insights 2.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 184812. |
1Ibm 1Security Guardium Insights Jun 17, 2026 Jan 13, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IBM Security Guardium Insights 2.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 184819. |
1Ibm 1Security Guardium Insights Jun 17, 2026 Jan 13, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IBM Security Guardium Insights 2.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 184800. |
1Ibm 1Emptoris Strategic Supply Management Jun 17, 2026 Jan 7, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IBM Emptoris Strategic Supply Management 10.1.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 190989. |
GigaVUE-OS (GVOS) 5.4 - 5.9 uses a weak algorithm for a hash stored in internal database. |
An issue was discovered in the streebog crate before 0.8.0 for Rust. The Streebog hash function can produce the wrong answer. |
TLS-RSA cipher suites are not disabled in HCL BigFix Inventory up to v10.0.2. If TLS 2.0 and secure ciphers are not enabled then an attacker can passively record traffic and later decrypt it. |
1Siemens 3Sicam A8000 Cp 8000 Firmware Sicam A8000 Cp 8021 FirmwareSicam A8000 Cp 8022 FirmwareJun 17, 2026 Dec 14, 2020 N/A· v4 7.3 HIGH· v3 4.9 MEDIUM· v2 A vulnerability has been identified in SICAM A8000 CP-8000 (All versions < V16), SICAM A8000 CP-8021 (All versions < V16), SICAM A8000 CP-8022 (All versions < V16). A web server misconfiguration of the affected device ca...Show more |
A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). Due to the usage of an insecure random number generation function and a deprecated cryptographic function, an attacker coul...Show more |
A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). Due to the usage of an outdated cipher mode on port 10005/tcp, an attacker could extract the encryption key from a captured...Show more |
Use of a Broken or Risky Cryptographic Algorithm vulnerability in McAfee Database Security Server and Sensor prior to 4.8.0 in the form of a SHA1 signed certificate that would allow an attacker on the same local network...Show more |
IBM Cloud Pak for Security 1.3.0.1 (CP4S) uses weaker than expected cryptographic algorithms during negotiation could allow an attacker to decrypt sensitive information. |
1Cdatatec 2872408a Firmware 9008a Firmware9016a Firmware+25 moreJun 17, 2026 Nov 24, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B, FD1104S, FD1104SN, FD1108S, FD1204S-R2, FD1204SN, FD1204SN-R2, FD1208S...Show more |
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 191814. |
A weak robustness vulnerability exists in the AWS Encryption SDKs for Java, Python, C and Javalcript prior to versions 2.0.0. Due to the non-committing property of AES-GCM (and other AEAD ciphers such as AES-GCM-SIV or (...Show more |