← Back
CWE-327

685 CVEs • Abstraction: Class • Likelihood of Exploit: High

Use of a Broken or Risky Cryptographic Algorithm

The product uses a broken or risky cryptographic algorithm or protocol.

JSON object

Loading...

CVEs (685)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Debian
Postgresql
2Debian Linux
Postgresql
Jun 17, 2026
Nov 16, 2020
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. If a client application that creates additional database connections only reuses the basic co...Show more
A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. If a client application that creates additional database connections only reuses the basic connection parameters while dropping security-relevant parameters, an opportunity for a man-in-the-middle attack, or the ability to observe clear-text transmissions, could exist. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.Show less
3Fedoraproject
Python Rsa ProjectRedhat
3Fedora
Openstack PlatformPython Rsa
Jun 17, 2026
Nov 12, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
It was found that python-rsa is vulnerable to Bleichenbacher timing attacks. An attacker can use this flaw via the RSA decryption API to decrypt parts of the cipher text encrypted with RSA.
1F5
14Big Ip Access Policy Manager
Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+11 more
Jun 17, 2026
Nov 5, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In versions 14.1.0-14.1.0.1 and 14.1.2.5-14.1.2.7, when a BIG-IP object is created or listed through the REST interface, the protected fields are obfuscated in the REST response, not protected via a SecureVault cryptogra...Show more
In versions 14.1.0-14.1.0.1 and 14.1.2.5-14.1.2.7, when a BIG-IP object is created or listed through the REST interface, the protected fields are obfuscated in the REST response, not protected via a SecureVault cryptogram as TMSH does. One example of protected fields is the GTM monitor password.Show less
1Synology
2Diskstation Manager
Router Manager
Jun 17, 2026
Oct 29, 2020
N/A· v4
8.3 HIGH· v3
5.1 MEDIUM· v2
Algorithm downgrade vulnerability in QuickConnect in Synology Router Manager (SRM) before 1.2.4-8081 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via unspecified vectors.
1Synology
2Diskstation Manager
Skynas Firmware
Jun 17, 2026
Oct 29, 2020
N/A· v4
8.3 HIGH· v3
5.1 MEDIUM· v2
Algorithm downgrade vulnerability in QuickConnect in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via unspecified vectors.
1Bigbluebutton
1Bigbluebutton
Jun 17, 2026
Oct 21, 2020
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
BigBlueButton through 2.2.28 uses STUN/TURN resources from a third party, which may represent an unintended endpoint.
1Ibm
1Security Guardium Big Data Intelligence
Jun 17, 2026
Oct 16, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM Security Guardium Big Data Intelligence 1.0 (SonarG) uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 175560.
1Ibm
1Curam Social Program Management
Jun 17, 2026
Oct 12, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM Curam Social Program Management 7.0.9 and 7.0.10 uses MD5 algorithm for hashing token in a single instance which less safe than default SHA-256 cryptographic algorithm used throughout the Cúram application. IBM X-Fo...Show more
IBM Curam Social Program Management 7.0.9 and 7.0.10 uses MD5 algorithm for hashing token in a single instance which less safe than default SHA-256 cryptographic algorithm used throughout the Cúram application. IBM X-Force ID: 189156.Show less
1Hcltech
1Appscan
Jun 17, 2026
Oct 6, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
"HCL AppScan Enterprise makes use of broken or risky cryptographic algorithm to store REST API user details."
1Apache
1Nifi
Jun 17, 2026
Oct 1, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Apache NiFi 1.2.0 to 1.11.4, the NiFi UI and API were protected by mandating TLS v1.2, as well as listening connections established by processors like ListenHTTP, HandleHttpRequest, etc. However intracluster communica...Show more
In Apache NiFi 1.2.0 to 1.11.4, the NiFi UI and API were protected by mandating TLS v1.2, as well as listening connections established by processors like ListenHTTP, HandleHttpRequest, etc. However intracluster communication such as cluster request replication, Site-to-Site, and load balanced queues continued to support TLS v1.0 or v1.1.Show less
1Glpi Project
1Glpi
Jun 17, 2026
Sep 23, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In GLPI before version 9.5.0, the encryption algorithm used is insecure. The security of the data encrypted relies on the password used, if a user sets a weak/predictable password, an attacker could decrypt data. This is...Show more
In GLPI before version 9.5.0, the encryption algorithm used is insecure. The security of the data encrypted relies on the password used, if a user sets a weak/predictable password, an attacker could decrypt data. This is fixed in version 9.5.0 by using a more secure encryption library. The library chosen is sodium.Show less
1Ibm
1Data Risk Manager
Jun 17, 2026
Sep 22, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM Data Risk Manager (iDNA) 2.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt sensitive information. IBM X-Force ID: 184927.
1Ibm
1Data Risk Manager
Jun 17, 2026
Sep 22, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM Data Risk Manager (iDNA) 2.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 184925.
1Wibu
1Codemeter
Jun 17, 2026
Sep 16, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Protocol encryption can be easily broken for CodeMeter (All versions prior to 6.90 are affected, including Version 6.90 or newer only if CodeMeter Runtime is running as server) and the server accepts external connections...Show more
Protocol encryption can be easily broken for CodeMeter (All versions prior to 6.90 are affected, including Version 6.90 or newer only if CodeMeter Runtime is running as server) and the server accepts external connections, which may allow an attacker to remotely communicate with the CodeMeter API.Show less
1Microsoft
8Windows 10
Windows 7Windows 8.1+5 more
Jun 17, 2026
Sep 11, 2020
N/A· v4
5.3 MEDIUM· v3
2.9 LOW· v2
<p>A information disclosure vulnerability exists when TLS components use weak hash algorithms. An attacker who successfully exploited this vulnerability could obtain information to further compromise a users's encrypted...Show more
<p>A information disclosure vulnerability exists when TLS components use weak hash algorithms. An attacker who successfully exploited this vulnerability could obtain information to further compromise a users's encrypted transmission channel.</p> <p>To exploit the vulnerability, an attacker would have to conduct a man-in-the-middle attack.</p> <p>The update addresses the vulnerability by correcting how TLS components use hash algorithms.</p>Show less
1Qualcomm
15Kamorta Firmware
Nicobar FirmwareQcs404 Firmware+12 more
Jun 17, 2026
Sep 8, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
u'Keymaster attestation key and device IDs provisioning which is a one time process is incorrectly allowed to be re-provisioned after a user data erase or a factory reset' in Snapdragon Auto, Snapdragon Compute, Snapdrag...Show more
u'Keymaster attestation key and device IDs provisioning which is a one time process is incorrectly allowed to be re-provisioned after a user data erase or a factory reset' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in Kamorta, Nicobar, QCS404, QCS610, Rennell, SA515M, SA6155P, SC7180, SC8180X, SDX55, SM6150, SM7150, SM8150, SM8250, SXR2130Show less
1Zte
1Zxiptv Firmware
Jun 17, 2026
Sep 1, 2020
N/A· v4
9.1 CRITICAL· v3
5.5 MEDIUM· v2
A ZTE product is impacted by the cryptographic issues vulnerability. The encryption algorithm is not properly used, so remote attackers could use this vulnerability for account credential enumeration attack or brute-forc...Show more
A ZTE product is impacted by the cryptographic issues vulnerability. The encryption algorithm is not properly used, so remote attackers could use this vulnerability for account credential enumeration attack or brute-force attack for password guessing. This affects: ZXIPTV, ZXIPTV-WEB-PV5.09.08.04.Show less
1Ibm
1Security Guardium Insights
Jun 17, 2026
Aug 27, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM Security Guardium Insights 2.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 174683.
1Ibm
1Security Guardium Insights
Jun 17, 2026
Aug 27, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM Security Guardium Insights 2.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 174405.
1Amazon
1Aws S3 Crypto Sdk
Jun 17, 2026
Aug 11, 2020
N/A· v4
2.5 LOW· v3
2.1 LOW· v2
A vulnerability in the in-band key negotiation exists in the AWS S3 Crypto SDK for GoLang versions prior to V2. An attacker with write access to the targeted bucket can change the encryption algorithm of an object in the...Show more
A vulnerability in the in-band key negotiation exists in the AWS S3 Crypto SDK for GoLang versions prior to V2. An attacker with write access to the targeted bucket can change the encryption algorithm of an object in the bucket, which can then allow them to change AES-GCM to AES-CTR. Using this in combination with a decryption oracle can reveal the authentication key used by AES-GCM as decrypting the GMAC tag leaves the authentication key recoverable as an algebraic equation. It is recommended to update your SDK to V2 or later, and re-encrypt your files.Show less