CWE-327
685 CVEs • Abstraction: Class • Likelihood of Exploit: High
Use of a Broken or Risky Cryptographic Algorithm
The product uses a broken or risky cryptographic algorithm or protocol.
CVEs (685)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Postgresql2Debian Linux PostgresqlJun 17, 2026 Nov 16, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. If a client application that creates additional database connections only reuses the basic co...Show more |
3Fedoraproject Python Rsa ProjectRedhat3Fedora Openstack PlatformPython RsaJun 17, 2026 Nov 12, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 It was found that python-rsa is vulnerable to Bleichenbacher timing attacks. An attacker can use this flaw via the RSA decryption API to decrypt parts of the cipher text encrypted with RSA. |
1F5 14Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+11 moreJun 17, 2026 Nov 5, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 In versions 14.1.0-14.1.0.1 and 14.1.2.5-14.1.2.7, when a BIG-IP object is created or listed through the REST interface, the protected fields are obfuscated in the REST response, not protected via a SecureVault cryptogra...Show more |
1Synology 2Diskstation Manager Router ManagerJun 17, 2026 Oct 29, 2020 N/A· v4 8.3 HIGH· v3 5.1 MEDIUM· v2 Algorithm downgrade vulnerability in QuickConnect in Synology Router Manager (SRM) before 1.2.4-8081 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via unspecified vectors. |
1Synology 2Diskstation Manager Skynas FirmwareJun 17, 2026 Oct 29, 2020 N/A· v4 8.3 HIGH· v3 5.1 MEDIUM· v2 Algorithm downgrade vulnerability in QuickConnect in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via unspecified vectors. |
BigBlueButton through 2.2.28 uses STUN/TURN resources from a third party, which may represent an unintended endpoint. |
1Ibm 1Security Guardium Big Data Intelligence Jun 17, 2026 Oct 16, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IBM Security Guardium Big Data Intelligence 1.0 (SonarG) uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 175560. |
1Ibm 1Curam Social Program Management Jun 17, 2026 Oct 12, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IBM Curam Social Program Management 7.0.9 and 7.0.10 uses MD5 algorithm for hashing token in a single instance which less safe than default SHA-256 cryptographic algorithm used throughout the Cúram application. IBM X-Fo...Show more |
"HCL AppScan Enterprise makes use of broken or risky cryptographic algorithm to store REST API user details." |
In Apache NiFi 1.2.0 to 1.11.4, the NiFi UI and API were protected by mandating TLS v1.2, as well as listening connections established by processors like ListenHTTP, HandleHttpRequest, etc. However intracluster communica...Show more |
In GLPI before version 9.5.0, the encryption algorithm used is insecure. The security of the data encrypted relies on the password used, if a user sets a weak/predictable password, an attacker could decrypt data. This is...Show more |
IBM Data Risk Manager (iDNA) 2.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt sensitive information. IBM X-Force ID: 184927. |
IBM Data Risk Manager (iDNA) 2.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 184925. |
Protocol encryption can be easily broken for CodeMeter (All versions prior to 6.90 are affected, including Version 6.90 or newer only if CodeMeter Runtime is running as server) and the server accepts external connections...Show more |
1Microsoft 8Windows 10 Windows 7Windows 8.1+5 moreJun 17, 2026 Sep 11, 2020 N/A· v4 5.3 MEDIUM· v3 2.9 LOW· v2 <p>A information disclosure vulnerability exists when TLS components use weak hash algorithms. An attacker who successfully exploited this vulnerability could obtain information to further compromise a users's encrypted...Show more |
1Qualcomm 15Kamorta Firmware Nicobar FirmwareQcs404 Firmware+12 moreJun 17, 2026 Sep 8, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 u'Keymaster attestation key and device IDs provisioning which is a one time process is incorrectly allowed to be re-provisioned after a user data erase or a factory reset' in Snapdragon Auto, Snapdragon Compute, Snapdrag...Show more |
A ZTE product is impacted by the cryptographic issues vulnerability. The encryption algorithm is not properly used, so remote attackers could use this vulnerability for account credential enumeration attack or brute-forc...Show more |
1Ibm 1Security Guardium Insights Jun 17, 2026 Aug 27, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IBM Security Guardium Insights 2.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 174683. |
1Ibm 1Security Guardium Insights Jun 17, 2026 Aug 27, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IBM Security Guardium Insights 2.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 174405. |
A vulnerability in the in-band key negotiation exists in the AWS S3 Crypto SDK for GoLang versions prior to V2. An attacker with write access to the targeted bucket can change the encryption algorithm of an object in the...Show more |