CWE-327
685 CVEs • Abstraction: Class • Likelihood of Exploit: High
Use of a Broken or Risky Cryptographic Algorithm
The product uses a broken or risky cryptographic algorithm or protocol.
CVEs (685)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1St 4St33tphf20i2c Firmware St33tphf20spi FirmwareSt33tphf2ei2c Firmware+1 moreJun 17, 2026 Nov 14, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 STMicroelectronics ST33TPHF2ESPI TPM devices before 2019-09-12 allow attackers to extract the ECDSA private key via a side-channel timing attack because ECDSA scalar multiplication is mishandled, aka TPM-FAIL. |
Password-based encryption (PBE) algorithm, of Brocade SANnav versions before v2.0, has a weakness in generating cryptographic keys that may allow an attacker to decrypt passwords used with several services (Radius, TACAS...Show more |
IBM Cloud Orchestrator 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 162260. |
1Adobe 2Acrobat Dc Acrobat Reader DcJun 17, 2026 Oct 23, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an insuffi...Show more |
On certain Samsung P(9.0) phones, an attacker with physical access can start a TCP Dump capture without the user's knowledge. This feature of the Service Mode application is available after entering the *#9900# check cod...Show more |
"managed-keys" is a feature which allows a BIND resolver to automatically maintain the keys used by trust anchors which operators configure for use in DNSSEC validation. Due to an error in the managed-keys feature it is...Show more |
MatrixSSL 4.2.1 and earlier contains a timing side channel in ECDSA signature generation. This allows a local or a remote attacker, able to measure the duration of hundreds to thousands of signing operations, to compute...Show more |
1Enterprisedt 1Completeftp Server Jun 17, 2026 Oct 2, 2019 N/A· v4 4.3 MEDIUM· v3 3.5 LOW· v2 EnterpriseDT CompleteFTP Server prior to version 12.1.3 is vulnerable to information exposure in the Bootstrap.log file. This allows an attacker to obtain the administrator password hash. |
1Dell 1Emc Integrated Data Protection Appliance Firmware Jun 17, 2026 Sep 27, 2019 N/A· v4 7.2 HIGH· v3 4.0 MEDIUM· v2 Dell EMC Integrated Data Protection Appliance versions prior to 2.3 contain a password storage vulnerability in the ACM component. A remote authenticated malicious user with root privileges may potentially use a support...Show more |
The Print Service is susceptible to man in the middle attacks due to improperly used crypto. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed...Show more |
The PGP signing plugin in Gradle before 6.0 relies on the SHA-1 algorithm, which might allow an attacker to replace an artifact with a different one that has the same SHA-1 message digest, a related issue to CVE-2005-490...Show more |
In situations where an attacker receives automated notification of the success or failure of a decryption attempt an attacker, after sending a very large number of messages to be decrypted, can recover a CMS/PKCS7 transp...Show more |
An issue was discovered in the blake2 crate before 0.8.1 for Rust. The BLAKE2b and BLAKE2s algorithms, when used with HMAC, produce incorrect results because the block sizes are half of the required sizes. |
An issue was discovered in Total.js CMS 12.0.0. A low privilege user can perform a simple transformation of a cookie to obtain the random values inside it. If an attacker can discover a session cookie owned by an admin,...Show more |
1Espressif 2Esp Idf Esp8266 Nonos SdkJun 17, 2026 Sep 4, 2019 N/A· v4 8.1 HIGH· v3 4.8 MEDIUM· v2 The EAP peer implementation in Espressif ESP-IDF 2.0.0 through 4.0.0 and ESP8266_NONOS_SDK 2.2.0 through 3.1.0 allows the installation of a zero Pairwise Master Key (PMK) after the completion of any EAP authentication me...Show more |
1Broadcom 2Advanced Secure Gateway Symantec ProxysgNov 21, 2024 Aug 30, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The ASG/ProxySG FTP proxy WebFTP mode allows intercepting FTP connections where a user accesses an FTP server via a ftp:// URL in a web browser. An information disclosure vulnerability in the WebFTP mode allows a malicio...Show more |
A cryptographic issue in OpenPGP.js <=4.2.0 allows an attacker who is able provide forged messages and gain feedback about whether decryption of these messages succeeded to conduct an invalid curve attack in order to gai...Show more |
1Cisco 5Hyperflex Hx220c Af M5 Firmware Hyperflex Hx220c Edge M5 FirmwareHyperflex Hx220c M5 Firmware+2 moreJun 17, 2026 Aug 21, 2019 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 A vulnerability in Cisco HyperFlex Software could allow an unauthenticated, remote attacker to perform a man-in-the-middle attack. The vulnerability is due to insufficient key management. An attacker could exploit this v...Show more |
1Google 1Nest Cam Iq Indoor Firmware Jun 17, 2026 Aug 20, 2019 N/A· v4 9.0 CRITICAL· v3 6.8 MEDIUM· v2 An exploitable information disclosure vulnerability exists in the Weave PASE pairing functionality of the Nest Cam IQ Indoor, version 4620002. A set of specially crafted weave packets can brute force a pairing code, resu...Show more |
1Codesys 12Control For Beaglebone Sl Control For Empc A/imx6 SlControl For Iot2000 Sl+9 moreJun 17, 2026 Aug 15, 2019 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 An issue was discovered in 3S-Smart CODESYS V3 products. The application may utilize non-TLS based encryption, which results in user credentials being insufficiently protected during transport. All variants of the follow...Show more |