CWE-327
685 CVEs • Abstraction: Class • Likelihood of Exploit: High
Use of a Broken or Risky Cryptographic Algorithm
The product uses a broken or risky cryptographic algorithm or protocol.
CVEs (685)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
7Apple CanonicalDebian+4 more147Alp Al00b Firmware AndroidAres Al00b Firmware+144 moreJun 17, 2026 Aug 14, 2019 N/A· v4 8.1 HIGH· v3 4.8 MEDIUM· v2 The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-...Show more |
1Siemens 20Simatic Cp 1626 Firmware Simatic Et 200sp Open Controller Cpu 1515sp Pc2 FirmwareSimatic Et 200sp Open Controller Cpu 1515sp Pc Firmware+17 moreJun 17, 2026 Aug 13, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability has been identified in SIMATIC CP 1626 (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants) (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS...Show more |
The PHP JOSE Library by Gree Inc. before version 2.2.1 is vulnerable to key confusion/algorithm substitution in the JWS component resulting in bypassing the signature verification via crafted tokens. |
SMB in Data ONTAP operating in 7-Mode versions prior to 8.2.5P3 has weak cryptography which when exploited could lead to information disclosure or addition or modification of data. |
A cryptographic flaw in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9 and Magento 2.3 prior to 2.3.2 resulted in storage of sensitive information with an algorithm that is insufficiently resistant to brute forc...Show more |
1Assaabloy 1Hid Digitalpersona 4500 Firmware Jun 17, 2026 Jul 15, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 There is a short key vulnerability in HID Global DigitalPersona (formerly Crossmatch) U.are.U 4500 Fingerprint Reader v24. The key for obfuscating the fingerprint image is vulnerable to brute-force attacks. This allows a...Show more |
1Logitech 1Unifying Receiver Firmware Jun 17, 2026 Jun 29, 2019 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 Logitech Unifying devices allow live decryption if the pairing of a keyboard to a receiver is sniffed. |
2Amd Opensuse2Leap Secure Encrypted Virtualization FirmwareJun 17, 2026 Jun 25, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Secure Encrypted Virtualization (SEV) on Advanced Micro Devices (AMD) Platform Security Processor (PSP; aka AMD Secure Processor or AMD-SP) 0.17 build 11 and earlier has an insecure cryptographic implementation. |
1Ibm 1Security Access Manager Jun 17, 2026 Jun 25, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 IBM Security Access Manager 9.0.1 through 9.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 158572. |
HAProxy before 1.9.7 mishandles a reload with rotated keys, which triggers use of uninitialized, and very predictable, HMAC keys. This is related to an include/types/ssl_sock.h error. |
1Cisco 1Adaptive Security Appliance Software Jun 17, 2026 May 3, 2019 N/A· v4 8.6 HIGH· v3 7.8 HIGH· v2 A vulnerability in the software cryptography module of the Cisco Adaptive Security Virtual Appliance (ASAv) and Firepower 2100 Series running Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticate...Show more |
IBM Sterling B2B Integrator Standard Edition 5.2.0.1, 5.2.6.3_6, 6.0.0.0, and 6.0.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force I...Show more |
1Microsoft 6Windows 10 Windows 8.1Windows Rt 8.1+3 moreJun 17, 2026 Apr 9, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An information disclosure vulnerability exists when the Windows TCP/IP stack improperly handles fragmented IP packets, aka 'Windows TCP/IP Information Disclosure Vulnerability'. |
1Cisco 2Rv320 Firmware Rv325 FirmwareJun 17, 2026 Apr 4, 2019 N/A· v4 8.1 HIGH· v3 4.3 MEDIUM· v2 A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to access administrative credentials. The vulnera...Show more |
A vulnerability in SonicWall SonicOS and SonicOSv TLS CBC Cipher allow remote attackers to obtain sensitive plaintext data when CBC cipher suites are enabled. This vulnerability affected SonicOS Gen 5 version 5.9.1.10 an...Show more |
An issue was discovered in portier vision 4.4.4.2 and 4.4.4.6. Passwords are stored using reversible encryption rather than as a hash value, and the used Vigenere algorithm is badly outdated. Moreover, the encryption key...Show more |
1Nablarch Project 1Nablarch Jun 17, 2026 Mar 12, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An incomplete cryptography of the data store function by using hidden tag in Nablarch 5 (5, and 5u1 to 5u13) allows remote attackers to obtain information of the stored data, to register invalid value, or alter the value...Show more |
ChaCha20-Poly1305 is an AEAD cipher, and requires a unique nonce input for every encryption operation. RFC 7539 specifies that the nonce value (IV) should be 96 bits (12 bytes). OpenSSL allows a variable nonce length and...Show more |
Unauthenticated RCE is possible when JMeter is used in distributed mode (-r or -R command line options). Attacker can establish a RMI connection to a jmeter-server using RemoteJMeterEngine and proceed with an attack usin...Show more |
1Amazon 1Ring Video Doorbell Firmware Jun 17, 2026 Mar 1, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Amazon Ring Doorbell before 3.4.7 mishandles encryption, which allows attackers to obtain audio and video data, or insert spoofed video that does not correspond to the actual person at the door. |