CWE-327
685 CVEs • Abstraction: Class • Likelihood of Exploit: High
Use of a Broken or Risky Cryptographic Algorithm
The product uses a broken or risky cryptographic algorithm or protocol.
CVEs (685)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Avaya one-X Communicator uses weak cryptographic algorithms in the client authentication component that could allow a local attacker to decrypt sensitive information. Affected versions include all 6.2.x versions prior to...Show more |
1F5 12Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+9 moreJun 17, 2026 Feb 26, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 On BIG-IP 11.5.1-11.5.4, 11.6.1, and 12.1.0, a virtual server configured with a Client SSL profile may be vulnerable to a chosen ciphertext attack against CBC ciphers. When exploited, this may result in plaintext recover...Show more |
1Citrix 2Netscaler Application Delivery Controller Firmware Netscaler Gateway FirmwareJun 17, 2026 Feb 22, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Citrix NetScaler Gateway 12.1 before build 50.31, 12.0 before build 60.9, 11.1 before build 60.14, 11.0 before build 72.17, and 10.5 before build 69.5 and Application Delivery Controller (ADC) 12.1 before build 50.31, 12...Show more |
4Debian FedoraprojectGoogle+1 more6Chrome Debian LinuxEnterprise Linux Desktop+3 moreJun 17, 2026 Feb 19, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Implementation error in QUIC Networking in Google Chrome prior to 72.0.3626.81 allowed an attacker running or able to cause use of a proxy server to obtain cleartext of transport encryption via malicious network proxy. |
1Ibm 1Websphere Application Server Nov 21, 2024 Feb 19, 2019 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could provide weaker than expected security, caused by the improper TLS configuration. A remote attacker could exploit this vulnerability to obtain sensitive inform...Show more |
An issue was discovered on MOBOTIX S14 MX-V4.2.1.61 devices. Administrator Credentials are stored in the 13-character DES hash format. |
2Kube Rbac Proxy Project Redhat2Kube Rbac Proxy Openshift Container PlatformJun 17, 2026 Feb 5, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The kube-rbac-proxy container before version 0.4.1 as used in Red Hat OpenShift Container Platform does not honor TLS configurations, allowing for use of insecure ciphers and TLS 1.0. An attacker could target traffic sen...Show more |
1Juniper 1Advanced Threat Prevention Firmware Jun 17, 2026 Jan 15, 2019 N/A· v4 7.2 HIGH· v3 4.0 MEDIUM· v2 Juniper ATP uses DES and a hardcoded salt for password hashing, allowing for trivial de-hashing of the password file contents. This issue affects Juniper ATP 5.0 versions prior to 5.0.3. |
2Debian Wireshark2Debian Linux WiresharkJun 17, 2026 Jan 8, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the ISAKMP dissector could crash. This was addressed in epan/dissectors/packet-isakmp.c by properly handling the case of a missing decryption data block. |
1Huawei 1Espace 7950 Firmware Jun 17, 2026 Nov 27, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 There is a short key vulnerability in Huawei eSpace product. An unauthenticated, remote attacker launches man-in-the-middle attack to intercept and decrypt the call information when the user enables SRTP to make a call....Show more |
6Canonical DebianNetapp+3 more19Api Gateway Cloud BackupCn1610 Firmware+16 moreNov 21, 2024 Oct 30, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.1a (Affected...Show more |
6Canonical DebianNetapp+3 more22Api Gateway Application ServerCloud Backup+19 moreNov 21, 2024 Oct 29, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.0j (Affect...Show more |
BigProf AppGini 5.70 stores the passwords in the database using the MD5 hash. |
1Dell 2Bsafe Crypto J Rsa Bsafe Ssl JNov 21, 2024 Sep 11, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 RSA BSAFE Crypto-J versions prior to 6.2.4 and RSA BSAFE SSL-J versions prior to 6.2.4 contain a Covert Timing Channel vulnerability during PKCS #1 unpadding operations, also known as a Bleichenbacher attack. A remote at...Show more |
RSA BSAFE SSL-J versions prior to 6.2.4 contain a Covert Timing Channel vulnerability during RSA decryption, also known as a Bleichenbacher attack on RSA decryption. A remote attacker may be able to recover a RSA key. |
1Pektron 1Passive Keyless Entry And Start System Firmware Nov 21, 2024 Sep 10, 2018 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 A Pektron Passive Keyless Entry and Start (PKES) system, as used on the Tesla Model S and possibly other vehicles, relies on the DST40 cipher, which makes it easier for attackers to obtain access via an approach involvin...Show more |
2Dell Oracle12Application Testing Suite BsafeCommunications Analytics+9 moreNov 21, 2024 Aug 31, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6.1 (in 4.1.x) contains a Covert Timing Channel vulnerability during RSA decryption, also known as a Bleichenbacher attack on RSA decryp...Show more |
1Schneider Electric 1Modicon M221 Firmware Jun 17, 2026 Aug 29, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A Permissions, Privileges, and Access Control vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firmware V1.6.2.0). The vulnerability allows unauthorized users to de...Show more |
5Canonical DebianFedoraproject+2 more7Debian Linux Enterprise Linux DesktopEnterprise Linux Server+4 moreNov 21, 2024 Aug 22, 2018 N/A· v4 5.6 MEDIUM· v3 1.9 LOW· v2 A cache-based side channel in GnuTLS implementation that leads to plain text recovery in cross-VM attack setting was found. An attacker could use a combination of "Just in Time" Prime+probe attack in combination with Luc...Show more |
5Canonical DebianFedoraproject+2 more7Debian Linux Enterprise Linux DesktopEnterprise Linux Server+4 moreNov 21, 2024 Aug 22, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 It was found that the GnuTLS implementation of HMAC-SHA-384 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to conduct distinguishing attacks and plain text recovery attacks via stat...Show more |