CWE-327
685 CVEs • Abstraction: Class • Likelihood of Exploit: High
Use of a Broken or Risky Cryptographic Algorithm
The product uses a broken or risky cryptographic algorithm or protocol.
CVEs (685)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Cavium Cisco14Ace30 Application Control Engine Module Firmware Ace4710 Application Control Engine FirmwareAdaptive Security Appliance 5505 Firmware+11 moreNov 21, 2024 Mar 5, 2018 N/A· v4 5.9 MEDIUM· v3 7.1 HIGH· v2 Cavium Nitrox SSL, Nitrox V SSL, and TurboSSL software development kits (SDKs) allow remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a ROBOT attack. |
An issue was discovered in iDashboards 9.6b. The SSO implementation is affected by a weak obfuscation library, allowing man-in-the-middle attackers to discover credentials. |
cipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages directly, improperly encodes plaintexts, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not hav...Show more |
1Valvesoftware 1Steam Link Firmware May 13, 2026 Dec 27, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An issue was discovered in Valve Steam Link build 643. Root passwords longer than 8 characters are truncated because of the default use of DES (aka the CONFIG_FEATURE_DEFAULT_PASSWD_ALGO="des" setting). |
IBM Security Guardium 10.0 Database Activity Monitor uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 132611. |
1Sonatype 1Nexus Repository Manager May 13, 2026 Dec 17, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Sonatype Nexus Repository Manager through 2.14.5 has weak password encryption with a hardcoded CMMDwoV value in the LDAP integration feature. |
1Citrix 2Application Delivery Controller Firmware Netscaler Gateway FirmwareMay 13, 2026 Dec 13, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.5 before build 67.13, 11.0 before build 71.22, 11.1 before build 56.19, and 12.0 before build 53.22 might allow remote attackers to decrypt...Show more |
1Cognitoys 1Stemosaur Firmware May 13, 2026 Dec 11, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Elemental Path's CogniToys Dino smart toys through firmware version 0.0.794 share a fixed small pool of hardcoded keys, allowing a remote attacker to use a different Dino device to decrypt VoIP traffic between a child's...Show more |
1Huawei 1Fusionsphere Openstack May 13, 2026 Nov 22, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 FusionSphere OpenStack V100R006C00SPC102(NFV)has a week cryptographic algorithm vulnerability. Attackers may exploit the vulnerability to crack the cipher text and cause information leak on the transmission links. |
1Huawei 2Oceanstor 5800 V3 Firmware Oceanstor 6900 V3 FirmwareMay 13, 2026 Nov 22, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 OceanStor 5800 V3 with software V300R002C00 and V300R002C10, OceanStor 6900 V3 V300R001C00 has an information leakage vulnerability. Products use TLS1.0 to encrypt. Attackers can exploit TLS1.0's vulnerabilities to decry...Show more |
Apache Hadoop before 0.23.4, 1.x before 1.0.4, and 2.x before 2.0.2 generate token passwords using a 20-bit secret when Kerberos security features are enabled, which makes it easier for context-dependent attackers to cra...Show more |
Apache WSS4J before 1.6.17 and 2.0.x before 2.0.2 improperly leaks information about decryption failures when decrypting an encrypted key or message data, which makes it easier for remote attackers to recover the plainte...Show more |
1Nq 1Contacts Backup & Restore May 13, 2026 Oct 29, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In the "NQ Contacts Backup & Restore" application 1.1 for Android, DES encryption with a static key is used to secure transmitted contact data. This makes it easier for remote attackers to obtain cleartext information by...Show more |
In the "NQ Contacts Backup & Restore" application 1.1 for Android, RC4 encryption is used to secure the user password locally stored in shared preferences. Because there is a static RC4 key, an attacker can gain access t...Show more |
The airbag detonation algorithm allows injury to passenger-car occupants via predictable Security Access (SA) data to the internal CAN bus (or the OBD connector). This affects the airbag control units (aka pyrotechnical...Show more |
IBM Spectrum Protect 7.1 and 8.1 (formerly Tivoli Storage Manager) Server uses weak encryption for the password. A database administrator may be able to decrypt the IBM Spectrum protect client or administrator password w...Show more |
In all Qualcomm products with Android releases from CAF using the Linux kernel, the GPS client may use an insecure cryptographic algorithm. |
1Sma 39Sunny Boy 1.5 Firmware Sunny Boy 2.5 FirmwareSunny Boy 3.0 Firmware+36 moreMay 13, 2026 Aug 5, 2017 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 An issue was discovered in SMA Solar Technology products. The inverters make use of a weak hashing algorithm to encrypt the password for REGISTER requests. This hashing algorithm can be cracked relatively easily. An atta...Show more |
An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android, through 0.0.80w for Web, and through 0.0.86 for Desktop. To encrypt messages, AES in CBC mode is used with a pseudo-random secret. This secret...Show more |
1Xoev 1Osci Transport Library May 13, 2026 Jun 30, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A Padding Oracle exists in OSCI-Transport 1.2 as used in OSCI Transport Library 1.6.1 (Java) and OSCI Transport Library 1.6 (.NET). Under an MITM condition within the OSCI infrastructure, an attacker needs to send crafte...Show more |