← Back
CWE-330

397 CVEs • Abstraction: Class • Likelihood of Exploit: High

Use of Insufficiently Random Values

The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.

JSON object

Loading...

CVEs (397)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Consensys
1Discovery
Jul 14, 2026
Jan 19, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Consensys Discovery versions less than 0.4.5 uses the same AES/GCM nonce for the entire session. which should ideally be unique for every message. The node's private key isn't compromised, only the session key generated...Show more
Consensys Discovery versions less than 0.4.5 uses the same AES/GCM nonce for the entire session. which should ideally be unique for every message. The node's private key isn't compromised, only the session key generated for specific peer communication is exposed.Show less
1Linuxfoundation
1Cubefs
Jun 17, 2026
Jan 3, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
CubeFS is an open-source cloud-native file storage system. Prior to version 3.3.1, CubeFS used an insecure random string generator to generate user-specific, sensitive keys used to authenticate users in a CubeFS deployme...Show more
CubeFS is an open-source cloud-native file storage system. Prior to version 3.3.1, CubeFS used an insecure random string generator to generate user-specific, sensitive keys used to authenticate users in a CubeFS deployment. This could allow an attacker to predict and/or guess the generated string and impersonate a user thereby obtaining higher privileges. When CubeFS creates new users, it creates a piece of sensitive information for the user called the “accessKey”. To create the "accesKey", CubeFS uses an insecure string generator which makes it easy to guess and thereby impersonate the created user. An attacker could leverage the predictable random string generator and guess a users access key and impersonate the user to obtain higher privileges. The issue has been fixed in v3.3.1. There is no other mitigation than to upgrade.Show less
1Mediatek
1Software Development Kit
Jun 17, 2026
Jan 2, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In wlan driver, there is a possible PIN crack due to use of insufficiently random values. This could lead to local information disclosure with no execution privileges needed. User interaction is not needed for exploitati...Show more
In wlan driver, there is a possible PIN crack due to use of insufficiently random values. This could lead to local information disclosure with no execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00325055; Issue ID: MSV-868.Show less
1Poly
4Ccx 400 Firmware
Ccx 600 FirmwareTrio 8800 Firmware+1 more
Jun 17, 2026
Dec 29, 2023
N/A· v4
5.9 MEDIUM· v3
2.6 LOW· v2
A vulnerability classified as problematic has been found in Poly Trio 8300, Trio 8500, Trio 8800, Trio C60, CCX 350, CCX 400, CCX 500, CCX 505, CCX 600, CCX 700, EDGE E100, EDGE E220, EDGE E300, EDGE E320, EDGE E350, EDG...Show more
A vulnerability classified as problematic has been found in Poly Trio 8300, Trio 8500, Trio 8800, Trio C60, CCX 350, CCX 400, CCX 500, CCX 505, CCX 600, CCX 700, EDGE E100, EDGE E220, EDGE E300, EDGE E320, EDGE E350, EDGE E400, EDGE E450, EDGE E500, EDGE E550, VVX 101, VVX 150, VVX 201, VVX 250, VVX 300, VVX 301, VVX 310, VVX 311, VVX 350, VVX 400, VVX 401, VVX 410, VVX 411, VVX 450, VVX 500, VVX 501, VVX 600 and VVX 601. This affects an unknown part of the component Web Configuration Application. The manipulation leads to insufficiently random values. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249255.Show less
1Henschen
1Court Document Management
Jun 17, 2026
Nov 30, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Henschen & Associates court document management software does not sufficiently randomize file names of cached documents, allowing a remote, unauthenticated attacker to access restricted documents.
1Bandoche
1Pypinksign
Jul 9, 2026
Nov 16, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
PyPinkSign v0.5.1 uses a non-random or static IV for Cipher Block Chaining (CBC) mode in AES encryption. This vulnerability can lead to the disclosure of information and communications.
1Microchip
1Mplab Network Creator
Jun 17, 2026
Oct 10, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
In Microchip MPLAB Net 3.6.1, TCP ISNs are improperly random.
1Capgemini
1Picotcp
Jun 17, 2026
Oct 10, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
In PicoTCP 1.7.0, TCP ISNs are improperly random.
1Contiki Ng
1Contiki Ng.
Jun 17, 2026
Oct 10, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
In Contiki 4.5, TCP ISNs are improperly random.
1Butok
1Fnet
Jun 17, 2026
Oct 10, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
In FNET 4.6.3, TCP ISNs are improperly random.
1Oryx Embedded
1Cyclonetcp
Jun 17, 2026
Oct 10, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In Oryx CycloneTCP 1.9.6, TCP ISNs are improperly random.
1Silabs
1Uc/tcp Ip
Jun 17, 2026
Oct 10, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In Silicon Labs uC/TCP-IP 3.6.0, TCP ISNs are improperly random.
1Ethernut
1Nut/os
Jun 17, 2026
Oct 10, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in Ethernut Nut/OS 5.1. The code that generates Initial Sequence Numbers (ISNs) for TCP connections derives the ISN from an insufficiently random source. As a result, an attacker may be able to de...Show more
An issue was discovered in Ethernut Nut/OS 5.1. The code that generates Initial Sequence Numbers (ISNs) for TCP connections derives the ISN from an insufficiently random source. As a result, an attacker may be able to determine the ISN of current and future TCP connections and either hijack existing ones or spoof future ones. While the ISN generator seems to adhere to RFC 793 (where a global 32-bit counter is incremented roughly every 4 microseconds), proper ISN generation should aim to follow at least the specifications outlined in RFC 6528.Show less
1Microsoft
1Azure Kubernetes Service
Jun 17, 2026
Sep 12, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
1Openmage
1Magento
Jun 17, 2026
Sep 11, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Magento LTS is the official OpenMage LTS codebase. Guest orders may be viewed without authentication using a "guest-view" cookie which contains the order's "protect_code". This code is 6 hexadecimal characters which is a...Show more
Magento LTS is the official OpenMage LTS codebase. Guest orders may be viewed without authentication using a "guest-view" cookie which contains the order's "protect_code". This code is 6 hexadecimal characters which is arguably not enough to prevent a brute-force attack. Exposing each order would require a separate brute force attack. This issue has been patched in versions 19.5.1 and 20.1.1.Show less
1Openautomationsoftware
1Oas Platform
Jun 17, 2026
Sep 5, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An authentication bypass vulnerability exists in the OAS Engine authentication functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted network sniffing can lead to decryption of sensitive...Show more
An authentication bypass vulnerability exists in the OAS Engine authentication functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted network sniffing can lead to decryption of sensitive information. An attacker can sniff network traffic to trigger this vulnerability.Show less
1Moxa
1Mxsecurity
Jun 17, 2026
Sep 2, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
There is a vulnerability in MXsecurity versions prior to 1.0.1 that can be exploited to bypass authentication. A remote attacker might access the system if the web service authenticator has insufficient random values....Show more
There is a vulnerability in MXsecurity versions prior to 1.0.1 that can be exploited to bypass authentication. A remote attacker might access the system if the web service authenticator has insufficient random values.   Show less
1Broadcom
1Raid Controller Web Interface
Jun 17, 2026
Aug 15, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Broadcom RAID Controller web interface is vulnerable to insufficient randomness due to improper use of ssl.rnd to setup CIM connection
1Intel
1Quartus Prime
Jun 17, 2026
Aug 15, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Use of insufficiently random values for some Intel Agilex(R) software included as part of Intel(R) Quartus(R) Prime Pro Edition for linux before version 22.4 may allow an authenticated user to potentially enable informat...Show more
Use of insufficiently random values for some Intel Agilex(R) software included as part of Intel(R) Quartus(R) Prime Pro Edition for linux before version 22.4 may allow an authenticated user to potentially enable information disclosure via local access.Show less
1Mitsubishielectric
2Gs21 Firmware
Gt21 Firmware
Jun 17, 2026
Aug 4, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Predictable Exact Value from Previous Values vulnerability in Mitsubishi Electric Corporation GOT2000 Series GT21 model versions 01.49.000 and prior and GOT SIMPLE Series GS21 model versions 01.49.000 and prior allows a...Show more
Predictable Exact Value from Previous Values vulnerability in Mitsubishi Electric Corporation GOT2000 Series GT21 model versions 01.49.000 and prior and GOT SIMPLE Series GS21 model versions 01.49.000 and prior allows a remote unauthenticated attacker to hijack data connections (session hijacking) or prevent legitimate users from establishing data connections (to cause DoS condition) by guessing the listening port of the data connection on FTP server and connecting to it.Show less