CWE-330
397 CVEs • Abstraction: Class • Likelihood of Exploit: High
Use of Insufficiently Random Values
The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.
CVEs (397)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Consensys Discovery versions less than 0.4.5 uses the same AES/GCM nonce for the entire session. which should ideally be unique for every message. The node's private key isn't compromised, only the session key generated...Show more |
CubeFS is an open-source cloud-native file storage system. Prior to version 3.3.1, CubeFS used an insecure random string generator to generate user-specific, sensitive keys used to authenticate users in a CubeFS deployme...Show more |
In wlan driver, there is a possible PIN crack due to use of insufficiently random values. This could lead to local information disclosure with no execution privileges needed. User interaction is not needed for exploitati...Show more |
1Poly 4Ccx 400 Firmware Ccx 600 FirmwareTrio 8800 Firmware+1 moreJun 17, 2026 Dec 29, 2023 N/A· v4 5.9 MEDIUM· v3 2.6 LOW· v2 A vulnerability classified as problematic has been found in Poly Trio 8300, Trio 8500, Trio 8800, Trio C60, CCX 350, CCX 400, CCX 500, CCX 505, CCX 600, CCX 700, EDGE E100, EDGE E220, EDGE E300, EDGE E320, EDGE E350, EDG...Show more |
Henschen & Associates court document management software does not sufficiently randomize file names of cached documents, allowing a remote, unauthenticated attacker to access restricted documents.
|
PyPinkSign v0.5.1 uses a non-random or static IV for Cipher Block Chaining (CBC) mode in AES encryption. This vulnerability can lead to the disclosure of information and communications. |
1Microchip 1Mplab Network Creator Jun 17, 2026 Oct 10, 2023 N/A· v4 9.1 CRITICAL· v3 N/A· v2 In Microchip MPLAB Net 3.6.1, TCP ISNs are improperly random. |
In PicoTCP 1.7.0, TCP ISNs are improperly random. |
In Contiki 4.5, TCP ISNs are improperly random. |
In FNET 4.6.3, TCP ISNs are improperly random. |
In Oryx CycloneTCP 1.9.6, TCP ISNs are improperly random. |
In Silicon Labs uC/TCP-IP 3.6.0, TCP ISNs are improperly random. |
An issue was discovered in Ethernut Nut/OS 5.1. The code that generates Initial Sequence Numbers (ISNs) for TCP connections derives the ISN from an insufficiently random source. As a result, an attacker may be able to de...Show more |
1Microsoft 1Azure Kubernetes Service Jun 17, 2026 Sep 12, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability |
Magento LTS is the official OpenMage LTS codebase. Guest orders may be viewed without authentication using a "guest-view" cookie which contains the order's "protect_code". This code is 6 hexadecimal characters which is a...Show more |
An authentication bypass vulnerability exists in the OAS Engine authentication functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted network sniffing can lead to decryption of sensitive...Show more |
There is a vulnerability in MXsecurity versions prior to 1.0.1 that can be exploited to bypass authentication. A remote attacker might access the system if the web service authenticator has insufficient random values....Show more |
1Broadcom 1Raid Controller Web Interface Jun 17, 2026 Aug 15, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Broadcom RAID Controller web interface is vulnerable to insufficient randomness due to improper use of ssl.rnd to setup CIM connection |
Use of insufficiently random values for some Intel Agilex(R) software included as part of Intel(R) Quartus(R) Prime Pro Edition for linux before version 22.4 may allow an authenticated user to potentially enable informat...Show more |
1Mitsubishielectric 2Gs21 Firmware Gt21 FirmwareJun 17, 2026 Aug 4, 2023 N/A· v4 9.1 CRITICAL· v3 N/A· v2 Predictable Exact Value from Previous Values vulnerability in Mitsubishi Electric Corporation GOT2000 Series GT21 model versions 01.49.000 and prior and GOT SIMPLE Series GS21 model versions 01.49.000 and prior allows a...Show more |