CWE-330
380 CVEs • Abstraction: Class • Likelihood of Exploit: High
Use of Insufficiently Random Values
The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.
CVEs (380)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
totd before 1.5.3 does not properly randomize mesg IDs. |
ZTE's MF297D product has cryptographic issues vulnerability. Due to the use of weak random values, the security of the device is reduced, and it may face the risk of attack. |
The Linux kernel before 5.17.9 allows TCP servers to identify clients by observing what source ports are used. This occurs because of use of Algorithm 4 ("Double-Hash Port Selection Algorithm") of RFC 6056. |
1Openmoney Api Project 1Openmoney Api Jun 17, 2026 May 16, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Openmoney API through 2020-06-29 uses the JavaScript Math.random function, which does not provide cryptographically secure random numbers. |
SHA1 implementation in JetBrains Ktor Native 2.0.0 was returning the same value. The issue was fixed in Ktor version 2.0.1. |
2Uclibc Uclibc Ng Project2Uclibc Uclibc NgJun 17, 2026 May 6, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 uClibc-ng through 1.0.40 and uClibc through 0.9.33.2 use predictable DNS transaction IDs that may lead to DNS cache poisoning. This is related to a reset of a value to 0x2. |
1F5 11Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+8 moreJun 17, 2026 May 5, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, a flaw in the way reply ICMP p...Show more |
1Pingidentity 2Pingid Pingid Windows LoginJun 17, 2026 Apr 30, 2022 N/A· v4 4.8 MEDIUM· v3 1.9 LOW· v2 A misconfiguration of RSA in PingID iOS app prior to 1.19 is vulnerable to pre-computed dictionary attacks, leading to an offline MFA bypass when using PingID Windows Login. |
1Pingidentity 2Pingid Pingid Windows LoginJun 17, 2026 Apr 30, 2022 N/A· v4 4.8 MEDIUM· v3 1.9 LOW· v2 A misconfiguration of RSA in PingID Android app prior to 1.19 is vulnerable to pre-computed dictionary attacks, leading to an offline MFA bypass when using PingID Windows Login. |
1Swiftsensors 1Sg3 1010 Firmware Jun 17, 2026 Apr 14, 2022 N/A· v4 10.0 CRITICAL· v3 10.0 HIGH· v2 An authentication bypass vulnerability exists in the device password generation functionality of Swift Sensors Gateway SG3-1010. A specially-crafted network request can lead to remote code execution. An attacker can send...Show more |
1Siemens 23Scalance X302 7eec Firmware Scalance X304 2fe FirmwareScalance X306 1ldfe Firmware+20 moreJun 17, 2026 Apr 12, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability has been identified in SCALANCE X302-7 EEC (230V), SCALANCE X302-7 EEC (230V, coated), SCALANCE X302-7 EEC (24V), SCALANCE X302-7 EEC (24V, coated), SCALANCE X302-7 EEC (2x 230V), SCALANCE X302-7 EEC (2x...Show more |
The vulnerability in the MSC800 in all versions before 4.15 allows for an attacker to predict the TCP initial sequence number. When the TCP sequence is predictable, an attacker can send packets that are forged to appear...Show more |
In JetBrains Ktor Native before version 2.0.0 random values used for nonce generation weren't using SecureRandom implementations |
1Dell 1Emc Powerscale Onefs Jun 17, 2026 Apr 8, 2022 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Dell PowerScale OneFS, 8.2.2-9.3.x, contains a predictable file name from observable state vulnerability. An unprivileged network attacker could potentially exploit this vulnerability, leading to data loss. |
1Codesys 20Control For Beaglebone Sl Control For Beckhoff Cx9020Control For Empc A/imx6 Sl+17 moreJun 17, 2026 Apr 7, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An unauthenticated, remote attacker can disrupt existing communication channels between CODESYS products by guessing a valid channel ID and injecting packets. This results in the communication channel to be closed. |
randomUUID in Scala.js before 1.10.0 generates predictable values. |
Totolink A3100R V5.9c.4577 suffers from Use of Insufficiently Random Values via the web configuration. The SESSION_ID is predictable. An attacker can hijack a valid session and conduct further malicious operations. |
3Canon FujifilmRambus92Apeos C3070 Firmware Apeos C3070 G FirmwareApeos C325 Dw Firmware+89 moreJun 17, 2026 Mar 14, 2022 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 The Rambus SafeZone Basic Crypto Module before 10.4.0, as used in certain Fujifilm (formerly Fuji Xerox) devices before 2022-03-01, Canon imagePROGRAF and imageRUNNER devices through 2022-03-14, and potentially many othe...Show more |
A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.29). When returning the result of a completed Microflow execution call the affected framework does not correctly verify, if...Show more |
CyberArk Identity versions up to and including 22.1 in the 'StartAuthentication' resource, exposes the response header 'X-CFY-TX-TM'. In certain configurations, that response header contains different, predictable value...Show more |