CWE-330
397 CVEs • Abstraction: Class • Likelihood of Exploit: High
Use of Insufficiently Random Values
The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.
CVEs (397)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Zte 2Zxhn H108n Firmware Zxhn H168n FirmwareJun 17, 2026 Apr 13, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Some ZTE products have CSRF vulnerability. Because some pages lack CSRF random value verification, attackers could perform illegal authorization operations by constructing messages.This affects: ZXHN H168N V3.5.0_EG1T5_T...Show more |
Using predictable index for attachments in Samsung Email prior to version 6.1.41.0 allows remote attackers to get attachments of another emails when users open the malicious attachment. |
3Fedoraproject Libtpms ProjectRedhat3Enterprise Linux FedoraLibtpmsJun 17, 2026 Mar 25, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A flaw was found in libtpms in versions before 0.8.2. The commonly used integration of libtpms with OpenSSL contained a vulnerability related to the returned IV (initialization vector) when certain symmetric ciphers were...Show more |
In Netflix OSS Hollow, since the Files.exists(parent) is run before creating the directories, an attacker can pre-create these directories with wide permissions. Additionally, since an insecure source of randomness is us...Show more |
1Huawei 4Usg9500 Firmware Usg9520 FirmwareUsg9560 Firmware+1 moreJun 17, 2026 Mar 22, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 There is insecure algorithm vulnerability in Huawei products. A module uses less random input in a secure mechanism. Attackers can exploit this vulnerability by brute forcing to obtain sensitive message. This can lead to...Show more |
In onPackageModified of VoiceInteractionManagerService.java, there is a possible change of default applications due to an insecure default value. This could lead to local escalation of privilege with no additional execut...Show more |
Anuko Time Tracker is an open source, web-based time tracking application written in PHP. In TimeTracker before version 1.19.24.5415 tokens used in password reset feature in Time Tracker are based on system time and, the...Show more |
Weak JSON Web Token (JWT) signing secret generation in YMFE YApi through 1.9.2 allows recreation of other users' JWT tokens. This occurs because Math.random in Node.js is used. |
ownCloud Server 10.x before 10.3.1 allows an attacker, who has one outgoing share from a victim, to access any version of any file by sending a request for a predictable ID number. |
1Mofinetwork 1Mofi4500 4gxelte Firmware Jun 17, 2026 Feb 1, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. The one-time password algorithm for the undocumented system account mofidev generates a predictable six-digit password. |
1Sooil 3Anydana A Firmware Anydana I FirmwareDiabecare Rs FirmwareJun 17, 2026 Jan 19, 2021 N/A· v4 8.8 HIGH· v3 3.3 LOW· v2 In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, the communication protocol of the insulin pump and its AnyDana-i and AnyDana-A mobile applications use deterministic keys, which allows unauthenticate...Show more |
An issue was discovered in the nanorand crate before 0.5.1 for Rust. It caused any random number generator (even ChaCha) to return all zeroes because integer truncation was mishandled. |
An issue was discovered in FNET through 4.6.4. The code that initializes the DNS client interface structure does not set sufficiently random transaction IDs (they are always set to 1 in _fnet_dns_poll in fnet_dns.c). Thi...Show more |
Askey AP5100W devices through AP5100W_Dual_SIG_1.01.097 are affected by WPS PIN offline brute-force cracking. This arises because of issues with the random number selection for the Diffie-Hellman exchange. By capturing a...Show more |
1Schneider Electric 7Acti9 Powertag Link Firmware Acti9 Powertag Link Hd FirmwareActi9 Smartlink El B Firmware+4 moreJun 17, 2026 Dec 1, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A CWE-330 - Use of Insufficiently Random Values vulnerability exists in Smartlink, PowerTag, and Wiser Series Gateways (see security notification for version information) that could allow unauthorized users to login. |
An issue was discovered in Aviatrix Controller before R5.3.1151. An encrypted file containing credentials to unrelated systems is protected by a three-character key. |
1Basetech 1Ge 131 Bt 1837836 Firmware Jun 17, 2026 Nov 17, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A predictable device ID in BASETech GE-131 BT-1837836 firmware 20180921 allows unauthenticated remote attackers to connect to the device. |
2Linux Redhat2Enterprise Linux Linux KernelJun 17, 2026 Nov 17, 2020 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 A flaw in ICMP packets in the Linux kernel may allow an attacker to quickly scan open UDP ports. This flaw allows an off-path remote attacker to effectively bypass source port UDP randomization. Software that relies on U...Show more |
konzept-ix publiXone before 2020.015 allows attackers to download files by iterating over the IXCopy fileID parameter. |
1Pam Tacplus Project 1Pam Tacplus Jun 17, 2026 Oct 26, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 libtac in pam_tacplus through 1.5.1 lacks a check for a failure of RAND_bytes()/RAND_pseudo_bytes(). This could lead to use of a non-random/predictable session_id. |