← Back
CWE-330

380 CVEs • Abstraction: Class • Likelihood of Exploit: High

Use of Insufficiently Random Values

The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.

JSON object

Loading...

CVEs (380)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Linux
Redhat
2Enterprise Linux
Linux Kernel
Jun 17, 2026
Nov 17, 2020
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
A flaw in ICMP packets in the Linux kernel may allow an attacker to quickly scan open UDP ports. This flaw allows an off-path remote attacker to effectively bypass source port UDP randomization. Software that relies on U...Show more
A flaw in ICMP packets in the Linux kernel may allow an attacker to quickly scan open UDP ports. This flaw allows an off-path remote attacker to effectively bypass source port UDP randomization. Software that relies on UDP source port randomization are indirectly affected as well on the Linux Based Products (RUGGEDCOM RM1224: All versions between v5.0 and v6.4, SCALANCE M-800: All versions between v5.0 and v6.4, SCALANCE S615: All versions between v5.0 and v6.4, SCALANCE SC-600: All versions prior to v2.1.3, SCALANCE W1750D: v8.3.0.1, v8.6.0, and v8.7.0, SIMATIC Cloud Connect 7: All versions, SIMATIC MV500 Family: All versions, SIMATIC NET CP 1243-1 (incl. SIPLUS variants): Versions 3.1.39 and later, SIMATIC NET CP 1243-7 LTE EU: VersionShow less
1Konzept Ix
1Publixone
Jun 17, 2026
Oct 27, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
konzept-ix publiXone before 2020.015 allows attackers to download files by iterating over the IXCopy fileID parameter.
1Pam Tacplus Project
1Pam Tacplus
Jun 17, 2026
Oct 26, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
libtac in pam_tacplus through 1.5.1 lacks a check for a failure of RAND_bytes()/RAND_pseudo_bytes(). This could lead to use of a non-random/predictable session_id.
1Whatsapp
1Whatsapp
Jun 17, 2026
Oct 6, 2020
N/A· v4
3.3 LOW· v3
4.3 MEDIUM· v2
Media ContentProvider URIs used for opening attachments in other apps were generated sequentially prior to WhatsApp for Android v2.20.185, which could have allowed a malicious third party app chosen to open the file to g...Show more
Media ContentProvider URIs used for opening attachments in other apps were generated sequentially prior to WhatsApp for Android v2.20.185, which could have allowed a malicious third party app chosen to open the file to guess the URIs for previously opened attachments until the opener app is terminated.Show less
1Cpanel
1Cpanel
Jun 17, 2026
Sep 25, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
cPanel before 88.0.3, upon an upgrade, establishes predictable PowerDNS API keys (SEC-561).
1Google
1Android
Jun 17, 2026
Sep 17, 2020
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
In various functions in fscrypt_ice.c and related files in some implementations of f2fs encryption that use encryption hardware which only supports 32-bit IVs (Initialization Vectors), 64-bit IVs are used and later are t...Show more
In various functions in fscrypt_ice.c and related files in some implementations of f2fs encryption that use encryption hardware which only supports 32-bit IVs (Initialization Vectors), 64-bit IVs are used and later are truncated to 32 bits. This may cause IV reuse and thus weakened disk encryption. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-153450752References: N/AShow less
1Gitlab
1Gitlab
Jun 17, 2026
Sep 14, 2020
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Same 2 factor Authentication secret code was generated which resulted an attacker to maintain access under certain conditions.
1Kee
1Keepassrpc
Jun 17, 2026
Aug 3, 2020
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
The SRP-6a implementation in Kee Vault KeePassRPC before 1.12.0 generates insufficiently random numbers, which allows remote attackers to read and modify data in the KeePass database via a WebSocket connection.
7Canonical
DebianFedoraproject+4 more
15Active Iq Unified Manager
Cloud Volumes Ontap MediatorDebian Linux+12 more
Jun 17, 2026
Jul 30, 2020
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
The Linux kernel through 5.7.11 allows remote attackers to make observations that help to obtain sensitive information about the internal state of the network RNG, aka CID-f227e3ec3b5c. This is related to drivers/char/ra...Show more
The Linux kernel through 5.7.11 allows remote attackers to make observations that help to obtain sensitive information about the internal state of the network RNG, aka CID-f227e3ec3b5c. This is related to drivers/char/random.c and kernel/time/timer.c.Show less
3Easyrobotics
Mobile Industrial RobotsUvd Robots
10Er Flex Firmware
Er Lite FirmwareEr One Firmware+7 more
Jun 17, 2026
Jun 24, 2020
N/A· v4
7.1 HIGH· v3
5.5 MEDIUM· v2
The access tokens for the REST API are directly derived (sha256 and base64 encoding) from the publicly available default credentials from the Control Dashboard (refer to CVE-2020-10270 for related flaws). This flaw in co...Show more
The access tokens for the REST API are directly derived (sha256 and base64 encoding) from the publicly available default credentials from the Control Dashboard (refer to CVE-2020-10270 for related flaws). This flaw in combination with CVE-2020-10273 allows any attacker connected to the robot networks (wired or wireless) to exfiltrate all stored data (e.g. indoor mapping images) and associated metadata from the robot's database.Show less
1Ibm
1Security Guardium
Jun 17, 2026
Jun 23, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM Security Guardium 10.6 and 11.1 may use insufficiently random numbers or values in a security context that depends on unpredictable numbers. IBM X-Force ID: 174807.
1Convos
1Convos
Jun 17, 2026
Jun 18, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Convos before 4.20 does not properly generate a random secret in Core/Settings.pm and Util.pm. This leads to a predictable CONVOS_LOCAL_SECRET value, affecting password resets and invitations.
4Fedoraproject
OpensuseOracle+1 more
4Enterprise Manager Ops Center
FedoraLeap+1 more
Jun 17, 2026
Jun 18, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Lib/ipaddress.py in Python through 3.8.3 improperly computes hash values in the IPv4Interface and IPv6Interface classes, which might allow a remote attacker to cause a denial of service if an application is affected by t...Show more
Lib/ipaddress.py in Python through 3.8.3 improperly computes hash values in the IPv4Interface and IPv6Interface classes, which might allow a remote attacker to cause a denial of service if an application is affected by the performance of a dictionary containing IPv4Interface or IPv6Interface objects, and this attacker can cause many dictionary entries to be created. This is fixed in: v3.5.10, v3.5.10rc1; v3.6.12; v3.7.9; v3.8.4, v3.8.4rc1, v3.8.5, v3.8.6, v3.8.6rc1; v3.9.0, v3.9.0b4, v3.9.0b5, v3.9.0rc1, v3.9.0rc2.Show less
1Treck
1Tcp/ip
Jun 17, 2026
Jun 17, 2020
N/A· v4
9.0 CRITICAL· v3
9.3 HIGH· v2
The Treck TCP/IP stack before 6.0.1.66 allows Remote Code execution via a single invalid DNS response.
1Sos Berlin
1Jobscheduler
Jun 17, 2026
Jun 11, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability based on insecure user/password encryption in the JOE (job editor) component of SOS JobScheduler 1.12 and 1.13 allows attackers to decrypt the user/password that is optionally stored with a user's profile...Show more
A vulnerability based on insecure user/password encryption in the JOE (job editor) component of SOS JobScheduler 1.12 and 1.13 allows attackers to decrypt the user/password that is optionally stored with a user's profile.Show less
4Fujitsu
NetappNtp+1 more
25Cloud Backup
Clustered Data OntapData Ontap+22 more
Jun 17, 2026
Jun 4, 2020
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows remote attackers to cause a denial of service (daemon exit or system time change) by predicting transmit timestamps for use in spoofed packets. The victim must...Show more
ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows remote attackers to cause a denial of service (daemon exit or system time change) by predicting transmit timestamps for use in spoofed packets. The victim must be relying on unauthenticated IPv4 time sources. There must be an off-path attacker who can query time from the victim's ntpd instance.Show less
1Dell
1Emc Isilon Onefs
Jun 17, 2026
May 20, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Dell EMC Isilon versions 8.2.2 and earlier contain a remotesupport vulnerability. The pre-configured support account, remotesupport, is bundled in the Dell EMC Isilon OneFS installation. This account is used for diagnost...Show more
Dell EMC Isilon versions 8.2.2 and earlier contain a remotesupport vulnerability. The pre-configured support account, remotesupport, is bundled in the Dell EMC Isilon OneFS installation. This account is used for diagnostics and other support functions. Although the default password is different for every cluster, it is predictable.Show less
1Netgear
3Rbs50y Firmware
Srr60 FirmwareSrs60 Firmware
Jun 17, 2026
May 18, 2020
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
An issue was discovered on NETGEAR Orbi Tri-Band Business WiFi Add-on Satellite (SRS60) AC3000 V2.5.1.106, Outdoor Satellite (RBS50Y) V2.5.1.106, and Pro Tri-Band Business WiFi Router (SRR60) AC3000 V2.5.1.106. The admin...Show more
An issue was discovered on NETGEAR Orbi Tri-Band Business WiFi Add-on Satellite (SRS60) AC3000 V2.5.1.106, Outdoor Satellite (RBS50Y) V2.5.1.106, and Pro Tri-Band Business WiFi Router (SRR60) AC3000 V2.5.1.106. The administrative SOAP interface allows an unauthenticated remote write of arbitrary Wi-Fi configuration data such as authentication details (e.g., the Web-admin password), network settings, DNS settings, system administration interface configuration, etc.Show less
1Health
1Covidsafe
Jun 17, 2026
May 18, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Non-reinitialisation of random data in the advertising payload in COVIDSafe v1.0.15 and v1.0.16 allows a remote attacker to re-identify Android devices running COVIDSafe by scanning for their advertising beacons.
2Pivotal Software
Vmware
2Spring Security
Spring Security
Jun 17, 2026
May 14, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Spring Security versions 5.3.x prior to 5.3.2, 5.2.x prior to 5.2.4, 5.1.x prior to 5.1.10, 5.0.x prior to 5.0.16 and 4.2.x prior to 4.2.16 use a fixed null initialization vector with CBC Mode in the implementation of th...Show more
Spring Security versions 5.3.x prior to 5.3.2, 5.2.x prior to 5.2.4, 5.1.x prior to 5.1.10, 5.0.x prior to 5.0.16 and 4.2.x prior to 4.2.16 use a fixed null initialization vector with CBC Mode in the implementation of the queryable text encryptor. A malicious user with access to the data that has been encrypted using such an encryptor may be able to derive the unencrypted values using a dictionary attack.Show less