CWE-330
380 CVEs • Abstraction: Class • Likelihood of Exploit: High
Use of Insufficiently Random Values
The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.
CVEs (380)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In random_get_bytes of random.c, there is a possible degradation of randomness due to an insecure default value. This could lead to local information disclosure via an insecure wireless connection with no additional exec...Show more |
1Codesys 15Control For Beaglebone Sl Control For Empc A/imx6 SlControl For Iot2000 Sl+12 moreNov 21, 2024 Feb 19, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Use of Insufficiently Random Values exists in CODESYS V3 products versions prior V3.5.14.0. |
The seadroid (aka Seafile Android Client) application through 2.2.13 for Android always uses the same Initialization Vector (IV) with Cipher Block Chaining (CBC) Mode to encrypt private data, making it easier to conduct...Show more |
The vMX Series software uses a predictable IP ID Sequence Number. This leaves the system as well as clients connecting through the device susceptible to a family of attacks which rely on the use of predictable IP ID sequ...Show more |
1Guardzilla 6180 Indoor Firmware 180 Outdoor Firmware360 Indoor Firmware+3 moreMay 6, 2025 Dec 31, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 The Cloud API on Guardzilla smart cameras allows user enumeration, with resultant arbitrary camera access and monitoring. |
The determineWinner function of a smart contract implementation for HashHeroes Tiles, an Ethereum game, uses a certain blockhash value in an attempt to generate a random number for the case where NUM_TILES equals the num...Show more |
Pivotal RabbitMQ for PCF, all versions, uses a deterministically generated cookie that is shared between all machines when configured in a multi-tenant cluster. A remote attacker who can gain information about the networ...Show more |
1Silabs 2Z Wave S0 Firmware Z Wave S2 FirmwareNov 21, 2024 Dec 9, 2018 N/A· v4 6.5 MEDIUM· v3 6.1 MEDIUM· v2 An issue was discovered on Sigma Design Z-Wave S0 through S2 devices. An attacker first prepares a Z-Wave frame-transmission program (e.g., Z-Wave PC Controller, OpenZWave, CC1110, etc.). Next, the attacker conducts a Do...Show more |
text/impl/DefaultTextCreator.java, text/impl/ChineseTextProducer.java, and text/impl/FiveLetterFirstNameTextCreator.java in kaptcha 2.3.2 use the Random (rather than SecureRandom) function for generating CAPTCHA values,...Show more |
goform/getProfileList in Orange AirBox Y858_FL_01.16_04 allows attackers to extract APN data (name, number, username, and password) via the rand parameter. |
NUUO CMS all versions 3.1 and prior, The application uses a session identification mechanism that could allow attackers to obtain the active session ID, which could allow arbitrary remote code execution. |
An issue was discovered in damiCMS V6.0.1. It relies on the PHP time() function for cookies, which makes it possible to determine the cookie for an existing admin session via 10800 guesses. |
POSIM EVO 15.13 for Windows includes an "Emergency Override" administrative account that may be accessed through POSIM's "override" feature. This Override prompt expects a code that is computed locally using a determinis...Show more |
1Synology 1Diskstation Manager Jan 14, 2025 Jul 30, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Use of insufficiently random values vulnerability in SYNO.Encryption.GenRandomKey in Synology DiskStation Manager (DSM) before 6.2-23739 allows man-in-the-middle attackers to compromise non-HTTPS sessions via unspecified...Show more |
1Pivotal Software 1Operations Manager Nov 21, 2024 Jul 11, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Pivotal Operations Manager, versions 2.1 prior to 2.1.6 and 2.0 prior to 2.0.15 and 1.12 prior to 1.12.22, contains a static Linux Random Number Generator (LRNG) seed file embedded in the appliance image. An attacker wit...Show more |
Socket.io is a realtime application framework that provides communication via websockets. Because socket.io 0.9.6 and earlier depends on `Math.random()` to create socket IDs, the IDs are predictable. An attacker is able...Show more |
1Randomatic Project 1Randomatic Nov 21, 2024 Jun 4, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 react-native-meteor-oauth is a library for Oauth2 login to a Meteor server in React Native. The oauth Random Token is generated using a non-cryptographically strong RNG (Math.random()). |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxNov 21, 2024 May 21, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 kernel drivers before version 4.17-rc1 are vulnerable to a weakness in the Linux kernel's implementation of random seed data. Programs, early in the boot sequence, could use the data allocated for the seed before it was...Show more |
Cloud Foundry Cloud Controller, versions prior to 1.52.0, contains information disclosure and path traversal vulnerabilities. An authenticated malicious user can predict the location of application blobs and leverage pat...Show more |
1Zohocorp 1Manageengine Desktop Central Nov 21, 2024 Feb 19, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Remote Information Disclosure and Escalation of Privileges in ManageEngine Desktop Central MSP 10.0.137 allows attackers to download unencrypted XML files containing all data for configuration policies via a predictable...Show more |