CWE-330
380 CVEs • Abstraction: Class • Likelihood of Exploit: High
Use of Insufficiently Random Values
The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.
CVEs (380)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Highly predictable session tokens in the HTTPd server in all current versions (<= 3.0.0.4.380.7743) of Asus asuswrt allow gaining administrative router access. |
1Swhouse 1Istar Ultra Firmware May 13, 2026 Dec 31, 2017 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 A door-unlocking issue was discovered on Software House iStar Ultra devices through 6.5.2.20569 when used in conjunction with the IP-ACM Ethernet Door Module. The communications between the IP-ACM and the iStar Ultra is...Show more |
1Hoermann 3Hs5 868 Bs Firmware Hse1 868 Bs FirmwareHse2 868 Bs FirmwareMay 13, 2026 Dec 29, 2017 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 On Hoermann BiSecur devices before 2018, a vulnerability can be exploited by recording a single radio transmission. An attacker can intercept an arbitrary radio frame exchanged between a BiSecur transmitter and a receive...Show more |
wp-admin/user-new.php in WordPress before 4.9.1 sets the newbloguser key to a string that can be directly derived from the user ID, which allows remote attackers to bypass intended access restrictions by entering this st...Show more |
PWR-Q200 does not use random values for source ports of DNS query packets, which allows remote attackers to conduct DNS cache poisoning attacks. |
A vulnerability in Cisco Jabber for Windows could allow an unauthenticated, local attacker to access sensitive communications made by the Jabber client. An attacker could exploit this vulnerability to gain information to...Show more |
Python package pysaml2 version 4.4.0 and earlier reuses the initialization vector across encryptions in the IDP server, resulting in weak encryption of data. |
7Canonical DebianFreebsd+4 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Server+9 moreMay 13, 2026 Oct 17, 2017 N/A· v4 5.3 MEDIUM· v3 2.9 LOW· v2 Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Integrity Group Temporal Key (IGTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame, allowing an attac...Show more |
7Canonical DebianFreebsd+4 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Server+9 moreMay 13, 2026 Oct 17, 2017 N/A· v4 5.3 MEDIUM· v3 2.9 LOW· v2 Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Group Temporal Key (GTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame, allowing an attacker within...Show more |
7Canonical DebianFreebsd+4 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Server+9 moreMay 13, 2026 Oct 17, 2017 N/A· v4 6.8 MEDIUM· v3 5.4 MEDIUM· v2 Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Tunneled Direct-Link Setup (TDLS) Peer Key (TPK) during the TDLS handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames. |
7Canonical DebianFreebsd+4 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Server+9 moreMay 13, 2026 Oct 17, 2017 N/A· v4 6.8 MEDIUM· v3 5.4 MEDIUM· v2 Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Station-To-Station-Link (STSL) Transient Key (STK) during the PeerKey handshake, allowing an attacker within radio range to replay, decrypt, or spoof fra...Show more |
7Canonical DebianFreebsd+4 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Server+9 moreMay 13, 2026 Oct 17, 2017 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11r allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during the fast BSS transmission (FT) handshake, allowing an attacker within ra...Show more |
7Canonical DebianFreebsd+4 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Server+9 moreMay 13, 2026 Oct 17, 2017 N/A· v4 5.3 MEDIUM· v3 2.9 LOW· v2 Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the Integrity Group Temporal Key (IGTK) during the group key handshake, allowing an attacker within radio range to spoof frames fr...Show more |
7Canonical DebianFreebsd+4 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Server+9 moreMay 13, 2026 Oct 17, 2017 N/A· v4 5.3 MEDIUM· v3 2.9 LOW· v2 Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the group key handshake, allowing an attacker within radio range to replay frames from access points to clients. |
7Canonical DebianFreebsd+4 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Server+9 moreMay 13, 2026 Oct 17, 2017 N/A· v4 5.3 MEDIUM· v3 2.9 LOW· v2 Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the Integrity Group Temporal Key (IGTK) during the four-way handshake, allowing an attacker within radio range to spoof frames fro...Show more |
7Canonical DebianFreebsd+4 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Server+9 moreMay 13, 2026 Oct 17, 2017 N/A· v4 5.3 MEDIUM· v3 2.9 LOW· v2 Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the four-way handshake, allowing an attacker within radio range to replay frames from access points to clients. |
7Canonical DebianFreebsd+4 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Server+9 moreMay 13, 2026 Oct 17, 2017 N/A· v4 6.8 MEDIUM· v3 5.4 MEDIUM· v2 Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during the four-way handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames...Show more |
1Ge 10Multilin Sr 369 Motor Protection Relay Firmware Multilin Sr 469 Motor Protection Relay FirmwareMultilin Sr 489 Generator Protection Relay Firmware+7 moreMay 13, 2026 Jun 30, 2017 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 A Weak Cryptography for Passwords issue was discovered in General Electric (GE) Multilin SR 750 Feeder Protection Relay, firmware versions prior to Version 7.47; SR 760 Feeder Protection Relay, firmware versions prior to...Show more |
1Rockwellautomation 201763 L16awa Series A 1763 L16awa Series B1763 L16bbb Series A+17 moreMay 13, 2026 Jun 30, 2017 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 A "Reusing a Nonce, Key Pair in Encryption" issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-logic controllers 1763-L16AWA, Series A and B, Version 16.00 and prior versions; 1763-L16...Show more |
1Rockwellautomation 201763 L16awa Series A 1763 L16awa Series B1763 L16bbb Series A+17 moreMay 13, 2026 Jun 30, 2017 N/A· v4 8.6 HIGH· v3 9.0 HIGH· v2 A Predictable Value Range from Previous Values issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-logic controllers 1763-L16AWA, Series A and B, Version 16.00 and prior versions; 1763-...Show more |