CWE-331
134 CVEs • Abstraction: Base
Insufficient Entropy
The product uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.
CVEs (134)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
SolarWinds Serv-U MFT before 15.1.6 HFv1 assigns authenticated users a low-entropy session token that can be included in requests to the application as a URL parameter in lieu of a session cookie. This session token's va...Show more |
1Unify 2Openscape Desk Phone Ip Sip Openstage SipNov 21, 2024 Apr 12, 2018 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 The web-based management (WBM) interface in Unify (former Siemens) OpenStage SIP and OpenScape Desk Phone IP V3 devices before R3.32.0 generates session cookies with insufficient entropy, which makes it easier for remote...Show more |
Cisco WebEx Meetings Server before 1.1 uses meeting IDs with insufficient entropy, which makes it easier for remote attackers to bypass authentication and join arbitrary meetings without a password, aka Bug ID CSCuc79643...Show more |
An Insufficient Entropy issue was discovered in LOYTEC LVIS-3ME versions prior to 6.2.0. The application does not utilize sufficiently random number generation for the web interface authentication mechanism, which could...Show more |
Lemur 0.1.4 does not use sufficient entropy in its IV when encrypting AES in CBC mode. |
7Debian FedoraprojectNtp+4 more13Debian Linux Enterprise Linux DesktopEnterprise Linux For Ibm Z Systems+10 moreMay 13, 2026 Aug 9, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ntp-keygen in ntp 4.2.8px before 4.2.8p2-RC2 and 4.3.x before 4.3.12 does not generate MD5 keys with sufficient entropy on big endian machines when the lowest order byte of the temp variable is between 0x20 and 0x7f and...Show more |
1Schneider Electric 3Modicon M221 Firmware Modicon M241 FirmwareModicon M251 FirmwareJun 4, 2026 Jun 30, 2017 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 A predictable value range from previous values issue was discovered in Schneider Electric Modicon PLCs Modicon M221, firmware versions prior to Version 1.5.0.0, Modicon M241, firmware versions prior to Version 4.0.5.11,...Show more |
1Expressionengine 1Expressionengine May 13, 2026 Jun 22, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ExpressionEngine version 2.x < 2.11.8 and version 3.x < 3.5.5 create an object signing token with weak entropy. Successfully guessing the token can lead to remote code execution. |
1Invisioncommunity 1Invision Power Board May 13, 2026 Apr 23, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Invision Power Services (IPS) Community Suite before 4.1.9 makes session hijack easier by relying on the PHP uniqid function without the more_entropy flag. Attackers can guess an Invision Power Board session cookie if th...Show more |
3Canonical DebianQemu3Debian Linux QemuUbuntu LinuxMay 6, 2026 Apr 7, 2016 N/A· v4 6.5 MEDIUM· v3 1.9 LOW· v2 QEMU, when built with the Pseudo Random Number Generator (PRNG) back-end support, allows local guest OS users to cause a denial of service (process crash) via an entropy request, which triggers arbitrary stack based allo...Show more |
Post Oak AWAM Bluetooth Reader Traffic System does not use a sufficient source of entropy for private keys, which makes it easier for man-in-the-middle attackers to spoof a device by predicting a key value. |
The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2; and other implementations allow remote att...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraPhp+1 moreApr 23, 2026 May 7, 2008 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The GENERATE_SEED macro in PHP 4.x before 4.4.8 and 5.x before 5.2.5, when running on 64-bit systems, performs a multiplication that generates a portion of zero bits during conversion due to insufficient precision, which...Show more |
1Valicert 1Enterprise Validation Authority Apr 16, 2026 Dec 4, 2001 N/A· v4 7.5 HIGH· v3 7.5 HIGH· v2 ValiCert Enterprise Validation Authority (EVA) Administration Server 3.3 through 4.2.1 uses insufficiently random data to (1) generate session tokens for HSMs using the C rand function, or (2) generate certificates or ke...Show more |