CWE-331
144 CVEs • Abstraction: Base
Insufficient Entropy
The product uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.
CVEs (144)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The CMS Commander plugin for WordPress is vulnerable to authorization bypass due to the use of an insufficiently unique cryptographic signature on the 'cmsc_add_site' function in versions up to, and including, 2.287. Thi...Show more |
The crypto-js package before 3.2.1 for Node.js generates random numbers by concatenating the string "0." with an integer, which makes the output more predictable than necessary. |
1Cisco 3Adaptive Security Appliance Firepower Threat DefenseSecure Firewall Threat DefenseAug 11, 2026 Mar 23, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A vulnerability in the deterministic random bit generator (DRBG), also known as pseudorandom number generator (PRNG), in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software...Show more |
A Insufficient Entropy vulnerability in SUSE Rancher allows attackers that gained knowledge of the cattle-token to continue abusing this even after the token was renewed. This issue affects: SUSE Rancher Rancher versions...Show more |
Randomly-generated alphanumeric strings contain significantly less entropy than expected. The RandomAlphaNumeric and CryptoRandomAlphaNumeric functions always return strings containing at least one digit from 0 to 9. Thi...Show more |
1Phpservermonitor 1Php Server Monitor Jun 17, 2026 Nov 15, 2022 N/A· v4 5.3 MEDIUM· v3 N/A· v2 A vulnerability, which was classified as problematic, was found in phpservermon. Affected is the function setUserLoggedIn of the file src/psm/Service/User.php. The manipulation leads to use of predictable algorithm in ra...Show more |
1Phpservermonitor 1Php Server Monitor Jun 17, 2026 Nov 15, 2022 N/A· v4 5.3 MEDIUM· v3 N/A· v2 A vulnerability, which was classified as problematic, was found in phpservermon. This affects the function generatePasswordResetToken of the file src/psm/Service/User.php. The manipulation leads to use of predictable alg...Show more |
1Cisco 1Secure Firewall Management Center Jun 17, 2026 Nov 15, 2022 N/A· v4 5.3 MEDIUM· v3 N/A· v2 A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to access sensitive information. This vulnerability is due to m...Show more |
1Zyxel 10Gs1900 10hp Firmware Gs1900 16 FirmwareGs1900 24 Firmware+7 moreJun 17, 2026 Sep 20, 2022 N/A· v4 5.9 MEDIUM· v3 N/A· v2 An insufficient entropy vulnerability caused by the improper use of randomness sources with low entropy for RSA key pair generation was found in Zyxel GS1900 series firmware versions prior to V2.70. This vulnerability co...Show more |
1Dproxy Nexgen Project 1Dproxy Nexgen Jun 17, 2026 Aug 15, 2022 N/A· v4 5.3 MEDIUM· v3 N/A· v2 dproxy-nexgen (aka dproxy nexgen) uses a static UDP source port (selected randomly only at boot time) in upstream queries sent to DNS resolvers. This allows DNS cache poisoning because there is not enough entropy to prev...Show more |
totd 1.5.3 uses a fixed UDP source port in upstream queries sent to DNS resolvers. This allows DNS cache poisoning because there is not enough entropy to prevent traffic injection attacks. |
Apache OpenOffice supports the storage of passwords for web connections in the user's configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in OpenOffice existed...Show more |
websda.c in GoAhead WebServer 2.1.8 has insufficient nonce entropy because the nonce calculation relies on the hardcoded onceuponatimeinparadise value, which does not follow the secret-data guideline for HTTP Digest Acce...Show more |
2Dell Oracle6Bsafe Crypto C Micro Edition Bsafe Micro Edition SuiteDatabase+3 moreJun 17, 2026 Jul 11, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Improper Input Validation Vulnerability. |
2Dell Oracle3Bsafe Crypto C Micro Edition Bsafe Micro Edition SuiteRetail Customer InsightsJun 17, 2026 Jul 11, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain a Key Management Error Vulnerability. |
1Openvpn 1Openvpn Access Server Jun 17, 2026 Jul 6, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 OpenVPN Access Server before 2.11 uses a weak random generator used to create user session token for the web portal |
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting with v0.11.0 are vulnerable to a variety of attacks when an SSO login is initiated from the Argo CD CLI or UI. Th...Show more |
1Broadcom 1Ca Automic Automation Jun 17, 2026 Jun 16, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 CA Automic Automation 12.2 and 12.3 contain an entropy weakness vulnerability in the Automic AutomationEngine that could allow a remote attacker to potentially access sensitive data. |
1Schneider Electric 1Software Update Jun 17, 2026 Jan 28, 2022 N/A· v4 3.8 LOW· v3 2.1 LOW· v2 A CWE-331: Insufficient Entropy vulnerability exists that could cause unintended connection from an internal network to an external network when an attacker manages to decrypt the SESU proxy password from the registry. A...Show more |
1Dell 1Emc Unity Operating Environment Jun 17, 2026 Jan 25, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authentication bypass vulnerability. A remote unauthenticated attacker may exploit this vulnerability by forging a cookie to login as any user. |