CWE-331
134 CVEs • Abstraction: Base
Insufficient Entropy
The product uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.
CVEs (134)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
totd 1.5.3 uses a fixed UDP source port in upstream queries sent to DNS resolvers. This allows DNS cache poisoning because there is not enough entropy to prevent traffic injection attacks. |
Apache OpenOffice supports the storage of passwords for web connections in the user's configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in OpenOffice existed...Show more |
websda.c in GoAhead WebServer 2.1.8 has insufficient nonce entropy because the nonce calculation relies on the hardcoded onceuponatimeinparadise value, which does not follow the secret-data guideline for HTTP Digest Acce...Show more |
2Dell Oracle6Bsafe Crypto C Micro Edition Bsafe Micro Edition SuiteDatabase+3 moreJun 17, 2026 Jul 11, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Improper Input Validation Vulnerability. |
2Dell Oracle3Bsafe Crypto C Micro Edition Bsafe Micro Edition SuiteRetail Customer InsightsJun 17, 2026 Jul 11, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain a Key Management Error Vulnerability. |
1Openvpn 1Openvpn Access Server Jun 17, 2026 Jul 6, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 OpenVPN Access Server before 2.11 uses a weak random generator used to create user session token for the web portal |
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting with v0.11.0 are vulnerable to a variety of attacks when an SSO login is initiated from the Argo CD CLI or UI. Th...Show more |
1Broadcom 1Ca Automic Automation Jun 17, 2026 Jun 16, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 CA Automic Automation 12.2 and 12.3 contain an entropy weakness vulnerability in the Automic AutomationEngine that could allow a remote attacker to potentially access sensitive data. |
1Schneider Electric 1Software Update Jun 17, 2026 Jan 28, 2022 N/A· v4 3.8 LOW· v3 2.1 LOW· v2 A CWE-331: Insufficient Entropy vulnerability exists that could cause unintended connection from an internal network to an external network when an attacker manages to decrypt the SESU proxy password from the registry. A...Show more |
1Dell 1Emc Unity Operating Environment Jun 17, 2026 Jan 25, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authentication bypass vulnerability. A remote unauthenticated attacker may exploit this vulnerability by forging a cookie to login as any user. |
1Thalesgroup 1Safenet Windows Logon Agent Jun 17, 2026 Dec 20, 2021 N/A· v4 6.5 MEDIUM· v3 3.5 LOW· v2 A user of a machine protected by SafeNet Agent for Windows Logon may leverage weak entropy to access the encrypted credentials of any or all the users on that machine. |
1Dell 9X1008 Firmware X1008p FirmwareX1018 Firmware+6 moreJun 17, 2026 Nov 20, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Dell Networking X-Series firmware versions prior to 3.0.1.8 contain an authentication bypass vulnerability. A remote unauthenticated attacker may potentially hijack a session and access the webserver by forging the sessi...Show more |
The effective key space used to encrypt the cache in CyberArk Credential Provider prior to 12.1 has low entropy, and under certain conditions a local malicious user can obtain the plaintext of cache files. |
The user identification mechanism used by CyberArk Credential Provider prior to 12.1 is susceptible to a local host race condition, leading to password disclosure. |
1Hcc Embedded 1Nichestack Tcp/ip Jun 17, 2026 Aug 18, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The DNS client in InterNiche NicheStack TCP/IP 4.0.1 is affected by: Insufficient entropy in the DNS transaction id. The impact is: DNS cache poisoning (remote). The component is: dns_query_type(). The attack vector is:...Show more |
1Schneider Electric 6Evlink City Evc1s22p4 Firmware Evlink City Evc1s7p4 FirmwareEvlink Parking Ev.2 Firmware+3 moreJun 17, 2026 Jul 21, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A CWE-331: Insufficient Entropy vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart Wallbo...Show more |
Sylabs Singularity Enterprise through 1.6.2 has Insufficient Entropy in a nonce. |
2Fedoraproject Matrix2Fedora SynapseJun 17, 2026 May 11, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.33.2 "Push rules" can specify co...Show more |
3Fedoraproject Libtpms ProjectRedhat3Enterprise Linux FedoraLibtpmsJun 17, 2026 Apr 19, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A flaw was found in libtpms in versions before 0.8.0. The TPM 2 implementation returns 2048 bit keys with ~1984 bit strength due to a bug in the TCG specification. The bug is in the key creation algorithm in RsaAdjustPri...Show more |
2Fedoraproject Rclone2Fedora RcloneJun 17, 2026 Nov 19, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Rclone before 1.53.3. Due to the use of a weak random number generator, the password generator has been producing weak passwords with much less entropy than advertised. The suggested passwords...Show more |