CWE-757
35 CVEs • Abstraction: Base
Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')
A protocol or its implementation supports interaction between multiple actors and allows those actors to negotiate which algorithm should be used as a protection mechanism such as encryption or authentication, but it does not select the strongest algorithm that is available to both parties.
CVEs (35)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Wapro ERP Desktop is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unencrypted communication vulnerable to data interception and modification. This issue affects Wapro ERP Desk...Show more |
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Drop Encryption Level attack due to the selection of a less-secure a...Show more |
In modem, there is a possible selection of less-secure algorithm during the VoWiFi IKE due to a missing DH downgrade check. This could lead to remote information disclosure with no additional execution privileges needed....Show more |
Dex is an identity service that uses OpenID Connect to drive authentication for other apps. Dex 2.37.0 serves HTTPS with insecure TLS 1.0 and TLS 1.1. `cmd/dex/serve.go` line 425 seemingly sets TLS 1.2 as minimum version...Show more |
IBM Security Directory Suite 8.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 228568. |
A vulnerability was found in quarkus-core. This vulnerability occurs because the TLS protocol configured with quarkus.http.ssl.protocols is not enforced, and the client can force the selection of the weaker supported TLS...Show more |
1Westerndigital 9My Cloud Dl2100 Firmware My Cloud Dl4100 FirmwareMy Cloud Ex2100 Firmware+6 moreJun 17, 2026 Jul 25, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 The Western Digital My Cloud Web App [https://os5.mycloud.com/] uses a weak SSLContext when attempting to configure port forwarding rules. This was enabled to maintain compatibility with old or outdated home routers. By...Show more |
1Silabs 5Zgm130s037hgn Firmware Zgm2305a27hgn FirmwareZgm230sb27hgn Firmware+2 moreNov 21, 2024 Feb 4, 2022 N/A· v4 8.1 HIGH· v3 4.8 MEDIUM· v2 The Z-Wave specification requires that S2 security can be downgraded to S0 or other less secure protocols, allowing an attacker within radio range during pairing to downgrade and then exploit a different vulnerability (C...Show more |
1Dell 1Emc Streaming Data Platform Jun 17, 2026 Nov 30, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Dell EMC Streaming Data Platform, versions prior to 1.3 contain an SSL Strip Vulnerability in the User Interface (UI). A remote unauthenticated attacker could potentially exploit this vulnerability, leading to a downgrad...Show more |
1Philips 1Clinical Collaboration Platform Jun 17, 2026 Sep 18, 2020 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 Philips Clinical Collaboration Platform, Versions 12.2.1 and prior, does not properly control the allocation and maintenance of a limited resource, thereby enabling an attacker to influence the amount of resources co...Show more |
2Bluetooth Opensuse2Bluetooth Core LeapJun 17, 2026 May 19, 2020 N/A· v4 5.4 MEDIUM· v3 4.8 MEDIUM· v2 Legacy pairing and secure-connections pairing authentication in Bluetooth BR/EDR Core Specification v5.2 and earlier may allow an unauthenticated user to complete authentication without pairing credentials via adjacent a...Show more |
1Redhat 6Jboss Data Grid Jboss Enterprise Application PlatformJboss Fuse+3 moreJun 17, 2026 Mar 16, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A flaw was found when an OpenSSL security provider is used with Wildfly, the 'enabled-protocols' value in the Wildfly configuration isn't honored. An attacker could target the traffic sent from Wildfly and downgrade the...Show more |
1Postfix Mta Sts Resolver Project 1Postfix Mta Sts Resolver Jun 17, 2026 Jan 22, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 In postfix-mta-sts-resolver before 0.5.1, All users can receive incorrect response from daemon under rare conditions, rendering downgrade of effective STS policy. |
In Novell eDirectory before 9.0.3.1 the LDAP interface was not strictly enforcing cipher restrictions allowing weaker ciphers to be used during SSL BIND operations. |
In libzypp before August 2018 GPG keys attached to YUM repositories were not correctly pinned, allowing malicious repository mirrors to silently downgrade to unsigned repositories with potential malicious content. |