CWE-320
74 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-320page 1 of 2
- CVE-2013-2233HIGHCVSS 7.4EG 7.42018-05-04
Ansible before 1.2.1 makes it easier for remote attackers to conduct man-in-the-middle attacks by leveraging failure to cache SSH host keys.
- CVE-2015-0153HIGHCVSS 7.5EG 7.52018-04-12
D-Link DIR-815 devices with firmware before 2.07.B01 allow remote attackers to obtain sensitive information by leveraging cleartext storage of the wireless key.
- CVE-2015-1316MEDIUMCVSS 6.4EG 7.52019-04-22
Juju Core's Joyent provider before version 1.25.5 uploads the user's private ssh key.
- CVE-2016-1000346LOWCVSS 3.7EG 3.72018-06-04
In the Bouncy Castle JCE Provider version 1.55 and earlier the other party DH public key is not fully validated. This can cause issues as invalid keys can be used to reveal details about the other party's private key where static Diffie-He…
- CVE-2016-10011MEDIUMCVSS 6.2EG 5.52017-01-05
authfile.c in sshd in OpenSSH before 7.4 does not properly consider the effects of realloc on buffer contents, which might allow local users to obtain sensitive private-key information by leveraging access to a privilege-separated child pr…
- CVE-2016-10421CRITICALCVSS 9.8EG 9.82018-04-18
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410…
- CVE-2016-10467CRITICALCVSS 9.8EG 9.82018-04-18
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 615/16/SD 415, SD 617, SD 650/52, SD 800, SD 808, SD 820, and SD 820A, functio…
- CVE-2016-7056MEDIUMCVSS 5.5EG 5.52018-09-10
A timing attack flaw was found in OpenSSL 1.0.1u and before that could allow a malicious user with local access to recover ECDSA P-256 private keys.
- CVE-2016-8614MEDIUMCVSS 6.3EG 6.32018-07-31
A flaw was found in Ansible before version 2.2.0. The apt_key module does not properly verify key fingerprints, allowing remote adversary to create an OpenPGP key which matches the short key ID and inject this key instead of the correct ke…
- CVE-2016-8635MEDIUMCVSS 5.3EG 5.92018-08-01
It was found that Diffie Hellman Client key exchange handling in NSS 3.21.x was vulnerable to small subgroup confinement attack. An attacker could use this flaw to recover private keys by confining the client DH key to small subgroup of th…
- CVE-2017-13887HIGHCVSS 7.5EG 7.52019-01-11
In macOS High Sierra before 10.13.2, a logic issue existed in APFS when deleting keys during hibernation. This was addressed with improved state management.
- CVE-2017-18319MEDIUMCVSS 5.5EG 5.52019-01-03
Information leak in UIM API debug messages in snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD …
- CVE-2017-18323MEDIUMCVSS 5.5EG 5.52019-01-03
Cryptographic key material leaked in TDSCDMA RRC debug messages in snapdragon automobile, snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MDM9615, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, MSM8996AU, SD 21…
- CVE-2017-2625MEDIUMCVSS 6.5EG 5.52018-07-27
It was discovered that libXdmcp before 1.1.2 including used weak entropy to generate session keys. On a multi-user system using xdmcp, a local attacker could potentially use information available from the process list to brute force the ke…
- CVE-2018-0124CRITICALCVSS 9.8EG 9.82018-02-22
A vulnerability in Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to bypass security protections, gain elevated privileges, and execute arbitrary code. The vulnerability is due to insecure key g…
- CVE-2018-0732HIGHCVSS 7.5EG 7.52018-06-12
During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server can send a very large prime value to the client. This will cause the client to spend an unreasonably long period of time generating a key for this p…
- CVE-2018-12433MEDIUMCVSS 4.9EG 4.92018-06-15
cryptlib through 3.4.4 allows a memory-cache side-channel attack on DSA and ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP. To discover a key, the attacker needs access to either the local machine or a different vir…
- CVE-2018-12438MEDIUMCVSS 4.9EG 4.92018-06-15
The Elliptic Curve Cryptography library (aka sunec or libsunec) allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access to eit…
- CVE-2018-15397MEDIUMCVSS 6.8EG 6.82018-10-05
A vulnerability in the implementation of Traffic Flow Confidentiality (TFC) over IPsec functionality in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remo…
- CVE-2018-20187MEDIUMCVSS 5.9EG 5.92019-03-08
A side-channel issue was discovered in Botan before 2.9.0. An attacker capable of precisely measuring the time taken for ECC key generation may be able to derive information about the high bits of the secret key, as the function to derive …
- CVE-2018-7534MEDIUMCVSS 4.7EG 4.72018-05-30
In Stealth Authorization Server before 3.3.017.0 in Unisys Stealth Solution, an encryption key may be left in memory.
- CVE-2018-7559MEDIUMCVSS 5.3EG 5.32018-06-13
An issue was discovered in OPC UA .NET Standard Stack and Sample Code before GitHub commit 2018-04-12, and OPC UA .NET Legacy Stack and Sample Code before GitHub commit 2018-03-13. A vulnerability in OPC UA applications can allow a remote …
- CVE-2018-9234HIGHCVSS 7.5EG 7.52018-04-04
GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently valid certifications that occurred only with access to a signing subkey.
- CVE-2019-12621HIGHCVSS 7.4EG 7.42019-08-21
A vulnerability in Cisco HyperFlex Software could allow an unauthenticated, remote attacker to perform a man-in-the-middle attack. The vulnerability is due to insufficient key management. An attacker could exploit this vulnerability by obt…
- CVE-2019-1586MEDIUMCVSS 4.6EG 4.62019-05-03
A vulnerability in Cisco Application Policy Infrastructure Controller (APIC) Software could allow an unauthenticated, local attacker with physical access to obtain sensitive information from an affected device. The vulnerability is due to …
- CVE-2019-5672CRITICALCVSS 9.1EG 9.12019-04-11
NVIDIA Jetson TX1 and TX2 contain a vulnerability in the Linux for Tegra (L4T) operating system (on all versions prior to R28.3) where the Secure Shell (SSH) keys provided in the sample rootfs are not replaced by unique host keys after sam…
- CVE-2019-9150MEDIUMCVSS 5.3EG 5.32019-07-09
Mailvelope prior to 3.3.0 does not require user interaction to import public keys shown on web page. This functionality can be tricked to either hide a key import from the user or obscure which key was imported.
- CVE-2019-9894HIGHCVSS 7.5EG 7.52019-03-21
A remotely triggerable memory overwrite in RSA key exchange in PuTTY before 0.71 can occur before host key verification.
- CVE-2020-1688MEDIUMCVSS 6.5EG 6.52020-10-16
On Juniper Networks SRX Series and NFX Series, a local authenticated user with access to the shell may obtain the Web API service private key that is used to provide encrypted communication between the Juniper device and the authenticator …
- CVE-2021-26322HIGHCVSS 7.5EG 7.52021-11-16
Persistent platform private key may not be protected with a random IV leading to a potential “two time pad attack”.
- CVE-2023-21626HIGHCVSS 7.1EG 7.12023-08-08
Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key.
- CVE-2023-21652HIGHCVSS 7.7EG 7.72023-08-08
Cryptographic issue in HLOS as derived keys used to encrypt/decrypt information is present on stack after use.
- CVE-2024-10920LOWCVSS 3.1EG 3.12024-11-06
A vulnerability was found in mariazevedo88 travels-java-api up to 5.0.1 and classified as problematic. Affected by this issue is the function doFilterInternal of the file travels-java-api-master\src\main\java\io\github\mariazevedo88\travel…
- CVE-2024-36391CRITICALCVSS 9.1EG 9.12024-06-02
MileSight DeviceHub - CWE-320: Key Management Errors may allow Authentication Bypass and Man-In-The-Middle Traffic
- CVE-2024-40593MEDIUMCVSS 6.0EG 6.02025-12-11
A key management errors vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.2, FortiAnalyzer 7.2.0 through 7.2.5, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiManager 7.4.0 through 7.4.2, FortiManager 7.2.0 th…
- CVE-2025-10080LOWCVSS 3.1EG 3.12025-09-08
A vulnerability has been found in running-elephant Datart up to 1.0.0-rc3. Affected by this issue is the function getTokensecret of the file datart/security/src/main/java/datart/security/util/AESUtil.java of the component API. The manipula…
- CVE-2025-10250MEDIUMCVSS 5.0EG 5.02025-09-11
A weakness has been identified in DJI Mavic Spark, Mavic Air and Mavic Mini 01.00.0500. Affected is an unknown function of the component Telemetry Channel. Executing manipulation can lead to use of hard-coded cryptographic key . The attac…
- CVE-2025-11290MEDIUMCVSS 5.6EG 5.62025-10-05
A vulnerability was identified in CRMEB up to 5.6.1. This affects an unknown function of the component JWT HMAC Secret Handler. Such manipulation of the argument secret with the input default leads to use of hard-coded cryptographic key .…
- CVE-2025-11609LOWCVSS 3.7EG 3.72025-10-11
A flaw has been found in code-projects Hospital Management System 1.0. Affected is the function session of the component express-session. This manipulation of the argument secret with the input secret causes use of hard-coded cryptographic…
- CVE-2025-12615MEDIUMCVSS 5.0EG 5.02025-11-03
A security vulnerability has been detected in PHPGurukul News Portal 1.0. The affected element is an unknown function of the file /onps/settings.py. Such manipulation of the argument SECRET_KEY leads to use of hard-coded cryptographic key …
- CVE-2025-13877MEDIUMCVSS 5.6EG 5.62025-12-02
A vulnerability was detected in nocobase up to 1.9.4/2.0.0-alpha.37. The affected element is an unknown function of the file nocobase\packages\core\auth\src\base\jwt-service.ts of the component JWT Service. The manipulation of the argument…
- CVE-2025-13948MEDIUMCVSS 5.6EG 5.62025-12-03
A vulnerability was determined in opsre go-ldap-admin up to 20251011. This issue affects some unknown processing of the file docs/docker-compose/docker-compose.yaml of the component JWT Handler. Executing manipulation of the argument secre…
- CVE-2025-14651LOWCVSS 3.7EG 3.72025-12-14
A vulnerability has been found in MartialBE one-hub up to 0.14.27. This vulnerability affects unknown code of the file docker-compose.yml. The manipulation of the argument SESSION_SECRET leads to use of hard-coded cryptographic key . The …
- CVE-2025-15005LOWCVSS 3.7EG 3.72025-12-22
A security flaw has been discovered in CouchCMS up to 2.4. Affected is an unknown function of the file couch/config.example.php of the component reCAPTCHA Handler. The manipulation of the argument K_RECAPTCHA_SITE_KEY/K_RECAPTCHA_SECRET_KE…
- CVE-2025-15105LOWCVSS 3.7EG 3.72025-12-27
A security flaw has been discovered in getmaxun maxun up to 0.0.28. Impacted is an unknown function of the file /getmaxun/maxun/blob/develop/server/src/routes/auth.ts. Performing manipulation of the argument api_key results in use of hard-…
- CVE-2025-15107LOWCVSS 3.7EG 3.72025-12-27
A security vulnerability has been detected in actiontech sqle up to 4.2511.0. The impacted element is an unknown function of the file sqle/utils/jwt.go of the component JWT Secret Handler. The manipulation of the argument JWTSecretKey lead…
- CVE-2025-15108LOWCVSS 3.7EG 3.72025-12-27
A vulnerability was detected in PandaXGO PandaX up to fb8ff40f7ce5dfebdf66306c6d85625061faf7e5. This affects an unknown function of the file config.yml of the component JWT Secret Handler. The manipulation of the argument key results in us…
- CVE-2025-2220LOWCVSS 3.3EG 3.32025-03-12
A vulnerability was found in Odyssey CMS up to 10.34. It has been classified as problematic. Affected is an unknown function of the file /modules/odyssey_contact_form/odyssey_contact_form.php of the component reCAPTCHA Handler. The manipul…
- CVE-2025-3177MEDIUMCVSS 5.0EG 5.02025-04-03
A vulnerability was found in FastCMS 0.1.5. It has been declared as critical. This vulnerability affects unknown code of the component JWT Handler. The manipulation leads to use of hard-coded cryptographic key . The attack can be initiate…
- CVE-2025-5164LOWCVSS 3.7EG 3.72025-05-26
A vulnerability has been found in PerfreeBlog 4.0.11 and classified as problematic. This vulnerability affects the function JwtUtil of the component JWT Handler. The manipulation leads to use of hard-coded cryptographic key . The attack c…
Map vulnerabilities like CWE-320 to your infrastructure
EchelonGraph correlates every CVE — across CWE-320 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →