CWE-326— Inadequate Encryption Strength
496 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-326page 1 of 10
- CVE-2001-1546HIGHCVSS 7.8EG 7.82001-12-31
Pathways Homecare 6.5 uses weak encryption for user names and passwords, which allows local users to gain privileges by recovering the passwords from the pwhc.ini file.
- CVE-2002-1682MEDIUMCVSS 5.5EG 5.52002-12-31
NewsReactor 1.0 uses a weak encryption scheme, which could allow local users to decrypt the passwords and gain access to other users' newsgroup accounts.
- CVE-2002-1697HIGHCVSS 7.5EG 7.52002-12-31
Electronic Code Book (ECB) mode in VTun 2.0 through 2.5 uses a weak encryption algorithm that produces the same ciphertext from the same plaintext blocks, which could allow remote attackers to gain sensitive information.
- CVE-2002-1739MEDIUMCVSS 5.5EG 5.52002-12-31
Alt-N Technologies Mdaemon 5.0 through 5.0.6 uses a weak encryption algorithm to store user passwords, which allows local users to crack passwords.
- CVE-2002-1872HIGHCVSS 7.5EG 7.52002-12-31
Microsoft SQL Server 6.0 through 2000, with SQL Authentication enabled, uses weak password encryption (XOR), which allows remote attackers to sniff and decrypt the password.
- CVE-2002-1910HIGHCVSS 7.5EG 7.52002-12-31
Click2Learn Ingenium Learning Management System 5.1 and 6.1 uses weak encryption for passwords (reversible algorithm), which allows attackers to obtain passwords.
- CVE-2002-1946MEDIUMCVSS 5.5EG 5.52002-12-31
Videsh Sanchar Nigam Limited (VSNL) Integrated Dialer Software 1.2.000, when the "Save Password" option is used, stores the password with a weak encryption scheme (one-to-one mapping) in a registry key, which allows local users to obtain a…
- CVE-2002-1975MEDIUMCVSS 5.5EG 5.52002-12-31
Sharp Zaurus PDA SL-5000D and SL-5500 uses a salt of "A0" to encrypt the screen-locking password as stored in the Security.conf file, which makes it easier for local users to guess the password via brute force methods.
- CVE-2004-2172HIGHCVSS 7.5EG 7.52004-12-31
EarlyImpact ProductCart uses a weak encryption scheme to encrypt passwords, which allows remote attackers to obtain the password via a chosen plaintext attack.
- CVE-2005-0366NONECVSS 0.0EG 0.02005-05-02
The integrity check feature in OpenPGP, when handling a message that was encrypted using cipher feedback (CFB) mode, allows remote attackers to recover part of the plaintext via a chosen-ciphertext attack when the first 2 bytes of a messag…
- CVE-2005-2281HIGHCVSS 7.5EG 7.52005-07-18
WebEOC before 6.0.2 uses a weak encryption scheme for passwords, which makes it easier for attackers to crack passwords.
- CVE-2005-4900MEDIUMCVSS 5.9EG 5.92016-10-14
SHA-1 is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of SHA-1 in TLS 1.2. NOTE: this CVE exists to provide a common identifier for refer…
- CVE-2008-3188HIGHCVSS 7.5EG 7.52008-07-22
libxcrypt in SUSE openSUSE 11.0 uses the DES algorithm when the configuration specifies the MD5 algorithm, which makes it easier for attackers to conduct brute-force attacks against hashed passwords.
- CVE-2009-2474NONECVSS 0.0EG 0.02009-08-21
neon before 0.28.6, when OpenSSL or GnuTLS is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL…
- CVE-2010-3670MEDIUMCVSS 4.8EG 4.82019-11-05
TYPO3 before 4.3.4 and 4.4.x before 4.4.1 contains insecure randomness during generation of a hash with the "forgot password" function.
- CVE-2011-3389NONECVSS 0.0EG 0.02011-09-06
The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which…
- CVE-2011-3629HIGHCVSS 7.5EG 7.52020-02-04
Joomla! core 1.7.1 allows information disclosure due to weak encryption
- CVE-2011-4121CRITICALCVSS 9.8EG 9.82019-11-26
The OpenSSL extension of Ruby (Git trunk) versions after 2011-09-01 up to 2011-11-03 always generated an exponent value of '1' to be used for private RSA key generation. A remote attacker could use this flaw to bypass or corrupt integrity …
- CVE-2012-2130HIGHCVSS 7.4EG 7.42019-12-06
A Security Bypass vulnerability exists in PolarSSL 0.99pre4 through 1.1.1 due to a weak encryption error when generating Diffie-Hellman values and RSA keys.
- CVE-2013-0764NONECVSS 0.0EG 0.02013-01-13
The nsSOCKSSocketInfo::ConnectToProxy function in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 17.x before 17.0.2, and SeaMonkey before 2.15 does not ensure thread safety for SSL s…
- CVE-2013-2166CRITICALCVSS 9.8EG 9.82019-12-10
python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass
- CVE-2013-2566MEDIUMCVSS 5.9EG 9.02013-03-15
The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct plaintext-recovery attacks via statistical analysis of ciphertext in a large number of sess…
- CVE-2013-4104HIGHCVSS 7.5EG 7.52019-11-04
Cryptocat before 2.0.22 has weak encryption in the Socialist Millionnaire Protocol
- CVE-2013-4508HIGHCVSS 7.5EG 7.52013-11-08
lighttpd before 1.4.34, when SNI is enabled, configures weak SSL ciphers, which makes it easier for remote attackers to hijack sessions by inserting packets into the client-server data stream or obtain sensitive information by sniffing the…
- CVE-2013-7286HIGHCVSS 7.5EG 7.52020-02-12
MobileIron VSP < 5.9.1 and Sentry < 5.0 has a weak password obfuscation algorithm
- CVE-2013-7287CRITICALCVSS 9.8EG 9.82020-02-13
MobileIron VSP < 5.9.1 and Sentry < 5.0 has an insecure encryption scheme.
- CVE-2013-7469HIGHCVSS 7.5EG 7.52019-02-21
Seafile through 6.2.11 always uses the same Initialization Vector (IV) with Cipher Block Chaining (CBC) Mode to encrypt private data, making it easier to conduct chosen-plaintext attacks or dictionary attacks.
- CVE-2013-7484HIGHCVSS 7.5EG 7.52019-11-30
Zabbix before 5.0 represents passwords in the users table with unsalted MD5.
- CVE-2014-0224HIGHCVSS 7.4EG 9.02014-06-05
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL…
- CVE-2014-0841MEDIUMCVSS 5.3EG 5.32018-04-27
IBM Rational Focal Point 6.4.0, 6.4.1, 6.5.1, 6.5.2, and 6.6.0 use a weak algorithm to hash passwords, which makes it easier for context-dependent attackers to obtain cleartext values via a brute-force attack. IBM X-Force ID: 90704.
- CVE-2014-1491NONECVSS 0.0EG 0.02014-02-06
Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, does not properly restrict public values in Di…
- CVE-2014-2380NONECVSS 0.0EG 0.02014-08-28
Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 uses weak encryption, which allows remote attackers to obtain sensitive information by reading a credential file.
- CVE-2014-2381NONECVSS 0.0EG 0.02014-08-28
Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 uses weak encryption, which allows local users to obtain sensitive information by reading a credential file.
- CVE-2014-9199NONECVSS 0.0EG 0.02015-01-17
The Clorius Controls Java web client before 01.00.0009g allows remote attackers to discover credentials by sniffing the network for cleartext-equivalent traffic.
- CVE-2015-4953MEDIUMCVSS 4.8EG 4.82018-03-29
IBM BigFix Remote Control before Interim Fix pack 9.1.2-TIV-IBRC912-IF0001 makes it easier for man-in-the-middle attackers to decrypt traffic by leveraging a weakness in its encryption protocol. IBM X-Force ID: 105197.
- CVE-2015-5361MEDIUMCVSS 6.5EG 6.52020-02-28
Background For regular, unencrypted FTP traffic, the FTP ALG can inspect the unencrypted control channel and open related sessions for the FTP data channel. These related sessions (gates) are specific to source and destination IPs and port…
- CVE-2015-7449LOWCVSS 3.3EG 3.32018-03-20
IBM Rational Collaborative Lifecycle Management (CLM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, 6.0.x before 6.0.1 iFix5, and 6.0.2 before iFix2; Rational Quality Manager (RQM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix…
- CVE-2016-11043HIGHCVSS 7.5EG 7.52020-04-07
An issue was discovered on Samsung mobile devices with M(6.0) software. The S/MIME implementation in EAS uses DES (where 3DES is intended). The Samsung ID is SVE-2016-5871 (June 2016).
- CVE-2017-1000486CRITICALCVSS 9.8EG 9.8⚠ KEV2018-01-03
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
- CVE-2017-11317CRITICALCVSS 9.8EG 9.8⚠ KEV2017-08-23
Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload encryption, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.
- CVE-2017-1255HIGHCVSS 7.5EG 7.52018-05-02
IBM Security Guardium 10.0, 10.0.1, and 10.1 through 10.1.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 124675.
- CVE-2017-1366MEDIUMCVSS 5.9EG 7.52018-08-06
IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 126859.
- CVE-2017-1473HIGHCVSS 7.5EG 7.52018-04-23
IBM Security Access Manager Appliance 8.0.0 through 8.0.1.6 and 9.0.0 through 9.0.3.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 128605.
- CVE-2017-16632HIGHCVSS 7.5EG 7.52021-08-11
In SapphireIMS 4097_1, the password in the database is stored in Base64 format.
- CVE-2017-1664MEDIUMCVSS 5.9EG 5.92018-01-04
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 133557.
- CVE-2017-1665MEDIUMCVSS 5.9EG 5.92018-01-04
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 133559.
- CVE-2017-16726CRITICALCVSS 9.1EG 9.12018-06-27
Beckhoff TwinCAT supports communication over ADS. ADS is a protocol for industrial automation in protected environments. ADS has not been designed to achieve security purposes and therefore does not include any encryption algorithms becaus…
- CVE-2017-1695MEDIUMCVSS 5.9EG 7.52019-02-15
IBM QRadar SIEM 7.2 and 7.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 134177.
- CVE-2017-1701HIGHCVSS 8.8EG 8.82018-04-23
IBM Team Concert (RTC) 5.0, 5.0.1, 5.0.2, 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, and 6.0.5 stores credentials for users using a weak encryption algorithm, which could allow an authenticated user to obtain highly sensitive information. IBM X-Forc…
- CVE-2017-1712MEDIUMCVSS 5.9EG 5.92020-07-01
"A vulnerability in the TLS protocol implementation of the Domino server could allow an unauthenticated, remote attacker to access sensitive information, aka a Return of Bleichenbacher's Oracle Threat (ROBOT) attack. An attacker could iter…
Map vulnerabilities like CWE-326 to your infrastructure
EchelonGraph correlates every CVE — across CWE-326 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →