CWE-326— Inadequate Encryption Strength
497 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-326page 3 of 10
- CVE-2019-10907CRITICALCVSS 9.8EG 9.82019-04-07
Airsonic 10.2.1 uses Spring's default remember-me mechanism based on MD5, with a fixed key of airsonic in GlobalSecurityConfig.java. An attacker able to capture cookies might be able to trivially bruteforce offline the passwords of associa…
- CVE-2019-12121HIGHCVSS 7.5EG 7.52020-03-18
An issue was detected in ONAP Portal through Dublin. By executing a padding oracle attack using the ONAPPORTAL/processSingleSignOn UserId field, an attacker is able to decrypt arbitrary information encrypted with the same symmetric key as …
- CVE-2019-13163MEDIUMCVSS 5.9EG 5.92020-02-07
The Fujitsu TLS library allows a man-in-the-middle attack. This affects Interstage Application Development Cycle Manager V10 and other versions, Interstage Application Server V12 and other versions, Interstage Business Application Manager …
- CVE-2019-1338MEDIUMCVSS 5.9EG 5.92019-10-10
A security feature bypass vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully bypass the NTLMv2 protection if a client is also sending LMv2 responses, aka 'Windows NTLM Security Feature Bypas…
- CVE-2019-13539HIGHCVSS 7.0EG 7.82019-11-08
Medtronic Valleylab Exchange Client version 3.4 and below, Valleylab FT10 Energy Platform (VLFT10GEN) software version 4.0.0 and below, and Valleylab FX8 Energy Platform (VLFX8GEN) software version 1.1.0 and below use the descrypt algorith…
- CVE-2019-14332HIGHCVSS 7.8EG 7.82019-08-01
An issue was discovered on D-Link 6600-AP and DWL-3600AP Ax 4.2.0.14 21/03/2019 devices. There is use of weak ciphers for SSH such as diffie-hellman-group1-sha1.
- CVE-2019-14664MEDIUMCVSS 6.5EG 6.52019-08-05
In Enigmail below 2.1, an attacker in possession of PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This modified mul…
- CVE-2019-14855HIGHCVSS 7.5EG 7.52020-03-20
A flaw was found in the way certificate signatures could be forged using collisions found in the SHA-1 algorithm. An attacker could use this weakness to create forged certificate signatures. This issue affects GnuPG versions before 2.2.18.
- CVE-2019-14887CRITICALCVSS 9.1EG 9.12020-03-16
A flaw was found when an OpenSSL security provider is used with Wildfly, the 'enabled-protocols' value in the Wildfly configuration isn't honored. An attacker could target the traffic sent from Wildfly and downgrade the connection to a wea…
- CVE-2019-15805CRITICALCVSS 9.8EG 9.82019-08-29
CommScope ARRIS TR4400 devices with firmware through A1.00.004-180301 are vulnerable to an authentication bypass to the administrative interface because they include the current base64 encoded password within http://192.168.1.1/login.html.…
- CVE-2019-15806CRITICALCVSS 9.8EG 9.82019-08-29
CommScope ARRIS TR4400 devices with firmware through A1.00.004-180301 are vulnerable to an authentication bypass to the administrative interface because they include the current base64 encoded password within http://192.168.1.1/basic_sett.…
- CVE-2019-15947HIGHCVSS 7.5EG 7.52019-09-05
In Bitcoin Core 0.18.0, bitcoin-qt stores wallet.dat data unencrypted in memory. Upon a crash, it may dump a core file. If a user were to mishandle a core file, an attacker can reconstruct the user's wallet.dat file, including their privat…
- CVE-2019-16649CRITICALCVSS 10.0EG 10.02019-09-21
On Supermicro H11, H12, M11, X9, X10, and X11 products, a combination of encryption and authentication problems in the virtual media service allows capture of BMC credentials and data transferred over virtual media devices. Attackers can u…
- CVE-2019-17356MEDIUMCVSS 6.5EG 6.52019-10-15
The Infinite Design application 3.4.12 for Android sends a username and password via TCP without any encryption during login, as demonstrated by sniffing of a public Wi-Fi network.
- CVE-2019-17428MEDIUMCVSS 5.9EG 5.92019-12-12
An issue was discovered in Intesync Solismed 3.3sp1. An flaw in the encryption implementation exists, allowing for all encrypted data stored within the database to be decrypted.
- CVE-2019-17598HIGHCVSS 7.5EG 7.52019-11-05
An issue was discovered in Lightbend Play Framework 2.5.x through 2.6.23. When configured to make requests using an authenticated HTTP proxy, play-ws may sometimes, typically under high load, when connecting to a target host using https, e…
- CVE-2019-18241MEDIUMCVSS 6.5EG 6.52019-11-26
In Philips IntelliBridge EC40 and EC80, IntelliBridge EC40 Hub all versions, and IntelliBridge EC80 Hub all versions, the SSH server running on the affected products is configured to allow weak ciphers. This could enable an unauthorized at…
- CVE-2019-18263MEDIUMCVSS 6.5EG 6.52019-12-20
An issue was found in Philips Veradius Unity, Pulsera, and Endura Dual WAN Router, Veradius Unity (718132) with wireless option (shipped between 2016-August 2018), Veradius Unity (718132) with ViewForum option (shipped between 2016-August …
- CVE-2019-18630HIGHCVSS 7.5EG 7.52021-03-04
On Xerox AltaLink B8045/B8055/B8065/B8075/B8090 and C8030/C8035/C8045/C8055/C8070 multifunction printers with software releases before 101.00x.099.28200, portions of the drive containing executable code were not encrypted thus leaving it o…
- CVE-2019-18863MEDIUMCVSS 5.9EG 5.92020-03-02
A key length vulnerability in the implementation of the SRTP 128-bit key on Mitel 6800 and 6900 SIP series phones, versions 5.1.0.2051 SP2 and earlier, could allow an attacker to launch a man-in-the-middle attack when SRTP is used in a cal…
- CVE-2019-19097MEDIUMCVSS 5.9EG 7.52020-04-02
ABB eSOMS versions 4.0 to 6.0.3 accept connections using medium strength ciphers. If a connection is enabled using such a cipher, an attacker might be able to eavesdrop and/or intercept the connection.
- CVE-2019-19101MEDIUMCVSS 6.5EG 5.92020-04-29
A missing secure communication definition and an incomplete TLS validation in the upgrade service in B&R Automation Studio versions 4.0.x, 4.1.x, 4.2.x, < 4.3.11SP, < 4.4.9SP, < 4.5.5SP, < 4.6.4 and < 4.7.2 enable unauthenticated users to …
- CVE-2019-19299HIGHCVSS 7.5EG 7.52020-03-10
A vulnerability has been identified in SiNVR/SiVMS Video Server (All versions < V5.0.0), SiNVR/SiVMS Video Server (All versions >= V5.0.0 < V5.0.2), SiNVR/SiVMS Video Server (All versions >= V5.0.2). The streaming service (default port 541…
- CVE-2019-19766HIGHCVSS 7.5EG 7.52019-12-12
The Bitwarden server through 1.32.0 has a potentially unwanted KDF.
- CVE-2019-19891MEDIUMCVSS 5.9EG 5.92020-01-13
An encryption key vulnerability on Mitel SIP-DECT wireless devices 8.0 and 8.1 could allow an attacker to launch a man-in-the-middle attack. A successful exploit may allow the attacker to intercept sensitive information.
- CVE-2019-20138HIGHCVSS 7.5EG 7.52019-12-30
The HTTP Authentication library before 2019-12-27 for Nim has weak password hashing because the default algorithm for libsodium's crypto_pwhash_str is not used.
- CVE-2019-20775MEDIUMCVSS 5.5EG 5.52020-04-17
An issue was discovered on LG mobile devices with Android OS 9.0 (Qualcomm SDM450, SDM845, SM6150, and SM8150 chipsets) software. Weak encryption leads to local information disclosure. The LG ID is LVE-SMP-190010 (August 2019).
- CVE-2019-4102MEDIUMCVSS 5.9EG 5.92019-07-01
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 158092.
- CVE-2019-4151MEDIUMCVSS 5.9EG 5.92019-06-25
IBM Security Access Manager 9.0.1 through 9.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 158512.
- CVE-2019-4160HIGHCVSS 7.5EG 7.52021-01-13
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 158577.
- CVE-2019-4175HIGHCVSS 7.5EG 7.52019-09-17
IBM Cognos Controller 10.3.0, 10.3.1, 10.4.0, and 10.4.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 158880.
- CVE-2019-4256HIGHCVSS 7.5EG 7.52019-05-29
IBM API Connect 5.0.0.0 through 5.0.8.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 159944.
- CVE-2019-4291MEDIUMCVSS 6.5EG 6.52022-02-16
IBM Maximo Anywhere 7.6.4.0 could allow an attacker to reverse engineer the application due to the lack of binary protection precautions. IBM X-Force ID: 160697.
- CVE-2019-4339HIGHCVSS 7.5EG 7.52019-10-29
IBM Security Guardium Big Data Intelligence (SonarG) 4.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 161418.
- CVE-2019-4557HIGHCVSS 7.5EG 7.52020-02-25
IBM Qradar Advisor 1.1 through 2.5 with Watson uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 166206.
- CVE-2019-6972HIGHCVSS 7.5EG 7.52019-06-19
An issue was discovered on TP-Link TL-WR1043ND V2 devices. The credentials can be easily decoded and cracked by brute-force, WordList, or Rainbow Table attacks. Specifically, credentials in the "Authorization" cookie are encoded with URL e…
- CVE-2019-7648HIGHCVSS 7.5EG 7.52019-02-08
controller/fetchpwd.php and controller/doAction.php in Hotels_Server through 2018-11-05 rely on base64 in an attempt to protect password storage.
- CVE-2019-8237CRITICALCVSS 9.8EG 9.82019-10-23
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an insufficiently robust encr…
- CVE-2019-8772HIGHCVSS 7.5EG 7.52019-12-18
An issue existed in the handling of links in encrypted PDFs. This issue was addressed by adding a confirmation prompt. This issue is fixed in macOS Catalina 10.15. An attacker may be able to exfiltrate the contents of an encrypted PDF.
- CVE-2019-9399MEDIUMCVSS 5.9EG 5.92019-09-27
The Print Service is susceptible to man in the middle attacks due to improperly used crypto. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. …
- CVE-2020-0407MEDIUMCVSS 4.4EG 4.42020-09-17
In various functions in fscrypt_ice.c and related files in some implementations of f2fs encryption that use encryption hardware which only supports 32-bit IVs (Initialization Vectors), 64-bit IVs are used and later are truncated to 32 bits…
- CVE-2020-0533MEDIUMCVSS 6.7EG 6.72020-06-15
Reversible one-way hash in Intel(R) CSME versions before 11.8.76, 11.12.77 and 11.22.77 may allow a privileged user to potentially enable escalation of privilege, denial of service or information disclosure via local access.
- CVE-2020-10125HIGHCVSS 7.6EG 7.62020-08-21
NCR SelfServ ATMs running APTRA XFS 04.02.01 and 05.01.00 implement 512-bit RSA certificates to validate bunch note acceptor (BNA) software updates, which can be broken by an attacker with physical access in a sufficiently short period of …
- CVE-2020-10244HIGHCVSS 7.5EG 7.52020-03-09
JPaseto before 0.3.0 generates weak hashes when using v2.local tokens.
- CVE-2020-10275CRITICALCVSS 9.8EG 9.82020-06-24
The access tokens for the REST API are directly derived from the publicly available default credentials for the web interface. Given a USERNAME and a PASSWORD, the token string is generated directly with base64(USERNAME:sha256(PASSWORD)). …
- CVE-2020-10375MEDIUMCVSS 5.5EG 5.52021-02-05
An issue was discovered in New Media Smarty before 9.10. Passwords are stored in the database in an obfuscated format that can be easily reversed. The file data.mdb contains these obfuscated passwords in the second column. NOTE: this is un…
- CVE-2020-10377CRITICALCVSS 9.8EG 9.82020-04-17
A weak encryption vulnerability in Mitel MiVoice Connect Client before 214.100.1214.0 could allow an unauthenticated attacker to gain access to user credentials. A successful exploit could allow an attacker to access the system with compro…
- CVE-2020-10554HIGHCVSS 7.5EG 7.52021-02-05
An issue was discovered in Psyprax beforee 3.2.2. Passwords used to encrypt the data are stored in the database in an obfuscated format, which can be easily reverted. For example, the password AAAAAAAA is stored in the database as MMMMMMMM.
- CVE-2020-10601HIGHCVSS 7.8EG 7.82020-04-03
VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module allow weak hashing algorithm and insecure permissions which may allow a local attacker to bypass the password-protected mechanism through brute-force attacks, cracking techniq…
- CVE-2020-10636MEDIUMCVSS 6.5EG 6.52022-02-24
Inadequate encryption may allow the passwords for Emerson OpenEnterprise versions through 3.3.4 user accounts to be obtained.
Map vulnerabilities like CWE-326 to your infrastructure
EchelonGraph correlates every CVE — across CWE-326 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →