CWE-327— Use of a Broken or Risky Cryptographic Algorithm
653 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-327page 1 of 14
- CVE-1999-0007NONECVSS 0.0EG 0.01998-06-26
Information from SSL-encrypted sessions via PKCS #1.
- CVE-2002-2058HIGHCVSS 7.5EG 7.52002-12-31
TeeKai Tracking Online 1.0 uses weak encryption of web usage statistics in data/userlog/log.txt, which allows remote attackers to identify IP's visiting the site by dividing each octet by the MD5 hash of '20'.
- CVE-2005-2946HIGHCVSS 7.5EG 7.52005-09-16
The default configuration on OpenSSL before 0.9.8 uses MD5 for creating message digests instead of a more cryptographically strong algorithm, which makes it easier for remote attackers to forge certificates with a valid certificate authori…
- CVE-2005-4860HIGHCVSS 7.8EG 7.82005-12-31
Spectrum Cash Receipting System before 6.504 uses weak cryptography (static substitution) in the PASSFILE password file, which makes it easier for local users to gain privileges by decrypting a password.
- CVE-2005-4900MEDIUMCVSS 5.9EG 5.92016-10-14
SHA-1 is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of SHA-1 in TLS 1.2. NOTE: this CVE exists to provide a common identifier for refer…
- CVE-2007-4150HIGHCVSS 7.5EG 7.52007-08-03
The Visionsoft Audit on Demand Service (VSAOD) in Visionsoft Audit 12.4.0.0 uses weak cryptography (XOR) when (1) transmitting passwords, which allows remote attackers to obtain sensitive information by sniffing the network; and (2) storin…
- CVE-2007-5460MEDIUMCVSS 4.6EG 4.62007-10-15
Microsoft ActiveSync 4.1, as used in Windows Mobile 5.0, uses weak encryption (XOR obfuscation with a fixed key) when sending the user's PIN/Password over the USB connection from the host to the device, which might make it easier for attac…
- CVE-2007-6755NONECVSS 0.0EG 0.02013-10-11
The NIST SP 800-90A default statement of the Dual Elliptic Curve Deterministic Random Bit Generation (Dual_EC_DRBG) algorithm contains point Q constants with a possible relationship to certain "skeleton key" values, which might allow conte…
- CVE-2008-3188HIGHCVSS 7.5EG 7.52008-07-22
libxcrypt in SUSE openSUSE 11.0 uses the DES algorithm when the configuration specifies the MD5 algorithm, which makes it easier for attackers to conduct brute-force attacks against hashed passwords.
- CVE-2008-3775MEDIUMCVSS 4.4EG 4.42008-08-22
Folder Lock 5.9.5 and earlier uses weak encryption (ROT-25) for the password, which allows local administrators to obtain sensitive information by reading and decrypting the QualityControl\_pack registry value.
- CVE-2009-2273NONECVSS 0.0EG 0.02009-07-01
The default configuration of the Wi-Fi component on the Huawei D100 does not use encryption, which makes it easier for remote attackers to obtain sensitive information by sniffing the network.
- CVE-2011-2487MEDIUMCVSS 5.9EG 5.92020-03-11
The implementations of PKCS#1 v1.5 key transport mechanism for XMLEncryption in JBossWS and Apache WSS4J before 1.6.5 is susceptible to a Bleichenbacher attack.
- CVE-2012-2146NONECVSS 0.0EG 7.52012-08-26
Elixir 0.8.0 uses Blowfish in CFB mode without constructing a unique initialization vector (IV), which makes it easier for context-dependent users to obtain sensitive information and decrypt the database.
- CVE-2012-5623HIGHCVSS 7.5EG 7.52020-02-13
Squirrelmail 4.0 uses the outdated MD5 hash algorithm for passwords.
- CVE-2013-1053MEDIUMCVSS 5.5EG 5.52021-01-13
In crypt.c of remote-login-service, the cryptographic algorithm used to cache usernames and passwords is insecure. An attacker could use this vulnerability to recover usernames and passwords from the file. This issue affects version 1.0.0-…
- CVE-2013-20003HIGHCVSS 8.3EG 8.32022-02-04
Z-Wave devices from Sierra Designs (circa 2013) and Silicon Labs (using S0 security) may use a known, shared network key of all zeros, allowing an attacker within radio range to spoof Z-Wave traffic.
- CVE-2013-2213MEDIUMCVSS 5.5EG 5.52020-02-11
The KRandom::random function in KDE Paste Applet after 4.10.5 in kdeplasma-addons uses the GNU C Library rand function's linear congruential generator, which makes it easier for context-dependent attackers to defeat cryptographic protectio…
- CVE-2013-2566MEDIUMCVSS 5.9EG 9.02013-03-15
The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct plaintext-recovery attacks via statistical analysis of ciphertext in a large number of sess…
- CVE-2015-2808LOWCVSS 3.7EG 0.02015-04-01
The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recovery attacks against t…
- CVE-2015-9235CRITICALCVSS 9.8EG 9.82018-05-29
In jsonwebtoken node module before 4.2.2 it is possible for an attacker to bypass verification when a token digitally signed with an asymmetric key (RS/ES family) of algorithms but instead the attacker send a token digitally signed with a …
- CVE-2016-5431HIGHCVSS 7.5EG 7.52019-08-07
The PHP JOSE Library by Gree Inc. before version 2.2.1 is vulnerable to key confusion/algorithm substitution in the JWS component resulting in bypassing the signature verification via crafted tokens.
- CVE-2017-12129HIGHCVSS 8.0EG 8.02018-05-14
An exploitable Weak Cryptography for Passwords vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. An attacker could intercept weakly encrypted passwords and could brute force them.
- CVE-2017-15326MEDIUMCVSS 4.3EG 4.32018-03-23
DBS3900 TDD LTE V100R003C00, V100R004C10 have a weak encryption algorithm security vulnerability. DBS3900 TDD LTE supports SSL/TLS protocol negotiation using insecure encryption algorithms. If an insecure encryption algorithm is negotiated…
- CVE-2017-1571MEDIUMCVSS 5.1EG 5.52018-03-22
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 131853.
- CVE-2017-1575MEDIUMCVSS 5.1EG 5.52018-07-20
IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway 2.2.0 through 2.2.6) uses weaker than expected cryptographic algorithms that could allow a local attacker to decrypt highly sensitive information. IBM X-Force ID: 1320…
- CVE-2017-16718MEDIUMCVSS 5.9EG 5.92018-06-27
Beckhoff TwinCAT 3 supports communication over ADS. ADS is a protocol for industrial automation in protected environments. This protocol uses user configured routes, that can be edited remotely via ADS. This special command supports encryp…
- CVE-2017-17167MEDIUMCVSS 5.9EG 5.92018-03-09
Huawei DP300 V500R002C00; TP3206 V100R002C00; ViewPoint 9030 V100R011C02; V100R011C03 have a use of a broken or risky cryptographic algorithm vulnerability. The software uses risky cryptographic algorithm in SSL. This is dangerous because …
- CVE-2017-17428MEDIUMCVSS 5.9EG 5.92018-03-05
Cavium Nitrox SSL, Nitrox V SSL, and TurboSSL software development kits (SDKs) allow remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a ROBOT attack.
- CVE-2017-2488HIGHCVSS 7.5EG 7.52021-12-23
A cryptographic weakness existed in the authentication protocol of Remote Desktop. This issue was addressed by implementing the Secure Remote Password authentication protocol. This issue is fixed in Apple Remote Desktop 3.9. An attacker ma…
- CVE-2018-0734MEDIUMCVSS 5.9EG 5.92018-10-30
The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.1a (Affected 1.1.1). Fixed in O…
- CVE-2018-0735MEDIUMCVSS 5.9EG 5.92018-10-29
The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). F…
- CVE-2018-0737MEDIUMCVSS 5.9EG 5.92018-04-16
The OpenSSL RSA Key generation algorithm has been shown to be vulnerable to a cache timing side channel attack. An attacker with sufficient access to mount cache timing attacks during the RSA key generation process could recover the privat…
- CVE-2018-1000180HIGHCVSS 7.5EG 7.52018-06-05
Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than …
- CVE-2018-10084HIGHCVSS 8.8EG 8.82018-04-13
CMS Made Simple (CMSMS) through 2.2.6 contains a privilege escalation vulnerability from ordinary user to admin user by arranging for the eff_uid value within $_COOKIE[$this->_loginkey] to equal 1, because an SHA-1 cryptographic protection…
- CVE-2018-10831HIGHCVSS 7.5EG 7.52018-05-09
Z-NOMP before 2018-04-05 has an incorrect Equihash solution verifier that allows attackers to spoof mining shares, as demonstrated by providing a solution with {x1=1,x2=1,x3=1,...,x512=1} to bypass this verifier for any blockheader. This o…
- CVE-2018-10844MEDIUMCVSS 5.9EG 5.92018-08-22
It was found that the GnuTLS implementation of HMAC-SHA-256 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of …
- CVE-2018-10845MEDIUMCVSS 5.9EG 5.92018-08-22
It was found that the GnuTLS implementation of HMAC-SHA-384 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to conduct distinguishing attacks and plain text recovery attacks via statistical analysis of…
- CVE-2018-10846MEDIUMCVSS 5.6EG 5.62018-08-22
A cache-based side channel in GnuTLS implementation that leads to plain text recovery in cross-VM attack setting was found. An attacker could use a combination of "Just in Time" Prime+probe attack in combination with Lucky-13 attack to rec…
- CVE-2018-11057MEDIUMCVSS 5.9EG 5.92018-08-31
RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6.1 (in 4.1.x) contains a Covert Timing Channel vulnerability during RSA decryption, also known as a Bleichenbacher attack on RSA decryption. A remote atta…
- CVE-2018-11069MEDIUMCVSS 5.9EG 5.92018-09-11
RSA BSAFE SSL-J versions prior to 6.2.4 contain a Covert Timing Channel vulnerability during RSA decryption, also known as a Bleichenbacher attack on RSA decryption. A remote attacker may be able to recover a RSA key.
- CVE-2018-11070MEDIUMCVSS 5.9EG 5.92018-09-11
RSA BSAFE Crypto-J versions prior to 6.2.4 and RSA BSAFE SSL-J versions prior to 6.2.4 contain a Covert Timing Channel vulnerability during PKCS #1 unpadding operations, also known as a Bleichenbacher attack. A remote attacker may be able …
- CVE-2018-11209HIGHCVSS 7.2EG 7.22018-05-16
An issue was discovered in Z-BlogPHP 2.0.0. zb_system/cmd.php?act=verify relies on MD5 for the password parameter, which might make it easier for attackers to bypass intended access restrictions via a dictionary or rainbow-table attack. NO…
- CVE-2018-12420HIGHCVSS 7.5EG 7.52018-06-14
IceHrm before 23.0.1.OS has a risky usage of a hashed password in a request.
- CVE-2018-1428MEDIUMCVSS 6.2EG 5.52018-03-22
IBM GSKit (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 139073.
- CVE-2018-15355MEDIUMCVSS 5.9EG 5.92018-08-17
Usage of SSLv2 and SSLv3 leads to transmitted data decryption in Kraftway 24F2XG Router firmware 3.5.30.1118.
- CVE-2018-16806MEDIUMCVSS 6.5EG 6.52018-09-10
A Pektron Passive Keyless Entry and Start (PKES) system, as used on the Tesla Model S and possibly other vehicles, relies on the DST40 cipher, which makes it easier for attackers to obtain access via an approach involving a 5.4 TB precompu…
- CVE-2018-1720MEDIUMCVSS 5.9EG 5.92019-04-25
IBM Sterling B2B Integrator Standard Edition 5.2.0.1, 5.2.6.3_6, 6.0.0.0, and 6.0.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 147294.
- CVE-2018-18371MEDIUMCVSS 6.5EG 6.52019-08-30
The ASG/ProxySG FTP proxy WebFTP mode allows intercepting FTP connections where a user accesses an FTP server via a ftp:// URL in a web browser. An information disclosure vulnerability in the WebFTP mode allows a malicious user to obtain p…
- CVE-2018-18587MEDIUMCVSS 5.3EG 5.32018-10-23
BigProf AppGini 5.70 stores the passwords in the database using the MD5 hash.
- CVE-2018-1996MEDIUMCVSS 5.3EG 5.32019-02-19
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could provide weaker than expected security, caused by the improper TLS configuration. A remote attacker could exploit this vulnerability to obtain sensitive information using man in …
Map vulnerabilities like CWE-327 to your infrastructure
EchelonGraph correlates every CVE — across CWE-327 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →