CWE-327— Use of a Broken or Risky Cryptographic Algorithm
The product uses a broken or risky cryptographic algorithm or protocol.— MITRE CWE catalog
737 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-327page 10 of 15
- CVE-2023-28509HIGHCVSS 7.5EG 7.52023-03-29
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 use weak encryption for packet-level security and passwords transferred on the wire.
- CVE-2023-2900LOWCVSS 3.7EG 3.72023-05-25
A vulnerability was found in NFine Rapid Development Platform 20230511. It has been classified as problematic. Affected is an unknown function of the file /Login/CheckLogin. The manipulation leads to use of weak hash. It is possible to lau…
- CVE-2023-30441HIGHCVSS 7.5EG 7.52023-04-29
IBM Runtime Environment, Java Technology Edition IBMJCEPlus and JSSE 8.0.7.0 through 8.0.7.11 components could expose sensitive information using a combination of flaws and configurations. IBM X-Force ID: 253188.
- CVE-2023-30994MEDIUMCVSS 5.4EG 5.42023-10-14
IBM QRadar SIEM 7.5.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 254138
- CVE-2023-32043MEDIUMCVSS 6.8EG 6.82023-07-11
Windows Remote Desktop Security Feature Bypass Vulnerability
- CVE-2023-3350HIGHCVSS 8.2EG 8.22023-10-03
A Cryptographic Issue vulnerability has been found on IBERMATICA RPS, affecting version 2019. By firstly downloading the log file, an attacker could retrieve the SQL query sent to the application in plaint text. This log file contains the …
- CVE-2023-34039CRITICALCVSS 9.8EG 9.82023-08-29
Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key generation. A malicious actor with network access to Aria Operations for Networks could bypass SSH authentication to ga…
- CVE-2023-34130CRITICALCVSS 9.8EG 9.82023-07-13
SonicWall GMS and Analytics use outdated Tiny Encryption Algorithm (TEA) with a hardcoded key to encrypt sensitive data. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.
- CVE-2023-34758HIGHCVSS 8.1EG 8.12023-08-28
Sliver from v1.5.x to v1.5.39 has an improper cryptographic implementation, which allows attackers to execute a man-in-the-middle attack via intercepted and crafted responses.
- CVE-2023-35890MEDIUMCVSS 5.1EG 5.12023-07-07
IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security, caused by the improper encoding in a local configuration file. IBM X-Force ID: 258637.
- CVE-2023-36608MEDIUMCVSS 6.5EG 6.52023-07-03
The affected TBox RTUs store hashed passwords using MD5 encryption, which is an insecure encryption algorithm.
- CVE-2023-36749HIGHCVSS 7.4EG 7.42023-07-11
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V2.16.0), RUGGEDCOM …
- CVE-2023-37395LOWCVSS 2.5EG 2.52024-12-11
IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain sensitive information due to improper encryption of certain data.
- CVE-2023-37396LOWCVSS 2.5EG 2.52024-04-19
IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain sensitive information due to improper encryption of certain data. IBM X-Force ID: 259671.
- CVE-2023-37464HIGHCVSS 8.6EG 8.62023-07-14
OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). The AES GCM decryption routine incorrectly uses the Tag length from the actual Authentication Tag provided in the JWE. The spec says that a fix…
- CVE-2023-37484MEDIUMCVSS 5.3EG 5.32023-08-08
SAP PowerDesigner - version 16.7, queries all password hashes in the backend database and compares it with the user provided one during login attempt, which might allow an attacker to access password hashes from the client's memory.
- CVE-2023-38361MEDIUMCVSS 5.9EG 5.92023-11-18
IBM CICS TX Advanced 10.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 260770.
- CVE-2023-38371MEDIUMCVSS 5.9EG 5.92024-06-27
IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 261198.
- CVE-2023-38730MEDIUMCVSS 5.9EG 5.92023-08-27
IBM Storage Copy Data Management 2.2.0.0 through 2.2.19.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 262268.
- CVE-2023-39252MEDIUMCVSS 5.9EG 5.92023-09-21
Dell SCG Policy Manager 5.16.00.14 contains a broken cryptographic algorithm vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by performing MitM attacks and let attackers obtain sensitive inform…
- CVE-2023-40371MEDIUMCVSS 6.2EG 6.22023-08-24
IBM AIX 7.2, 7.3, VIOS 3.1's OpenSSH implementation could allow a non-privileged local user to access files outside of those allowed due to improper access controls. IBM X-Force ID: 263476.
- CVE-2023-40660MEDIUMCVSS 6.6EG 6.62023-11-06
A flaw was found in OpenSC packages that allow a potential PIN bypass. When a token/card is authenticated by one process, it can perform cryptographic operations in other processes when an empty zero-length pin is passed. This issue poses …
- CVE-2023-40696MEDIUMCVSS 5.9EG 5.92024-05-03
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 264939.
- CVE-2023-41097HIGHCVSS 7.5EG 7.52023-12-21
An Observable Timing Discrepancy, Covert Timing Channel vulnerability in Silabs GSDK on ARM potentially allows Padding Oracle Crypto Attack on CBC PKCS7.This issue affects GSDK: through 4.4.0.
- CVE-2023-41927MEDIUMCVSS 5.3EG 5.32024-07-02
The server supports at least one cipher suite which is on the NCSC-NL list of cipher suites to be phased out, increasing the risk of cryptographic weaknesses.
- CVE-2023-41928MEDIUMCVSS 5.3EG 5.32024-07-02
The device is observed to accept deprecated TLS protocols, increasing the risk of cryptographic weaknesses.
- CVE-2023-4326HIGHCVSS 7.5EG 7.52023-08-15
Broadcom RAID Controller web interface is vulnerable has an insecure default TLS configuration that supports obsolete SHA1-based ciphersuites
- CVE-2023-4327MEDIUMCVSS 5.5EG 5.52023-08-15
Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user on Linux
- CVE-2023-4331HIGHCVSS 7.5EG 7.52023-08-15
Broadcom RAID Controller web interface is vulnerable has an insecure default TLS configuration that support obsolete and vulnerable TLS protocols
- CVE-2023-43635HIGHCVSS 8.8EG 8.82023-09-20
Vault Key Sealed With SHA1 PCRs The measured boot solution implemented in EVE OS leans on a PCR locking mechanism. Different parts of the system update different PCR values in the TPM, resulting in a unique value for each PCR entry…
- CVE-2023-46133CRITICALCVSS 9.1EG 9.12023-10-25
CryptoES is a cryptography algorithms library compatible with ES6 and TypeScript. Prior to version 2.1.0, CryptoES PBKDF2 is 1,000 times weaker than originally specified in 1993, and at least 1,300,000 times weaker than current industry st…
- CVE-2023-46233CRITICALCVSS 9.1EG 9.12023-10-25
crypto-js is a JavaScript library of crypto standards. Prior to version 4.2.0, crypto-js PBKDF2 is 1,000 times weaker than originally specified in 1993, and at least 1,300,000 times weaker than current industry standard. This is because it…
- CVE-2023-47640HIGHCVSS 8.8EG 8.82023-11-14
DataHub is an open-source metadata platform. The HMAC signature for DataHub Frontend sessions was being signed using a SHA-1 HMAC with the frontend secret key. SHA1 with a 10 byte key can be brute forced using sufficient resources (i.e. st…
- CVE-2023-49259HIGHCVSS 7.5EG 7.52024-01-12
The authentication cookies are generated using an algorithm based on the username, hardcoded secret and the up-time, and can be guessed in a reasonable time.
- CVE-2023-50312MEDIUMCVSS 5.3EG 5.32024-03-01
IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.2 could provide weaker than expected security for outbound TLS connections caused by a failure to honor user configuration. IBM X-Force ID: 274711.
- CVE-2023-50313MEDIUMCVSS 5.3EG 5.32024-04-02
IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security for outbound TLS connections caused by a failure to honor user configuration. IBM X-Force ID: 274812.
- CVE-2023-50350HIGHCVSS 7.5EG 8.22024-01-03
HCL DRYiCE MyXalytics is impacted by the use of a broken cryptographic algorithm for encryption, potentially giving an attacker ability to decrypt sensitive information.
- CVE-2023-50351CRITICALCVSS 9.1EG 9.12024-01-03
HCL DRYiCE MyXalytics is impacted by the use of an insecure key rotation mechanism which can allow an attacker to compromise the confidentiality or integrity of data.
- CVE-2023-50475CRITICALCVSS 9.1EG 9.12023-12-21
An issue was discovered in bcoin-org bcoin version 2.2.0, allows remote attackers to obtain sensitive information via weak hashing algorithms in the component \vendor\faye-websocket.js.
- CVE-2023-50481HIGHCVSS 7.5EG 7.52023-12-21
An issue was discovered in blinksocks version 3.3.8, allows remote attackers to obtain sensitive information via weak encryption algorithms in the component /presets/ssr-auth-chain.js.
- CVE-2023-50937MEDIUMCVSS 5.9EG 5.92024-02-02
IBM PowerSC 1.3, 2.0, and 2.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 275117.
- CVE-2023-50939MEDIUMCVSS 5.9EG 5.92024-02-02
IBM PowerSC 1.3, 2.0, and 2.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 275129.
- CVE-2023-51392MEDIUMCVSS 6.2EG 6.22024-02-23
Ember ZNet between v7.2.0 and v7.4.0 used software AES-CCM instead of integrated hardware cryptographic accelerators, potentially increasing risk of electromagnetic and differential power analysis sidechannel attacks.
- CVE-2023-51838HIGHCVSS 7.5EG 7.52024-02-02
Ylianst MeshCentral 1.1.16 suffers from Use of a Broken or Risky Cryptographic Algorithm.
- CVE-2023-51839CRITICALCVSS 9.1EG 9.12024-01-29
DeviceFarmer stf v3.6.6 suffers from Use of a Broken or Risky Cryptographic Algorithm.
- CVE-2023-52236HIGHCVSS 7.0EG 7.02025-07-08
A vulnerability has been identified in RUGGEDCOM i800 (All versions), RUGGEDCOM i801 (All versions), RUGGEDCOM i802 (All versions), RUGGEDCOM i803 (All versions), RUGGEDCOM M2100 (All versions), RUGGEDCOM M2200 (All versions), RUGGEDCOM M9…
- CVE-2023-5347CRITICALCVSS 9.1EG 9.82024-01-09
An Improper Verification of Cryptographic Signature vulnerability in the update process of Korenix JetNet Series allows replacing the whole operating system including Trusted Executables. This issue affects JetNet devices older than firmw…
- CVE-2023-5627HIGHCVSS 7.5EG 7.52023-11-01
A vulnerability has been identified in NPort 6000 Series, making the authentication mechanism vulnerable. This vulnerability arises from the incorrect implementation of sensitive information protection, potentially allowing malicious users…
- CVE-2023-5962MEDIUMCVSS 6.5EG 6.52023-12-23
A weak cryptographic algorithm vulnerability has been identified in ioLogik E1200 Series firmware versions v3.3 and prior. This vulnerability can help an attacker compromise the confidentiality of sensitive data. This vulnerability may lea…
- CVE-2023-6240MEDIUMCVSS 6.5EG 6.52024-02-04
A Marvin vulnerability side-channel leakage was found in the RSA decryption operation in the Linux Kernel. This issue may allow a network attacker to decrypt ciphertexts or forge signatures, limiting the services that use that private key.
Map vulnerabilities like CWE-327 to your infrastructure
EchelonGraph correlates every CVE — across CWE-327 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →