CWE-327— Use of a Broken or Risky Cryptographic Algorithm
653 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-327page 3 of 14
- CVE-2019-20775MEDIUMCVSS 5.5EG 5.52020-04-17
An issue was discovered on LG mobile devices with Android OS 9.0 (Qualcomm SDM450, SDM845, SM6150, and SM8150 chipsets) software. Weak encryption leads to local information disclosure. The LG ID is LVE-SMP-190010 (August 2019).
- CVE-2019-25006HIGHCVSS 7.5EG 7.52020-12-31
An issue was discovered in the streebog crate before 0.8.0 for Rust. The Streebog hash function can produce the wrong answer.
- CVE-2019-25052CRITICALCVSS 9.1EG 9.12021-08-11
In Linaro OP-TEE before 3.7.0, by using inconsistent or malformed data, it is possible to call update and final cryptographic functions directly, causing a crash that could leak sensitive information.
- CVE-2019-25651HIGHCVSS 8.3EG 8.32026-03-27
Ubiquiti UniFi Network Controller prior to 5.10.12 (excluding 5.6.42), UAP FW prior to 4.0.6, UAP-AC, UAP-AC v2, and UAP-AC Outdoor FW prior to 3.8.17, USW FW prior to 4.0.6, USG FW prior to 4.4.34 uses AES-CBC encryption for device-to-con…
- CVE-2019-3700LOWCVSS 2.9EG 2.92020-01-24
yast2-security didn't use secure defaults to protect passwords. This became a problem on 2019-10-07 when configuration files that set secure settings were moved to a different location. As of the 20191022 snapshot the insecure default sett…
- CVE-2019-3736HIGHCVSS 7.2EG 7.22019-09-27
Dell EMC Integrated Data Protection Appliance versions prior to 2.3 contain a password storage vulnerability in the ACM component. A remote authenticated malicious user with root privileges may potentially use a support tool to decrypt enc…
- CVE-2019-3818HIGHCVSS 7.5EG 7.52019-02-05
The kube-rbac-proxy container before version 0.4.1 as used in Red Hat OpenShift Container Platform does not honor TLS configurations, allowing for use of insecure ciphers and TLS 1.0. An attacker could target traffic sent over a TLS connec…
- CVE-2019-4156MEDIUMCVSS 5.9EG 5.92019-06-25
IBM Security Access Manager 9.0.1 through 9.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 158572.
- CVE-2019-4325MEDIUMCVSS 5.3EG 5.32020-10-06
"HCL AppScan Enterprise makes use of broken or risky cryptographic algorithm to store REST API user details."
- CVE-2019-4399HIGHCVSS 7.5EG 7.52019-10-25
IBM Cloud Orchestrator 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 162260.
- CVE-2019-4427HIGHCVSS 7.5EG 7.52020-02-12
IBM Cloud CLI 0.6.0 through 0.16.1 windows installers are signed using SHA1 certificate. An attacker might be able to exploit the weak algorithm to generate a installer with malicious software inside. IBM X-Force ID: 162773.
- CVE-2019-4540HIGHCVSS 7.5EG 7.52020-02-04
IBM Security Directory Server 6.4.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 165813.
- CVE-2019-4553HIGHCVSS 7.5EG 7.52020-03-24
IBM API Connect V5.0.0.0 through 5.0.8.7iFix3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 165958.
- CVE-2019-4609HIGHCVSS 7.5EG 7.52019-12-18
IBM API Connect 2018.4.1.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 168510.
- CVE-2019-4639HIGHCVSS 7.5EG 7.52020-01-28
IBM Security Secret Server 10.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 170045.
- CVE-2019-5035CRITICALCVSS 9.0EG 9.02019-08-20
An exploitable information disclosure vulnerability exists in the Weave PASE pairing functionality of the Nest Cam IQ Indoor, version 4620002. A set of specially crafted weave packets can brute force a pairing code, resulting in greater We…
- CVE-2019-5106MEDIUMCVSS 5.5EG 5.52020-03-11
A hard-coded encryption key vulnerability exists in the authentication functionality of WAGO e!Cockpit version 1.5.1.1. An attacker with access to communications between e!Cockpit and CoDeSyS Gateway can trivially recover the password of a…
- CVE-2019-5135MEDIUMCVSS 5.3EG 5.32020-03-11
An exploitable timing discrepancy vulnerability exists in the authentication functionality of the Web-Based Management (WBM) web application on WAGO PFC100/200 controllers. The WBM application makes use of the PHP crypt() function which ca…
- CVE-2019-5163HIGHCVSS 7.5EG 7.52019-12-03
An exploitable denial-of-service vulnerability exists in the UDPRelay functionality of Shadowsocks-libev 3.3.2. When utilizing a Stream Cipher and a local_address, arbitrary UDP packets can cause a FATAL error code path and exit. An attack…
- CVE-2019-5502CRITICALCVSS 9.1EG 9.12019-08-05
SMB in Data ONTAP operating in 7-Mode versions prior to 8.2.5P3 has weak cryptography which when exploited could lead to information disclosure or addition or modification of data.
- CVE-2019-5719MEDIUMCVSS 5.5EG 5.52019-01-08
In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the ISAKMP dissector could crash. This was addressed in epan/dissectors/packet-isakmp.c by properly handling the case of a missing decryption data block.
- CVE-2019-5723CRITICALCVSS 9.8EG 9.82019-03-21
An issue was discovered in portier vision 4.4.4.2 and 4.4.4.6. Passwords are stored using reversible encryption rather than as a hash value, and the used Vigenere algorithm is badly outdated. Moreover, the encryption key is static and too …
- CVE-2019-5754MEDIUMCVSS 6.5EG 6.52019-02-19
Implementation error in QUIC Networking in Google Chrome prior to 72.0.3626.81 allowed an attacker running or able to cause use of a proxy server to obtain cleartext of transport encryption via malicious network proxy.
- CVE-2019-5919CRITICALCVSS 9.1EG 9.12019-03-12
An incomplete cryptography of the data store function by using hidden tag in Nablarch 5 (5, and 5u1 to 5u13) allows remote attackers to obtain information of the stored data, to register invalid value, or alter the value via unspecified ve…
- CVE-2019-6485MEDIUMCVSS 5.9EG 5.92019-02-22
Citrix NetScaler Gateway 12.1 before build 50.31, 12.0 before build 60.9, 11.1 before build 60.14, 11.0 before build 72.17, and 10.5 before build 69.5 and Application Delivery Controller (ADC) 12.1 before build 50.31, 12.0 before build 60.…
- CVE-2019-6593MEDIUMCVSS 5.9EG 5.92019-02-26
On BIG-IP 11.5.1-11.5.4, 11.6.1, and 12.1.0, a virtual server configured with a Client SSL profile may be vulnerable to a chosen ciphertext attack against CBC ciphers. When exploited, this may result in plaintext recovery of encrypted mess…
- CVE-2019-7006MEDIUMCVSS 5.5EG 5.52019-02-27
Avaya one-X Communicator uses weak cryptographic algorithms in the client authentication component that could allow a local attacker to decrypt sensitive information. Affected versions include all 6.2.x versions prior to 6.2 SP13.
- CVE-2019-7477HIGHCVSS 7.5EG 7.52019-04-02
A vulnerability in SonicWall SonicOS and SonicOSv TLS CBC Cipher allow remote attackers to obtain sensitive plaintext data when CBC cipher suites are enabled. This vulnerability affected SonicOS Gen 5 version 5.9.1.10 and earlier, Gen 6 ve…
- CVE-2019-7673HIGHCVSS 7.5EG 7.52019-02-09
An issue was discovered on MOBOTIX S14 MX-V4.2.1.61 devices. Administrator Credentials are stored in the 13-character DES hash format.
- CVE-2019-7858HIGHCVSS 7.5EG 7.52019-08-02
A cryptographic flaw in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9 and Magento 2.3 prior to 2.3.2 resulted in storage of sensitive information with an algorithm that is insufficiently resistant to brute force attacks.
- CVE-2019-8237CRITICALCVSS 9.8EG 9.82019-10-23
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an insufficiently robust encr…
- CVE-2019-9013HIGHCVSS 8.8EG 8.82019-08-15
An issue was discovered in 3S-Smart CODESYS V3 products. The application may utilize non-TLS based encryption, which results in user credentials being insufficiently protected during transport. All variants of the following CODESYS V3 prod…
- CVE-2019-9080HIGHCVSS 7.5EG 7.52020-10-20
DomainMOD before 4.14.0 uses MD5 without a salt for password storage.
- CVE-2019-9095CRITICALCVSS 9.8EG 9.82020-03-11
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. An attacker may be able to intercept weakly encrypted passwords and…
- CVE-2019-9155MEDIUMCVSS 5.9EG 5.92019-08-22
A cryptographic issue in OpenPGP.js <=4.2.0 allows an attacker who is able provide forged messages and gain feedback about whether decryption of these messages succeeded to conduct an invalid curve attack in order to gain the victim's ECDH…
- CVE-2019-9399MEDIUMCVSS 5.9EG 5.92019-09-27
The Print Service is susceptible to man in the middle attacks due to improperly used crypto. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. …
- CVE-2019-9483CRITICALCVSS 9.1EG 9.12019-03-01
Amazon Ring Doorbell before 3.4.7 mishandles encryption, which allows attackers to obtain audio and video data, or insert spoofed video that does not correspond to the actual person at the door.
- CVE-2019-9506HIGHCVSS 8.1EG 8.12019-08-14
The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka …
- CVE-2019-9836MEDIUMCVSS 5.3EG 5.32019-06-25
Secure Encrypted Virtualization (SEV) on Advanced Micro Devices (AMD) Platform Security Processor (PSP; aka AMD Secure Processor or AMD-SP) 0.17 build 11 and earlier has an insecure cryptographic implementation.
- CVE-2020-10377CRITICALCVSS 9.8EG 9.82020-04-17
A weak encryption vulnerability in Mitel MiVoice Connect Client before 214.100.1214.0 could allow an unauthenticated attacker to gain access to user credentials. A successful exploit could allow an attacker to access the system with compro…
- CVE-2020-10554HIGHCVSS 7.5EG 7.52021-02-05
An issue was discovered in Psyprax beforee 3.2.2. Passwords used to encrypt the data are stored in the database in an obfuscated format, which can be easily reverted. For example, the password AAAAAAAA is stored in the database as MMMMMMMM.
- CVE-2020-10560MEDIUMCVSS 5.9EG 5.92020-03-30
An issue was discovered in Open Source Social Network (OSSN) through 5.3. A user-controlled file path with a weak cryptographic rand() can be used to read any file with the permissions of the webserver. This can lead to further compromise.…
- CVE-2020-10601HIGHCVSS 7.8EG 7.82020-04-03
VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module allow weak hashing algorithm and insecure permissions which may allow a local attacker to bypass the password-protected mechanism through brute-force attacks, cracking techniq…
- CVE-2020-10788CRITICALCVSS 9.1EG 9.12020-03-25
openITCOCKPIT before 3.7.3 uses the 1fea123e07f730f76e661bced33a94152378611e API key rather than generating a random API Key for WebSocket connections.
- CVE-2020-10927HIGHCVSS 8.8EG 8.82020-07-28
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists wit…
- CVE-2020-10932MEDIUMCVSS 4.7EG 5.52020-04-15
An issue was discovered in Arm Mbed TLS before 2.16.6 and 2.7.x before 2.7.15. An attacker that can get precise enough side-channel measurements can recover the long-term ECDSA private key by (1) reconstructing the projective coordinate of…
- CVE-2020-11005MEDIUMCVSS 5.1EG 5.12020-04-14
The WindowsHello open source library (NuGet HaemmerElectronics.SeppPenner.WindowsHello), before version 1.0.4, has a vulnerability where encrypted data could potentially be decrypted without needing authentication. If the library is used t…
- CVE-2020-11031HIGHCVSS 7.8EG 7.82020-09-23
In GLPI before version 9.5.0, the encryption algorithm used is insecure. The security of the data encrypted relies on the password used, if a user sets a weak/predictable password, an attacker could decrypt data. This is fixed in version 9…
- CVE-2020-11035HIGHCVSS 7.5EG 7.52020-05-05
In GLPI after version 0.83.3 and before version 9.4.6, the CSRF tokens are generated using an insecure algorithm. The implementation uses rand and uniqid and MD5 which does not provide secure values. This is fixed in version 9.4.6.
- CVE-2020-11500HIGHCVSS 7.5EG 7.52020-04-03
Zoom Client for Meetings through 4.6.9 uses the ECB mode of AES for video and audio encryption. Within a meeting, all participants use a single 128-bit key.
Map vulnerabilities like CWE-327 to your infrastructure
EchelonGraph correlates every CVE — across CWE-327 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →