CWE-327— Use of a Broken or Risky Cryptographic Algorithm
The product uses a broken or risky cryptographic algorithm or protocol.— MITRE CWE catalog
737 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-327page 6 of 15
- CVE-2020-5229HIGHCVSS 7.7EG 7.72020-01-30
Opencast before 8.1 stores passwords using the rather outdated and cryptographically insecure MD5 hash algorithm. Furthermore, the hashes are salted using the username instead of a random salt, causing hashes for users with the same userna…
- CVE-2020-5943MEDIUMCVSS 6.5EG 6.52020-11-05
In versions 14.1.0-14.1.0.1 and 14.1.2.5-14.1.2.7, when a BIG-IP object is created or listed through the REST interface, the protected fields are obfuscated in the REST response, not protected via a SecureVault cryptogram as TMSH does. One…
- CVE-2020-6857MEDIUMCVSS 5.5EG 5.52020-01-21
CarbonFTP v1.4 uses insecure proprietary password encryption with a hard-coded weak encryption key. The key for local FTP server passwords is hard-coded in the binary.
- CVE-2020-6861MEDIUMCVSS 5.5EG 5.52020-05-06
A flawed protocol design in the Ledger Monero app before 1.5.1 for Ledger Nano and Ledger S devices allows a local attacker to extract the master spending key by sending crafted messages to this app selected on a PIN-entered Ledger connect…
- CVE-2020-6874CRITICALCVSS 9.1EG 9.12020-09-01
A ZTE product is impacted by the cryptographic issues vulnerability. The encryption algorithm is not properly used, so remote attackers could use this vulnerability for account credential enumeration attack or brute-force attack for passwo…
- CVE-2020-6984HIGHCVSS 7.5EG 7.52020-03-16
Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix 500 Software v12.001 and prior, The cryptographic function utilized to protect the passwo…
- CVE-2020-6987HIGHCVSS 7.5EG 7.52020-03-24
In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or lower, the affected products use a weak cryptographic algorithm, which may allow confidential information to be disclosed.
- CVE-2020-7001HIGHCVSS 7.5EG 7.52020-03-24
In Moxa EDS-G516E Series firmware, Version 5.2 or lower, the affected products use a weak cryptographic algorithm, which may allow confidential information to be disclosed.
- CVE-2020-7339MEDIUMCVSS 6.3EG 6.32020-12-10
Use of a Broken or Risky Cryptographic Algorithm vulnerability in McAfee Database Security Server and Sensor prior to 4.8.0 in the form of a SHA1 signed certificate that would allow an attacker on the same local network to potentially inte…
- CVE-2020-7511HIGHCVSS 7.5EG 7.52020-06-16
A CWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to acquire a password by brute force.
- CVE-2020-7514HIGHCVSS 7.8EG 7.82020-07-23
A CWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could allow an attacker access to the authorization credentials for a device and gain full access.
- CVE-2020-7689MEDIUMCVSS 5.9EG 5.92020-07-01
Data is truncated wrong when its length is greater than 255 bytes.
- CVE-2020-8897MEDIUMCVSS 4.8EG 4.82020-11-16
A weak robustness vulnerability exists in the AWS Encryption SDKs for Java, Python, C and Javalcript prior to versions 2.0.0. Due to the non-committing property of AES-GCM (and other AEAD ciphers such as AES-GCM-SIV or (X)ChaCha20Poly1305)…
- CVE-2020-8911MEDIUMCVSS 5.6EG 5.62020-08-11
A padding oracle vulnerability exists in the AWS S3 Crypto SDK for GoLang versions prior to V2. The SDK allows users to encrypt files with AES-CBC without computing a Message Authentication Code (MAC), which then allows an attacker who has…
- CVE-2020-8912LOWCVSS 2.5EG 2.52020-08-11
A vulnerability in the in-band key negotiation exists in the AWS S3 Crypto SDK for GoLang versions prior to V2. An attacker with write access to the targeted bucket can change the encryption algorithm of an object in the bucket, which can …
- CVE-2020-9491HIGHCVSS 7.5EG 7.52020-10-01
In Apache NiFi 1.2.0 to 1.11.4, the NiFi UI and API were protected by mandating TLS v1.2, as well as listening connections established by processors like ListenHTTP, HandleHttpRequest, etc. However intracluster communication such as cluste…
- CVE-2020-9526MEDIUMCVSS 5.9EG 5.92020-08-10
CS2 Network P2P through 3.x, as used in millions of Internet of Things devices, suffers from an information exposure flaw that exposes user session data to supernodes in the network, as demonstrated by passively eavesdropping on user video…
- CVE-2020-9528HIGHCVSS 7.5EG 7.52020-08-10
Firmware developed by Shenzhen Hichip Vision Technology (V6 through V20), as used by many different vendors in millions of Internet of Things devices, suffers from cryptographic issues that allow remote attackers to access user session dat…
- CVE-2021-20305HIGHCVSS 8.1EG 8.12021-04-05
A flaw was found in Nettle in versions before 3.7.2, where several Nettle signature verification functions (GOST DSA, EDDSA & ECDSA) result in the Elliptic Curve Cryptography point (ECC) multiply function being called with out-of-range sca…
- CVE-2021-20337HIGHCVSS 7.5EG 7.52021-07-26
IBM QRadar SIEM 7.3.0 to 7.3.3 Patch 8 and 7.4.0 to 7.4.3 GA uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 194448.
- CVE-2021-20379HIGHCVSS 7.5EG 7.52021-07-07
IBM Guardium Data Encryption (GDE) 3.0.0.3 and 4.0.0.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 195711.
- CVE-2021-20406MEDIUMCVSS 2.2EG 4.92021-02-12
IBM Security Verify Information Queue 1.0.6 and 1.0.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 196184.
- CVE-2021-20419HIGHCVSS 7.5EG 7.52021-05-24
IBM Security Guardium 11.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 196280.
- CVE-2021-20441MEDIUMCVSS 5.9EG 5.92021-03-03
IBM Security Verify Bridge uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 196617.
- CVE-2021-20479HIGHCVSS 7.5EG 7.52022-05-09
IBM Cloud Pak System 2.3.0 through 2.3.3.3 Interim Fix 1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 197498.
- CVE-2021-20497HIGHCVSS 7.5EG 7.52021-07-15
IBM Security Verify Access Docker 10.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 197969
- CVE-2021-20566HIGHCVSS 7.5EG 7.52021-06-16
IBM Resilient SOAR V38.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 199238.
- CVE-2021-22170HIGHCVSS 6.2EG 7.52021-12-06
Assuming a database breach, nonce reuse issues in GitLab 11.6+ allows an attacker to decrypt some of the database's encrypted content
- CVE-2021-22212HIGHCVSS 4.0EG 7.42021-06-08
ntpkeygen can generate keys that ntpd fails to parse. NTPsec 1.2.0 allows ntpkeygen to generate keys with '#' characters. ntpd then either pads, shortens the key, or fails to load these keys entirely, depending on the key type and the plac…
- CVE-2021-22309HIGHCVSS 7.5EG 7.52021-03-22
There is insecure algorithm vulnerability in Huawei products. A module uses less random input in a secure mechanism. Attackers can exploit this vulnerability by brute forcing to obtain sensitive message. This can lead to information leak. …
- CVE-2021-22356MEDIUMCVSS 5.9EG 5.92021-11-23
There is a weak secure algorithm vulnerability in Huawei products. A weak secure algorithm is used in a module. Attackers can exploit this vulnerability by capturing and analyzing the messages between devices to obtain information. This ca…
- CVE-2021-22738CRITICALCVSS 9.8EG 9.82021-05-26
Use of a Broken or Risky Cryptographic Algorithm vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior that could cause unauthorized access when credentials are discovered after a brute force attack.
- CVE-2021-22948HIGHCVSS 7.1EG 7.12021-09-23
Vulnerability in the generation of session IDs in revive-adserver < 5.3.0, based on the cryptographically insecure uniqid() PHP function. Under some circumstances, an attacker could theoretically be able to brute force session IDs in order…
- CVE-2021-2351HIGHCVSS 8.3EG 8.32021-07-21
Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network acces…
- CVE-2021-23839LOWCVSS 3.7EG 3.72021-02-16
OpenSSL 1.0.2 supports SSLv2. If a client attempts to negotiate SSLv2 with a server that is configured to support both SSLv2 and more recent SSL and TLS versions then a check is made for a version rollback attack when unpadding an RSA sign…
- CVE-2021-23993MEDIUMCVSS 6.5EG 6.52021-06-24
An attacker may perform a DoS attack to prevent a user from sending encrypted email to a correspondent. If an attacker creates a crafted OpenPGP key with a subkey that has an invalid self signature, and the Thunderbird user imports the cra…
- CVE-2021-25761MEDIUMCVSS 5.3EG 5.32021-02-03
In JetBrains Ktor before 1.5.0, a birthday attack on SessionStorage key was possible.
- CVE-2021-25763MEDIUMCVSS 5.3EG 5.32021-02-03
In JetBrains Ktor before 1.4.2, weak cipher suites were enabled by default.
- CVE-2021-26095HIGHCVSS 7.5EG 8.82021-07-20
The combination of various cryptographic issues in the session management of FortiMail 6.4.0 through 6.4.4 and 6.2.0 through 6.2.6, including the encryption construction of the session cookie, may allow a remote attacker already in possess…
- CVE-2021-26099MEDIUMCVSS 4.4EG 4.92021-07-12
Missing cryptographic steps in the Identity-Based Encryption service of FortiMail before 7.0.0 may allow an attacker who comes in possession of the encrypted master keys to compromise their confidentiality by observing a few invariant prop…
- CVE-2021-27211HIGHCVSS 7.5EG 7.52021-02-15
steghide 0.5.1 relies on a certain 32-bit seed value, which makes it easier for attackers to detect hidden data.
- CVE-2021-27457HIGHCVSS 7.5EG 7.52021-05-20
A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected products utilize a weak encryption algorithm for storage of sensitive data, which may allow an attacker to more easily obtain cre…
- CVE-2021-27756HIGHCVSS 7.5EG 7.52022-03-04
"TLS-RSA cipher suites are not disabled in BigFix Compliance up to v2.0.5. If TLS 2.0 and secure ciphers are not enabled then an attacker can passively record traffic and later decrypt it."
- CVE-2021-27784HIGHCVSS 5.9EG 7.52022-10-31
The provided HCL Launch Container images contain non-unique HTTPS certificates and a database encryption key. The fix provides directions and tools to replace the non-unique keys and certificates. This does not affect the standard installe…
- CVE-2021-27795MEDIUMCVSS 6.4EG 6.42023-12-06
Brocade Fabric OS (FOS) hardware platforms running any version of Brocade Fabric OS software, which supports the license string format; contain cryptographic issues that could allow for the installation of forged or fraudulent license …
- CVE-2021-27913LOWCVSS 3.5EG 3.52021-08-30
The function mt_rand is used to generate session tokens, this function is cryptographically flawed due to its nature being one pseudorandomness, an attacker can take advantage of the cryptographically insecure nature of this function to en…
- CVE-2021-29694HIGHCVSS 7.5EG 7.52021-04-26
IBM Spectrum Protect Plus 10.1.0 through 10.1.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 200258.
- CVE-2021-29704HIGHCVSS 7.5EG 7.52021-08-23
IBM Security SOAR uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
- CVE-2021-29722HIGHCVSS 7.5EG 7.52021-08-30
IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 201095.
- CVE-2021-29723HIGHCVSS 7.5EG 7.52021-08-30
IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-ForceID: 201100.
Map vulnerabilities like CWE-327 to your infrastructure
EchelonGraph correlates every CVE — across CWE-327 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →