CWE-327— Use of a Broken or Risky Cryptographic Algorithm
The product uses a broken or risky cryptographic algorithm or protocol.— MITRE CWE catalog
737 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-327page 9 of 15
- CVE-2022-33160LOWCVSS 3.7EG 3.72023-10-06
IBM Security Directory Suite 8.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 228568.
- CVE-2022-3365CRITICALCVSS 9.8EG 9.82025-01-28
Due to reliance on a trivial substitution cipher, sent in cleartext, and the reliance on a default password when the user does not set a password, the Remote Mouse Server by Emote Interactive can be abused by attackers to inject OS command…
- CVE-2022-34309MEDIUMCVSS 5.9EG 5.92024-02-12
IBM CICS TX Standard and Advanced 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 229440.
- CVE-2022-34310MEDIUMCVSS 5.9EG 5.92024-02-12
IBM CICS TX Standard and Advanced 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 229441.
- CVE-2022-34319HIGHCVSS 5.9EG 7.52022-11-14
IBM CICS TX 11.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 229463.
- CVE-2022-34320HIGHCVSS 5.9EG 7.52022-11-14
IBM CICS TX 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 229464.
- CVE-2022-34361HIGHCVSS 5.9EG 7.52022-12-06
IBM Sterling Secure Proxy 6.0.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 230522.
- CVE-2022-34444HIGHCVSS 5.9EG 7.52023-02-11
Dell PowerScale OneFS, versions 9.2.0.x through 9.4.0.x contain an information vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to cause data leak.
- CVE-2022-34632CRITICALCVSS 9.1EG 9.12022-07-18
Rocket-Chip commit 4f8114374d8824dfdec03f576a8cd68bebce4e56 was discovered to contain insufficient cryptography via the component /rocket/RocketCore.scala.
- CVE-2022-34757MEDIUMCVSS 6.7EG 6.72022-07-13
A CWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists where weak cipher suites can be used for the SSH connection between Easergy Pro software and the device, which may allow an attacker to observe protected comm…
- CVE-2022-35513HIGHCVSS 7.5EG 7.52022-09-07
The Blink1Control2 application <= 2.2.7 uses weak password encryption and an insecure method of storage.
- CVE-2022-35720MEDIUMCVSS 2.3EG 5.52023-02-08
IBM Sterling External Authentication Server 6.1.0 and IBM Sterling Secure Proxy 6.0.3 uses weaker than expected cryptographic algorithms during installation that could allow a local attacker to decrypt sensitive information. IBM X-Force I…
- CVE-2022-36937CRITICALCVSS 9.8EG 9.82023-05-10
HHVM 4.172.0 and all prior versions use TLS 1.0 for secure connections when handling tls:// URLs in the stream extension. TLS1.0 has numerous published vulnerabilities and is deprecated. HHVM 4.153.4, 4.168.2, 4.169.2, 4.170.2, 4.171.1, 4.…
- CVE-2022-37177HIGHCVSS 7.5EG 7.52022-08-29
HireVue Hiring Platform V1.0 suffers from Use of a Broken or Risky Cryptographic Algorithm. NOTE: this is disputed by the vendor for multiple reasons, e.g., it is inconsistent with CVE ID assignment rules for cloud services, and no product…
- CVE-2022-38391HIGHCVSS 5.1EG 7.52022-12-20
IBM Spectrum Control 5.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 233982.
- CVE-2022-38493HIGHCVSS 7.5EG 7.52022-08-20
Rhonabwy 0.9.99 through 1.1.x before 1.1.7 doesn't check the RSA private key length before RSA-OAEP decryption. This allows attackers to cause a Denial of Service via a crafted JWE (JSON Web Encryption) token.
- CVE-2022-39237MEDIUMCVSS 6.3EG 6.32022-10-06
syslabs/sif is the Singularity Image Format (SIF) reference implementation. In versions prior to 2.8.1the `github.com/sylabs/sif/v2/pkg/integrity` package did not verify that the hash algorithm(s) used are cryptographically secure when ver…
- CVE-2022-40675HIGHCVSS 6.5EG 7.42023-02-16
Some cryptographic issues in Fortinet FortiNAC versions 9.4.0 through 9.4.1, 9.2.0 through 9.2.7, 9.1.0 through 9.1.8, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow an attacker to decr…
- CVE-2022-40722HIGHCVSS 7.7EG 7.72023-04-25
A misconfiguration of RSA padding implemented in the PingID Adapter for PingFederate to support Offline MFA with PingID mobile authenticators is vulnerable to pre-computed dictionary attacks, leading to a bypass of offline MFA.
- CVE-2022-43843MEDIUMCVSS 5.9EG 5.92023-12-14
IBM Spectrum Scale 5.1.5.0 through 5.1.5.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 239080.
- CVE-2022-43851MEDIUMCVSS 5.9EG 5.92025-04-14
IBM Aspera Console 3.4.0 through 3.4.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
- CVE-2022-43917HIGHCVSS 5.9EG 7.52023-01-26
IBM WebSphere Application Server 8.5 and 9.0 traditional container uses weaker than expected cryptographic keys that could allow an attacker to decrypt sensitive information. This affects only the containerized version of WebSphere Applic…
- CVE-2022-43934HIGHCVSS 6.5EG 7.52024-11-21
Brocade SANnav before Brocade SANnav 2.2.2 supports key exchange algorithms, which are considered weak on ports 24, 6514, 18023, 19094, and 19095.
- CVE-2022-43949MEDIUMCVSS 6.2EG 6.22023-06-13
A use of a broken or risky cryptographic algorithm [CWE-327] in Fortinet FortiSIEM before 6.7.1 allows a remote unauthenticated attacker to perform brute force attacks on GUI endpoints via taking advantage of outdated hashing methods.
- CVE-2022-45141CRITICALCVSS 9.8EG 9.82023-03-06
Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was disclosed by Microsoft on Nov 8 2022 and per RFC8429 it is assumed that rc4-hmac is weak, Vulnerable Samba Active Directory DCs will issue rc4-hmac encrypted tick…
- CVE-2022-45170MEDIUMCVSS 6.5EG 6.52023-04-14
An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Cryptographic Issue can occur under the /api/v1/vencrypt/decrypt/file endpoint. A malicious user, logged into a victim's account, is able to decipher a file without kno…
- CVE-2022-45195MEDIUMCVSS 5.3EG 5.32022-11-12
SimpleXMQ before 3.4.0, as used in SimpleX Chat before 4.2, does not apply a key derivation function to intended data, which can interfere with forward secrecy and can have other impacts if there is a compromise of a single private key. Th…
- CVE-2022-45858MEDIUMCVSS 4.2EG 4.22023-05-03
A use of a weak cryptographic algorithm vulnerability [CWE-327] in FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.0 all versions, 8.8.0 all versions, 8.7.0 all versions may increase the chances of an attacker to have access to sensitive in…
- CVE-2022-4610MEDIUMCVSS 1.9EG 5.52022-12-19
A vulnerability, which was classified as problematic, has been found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome. Affected by this issue is some unknown functionality. The manipulation leads to risky cryptogra…
- CVE-2022-46140MEDIUMCVSS 6.5EG 6.52022-12-13
Affected devices use a weak encryption scheme to encrypt the debug zip file. This could allow an authenticated attacker to decrypt the contents of the file and retrieve debug information about the system.
- CVE-2022-46832MEDIUMCVSS 6.5EG 6.52022-12-13
Use of a Broken or Risky Cryptographic Algorithm in SICK RFU62x firmware version < 2.21 allows a low-privileged remote attacker to decrypt the encrypted data if the user requested weak cipher suites to be used for encryption via the SSH in…
- CVE-2022-46833MEDIUMCVSS 6.5EG 6.52022-12-13
Use of a Broken or Risky Cryptographic Algorithm in SICK RFU63x firmware version < v2.21 allows a low-privileged remote attacker to decrypt the encrypted data if the user requested weak cipher suites to be used for encryption via the SSH i…
- CVE-2022-46834MEDIUMCVSS 6.5EG 6.52022-12-13
Use of a Broken or Risky Cryptographic Algorithm in SICK RFU65x firmware version < v2.21 allows a low-privileged remote attacker to decrypt the encrypted data if the user requested weak cipher suites to be used for encryption via the SSH i…
- CVE-2023-0296MEDIUMCVSS 5.3EG 5.32023-01-17
The Birthday attack against 64-bit block ciphers flaw (CVE-2016-2183) was reported for the health checks port (9979) on etcd grpc-proxy component. Even though the CVE-2016-2183 has been fixed in the etcd components, to enable periodic heal…
- CVE-2023-0452CRITICALCVSS 9.8EG 9.82023-01-26
Econolite EOS versions prior to 3.2.23 use a weak hash algorithm for encrypting privileged user credentials. A configuration file that is accessible without authentication uses MD5 hashes for encrypting credentials, including those of admi…
- CVE-2023-21115HIGHCVSS 8.8EG 8.82023-06-15
In btm_sec_encrypt_change of btm_sec.cc, there is a possible way to downgrade the link key type due to improperly used crypto. This could lead to paired device escalation of privilege with no additional execution privileges needed. User in…
- CVE-2023-21399HIGHCVSS 7.8EG 7.82023-07-13
there is a possible way to bypass cryptographic assurances due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- CVE-2023-22812HIGHCVSS 7.4EG 7.42023-03-24
SanDisk PrivateAccess versions prior to 6.4.9 support insecure TLS 1.0 and TLS 1.1 protocols which are susceptible to man-in-the-middle attacks thereby compromising confidentiality and integrity of data.
- CVE-2023-23040HIGHCVSS 7.5EG 7.52023-02-22
TP-Link router TL-WR940N V6 3.19.1 Build 180119 uses a deprecated MD5 algorithm to hash the admin password used for basic authentication.
- CVE-2023-23346MEDIUMCVSS 6.4EG 6.42023-08-09
HCL DRYiCE MyCloud is affected by the use of a broken cryptographic algorithm. An attacker can potentially compromise the confidentiality and integrity of sensitive information.
- CVE-2023-23347MEDIUMCVSS 6.4EG 6.42023-08-09
HCL DRYiCE iAutomate is affected by the use of a broken cryptographic algorithm. An attacker can potentially compromise the confidentiality and integrity of sensitive information.
- CVE-2023-23695MEDIUMCVSS 5.9EG 5.92023-02-17
Dell Secure Connect Gateway (SCG) version 5.14.00.12 contains a broken cryptographic algorithm vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by performing MitM attacks and let attackers obta…
- CVE-2023-26024MEDIUMCVSS 6.5EG 6.52023-12-01
IBM Planning Analytics on Cloud Pak for Data 4.0 could allow an attacker on a shared network to obtain sensitive information caused by insecure network communication. IBM X-Force ID: 247898.
- CVE-2023-26276MEDIUMCVSS 5.9EG 5.92023-06-27
IBM QRadar SIEM 7.5.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 248147.
- CVE-2023-27557MEDIUMCVSS 5.9EG 5.92023-04-28
IBM Counter Fraud Management for Safer Payments 6.1.0.00 through 6.1.1.02, 6.2.0.00 through 6.2.2.02, 6.3.0.00 through 6.3.1.02, 6.4.0.00 through 6.4.2.01, and 6.5.0.00 uses weaker than expected cryptographic algorithms that could allow an…
- CVE-2023-28006HIGHCVSS 7.0EG 7.02023-06-22
The OSD Bare Metal Server uses a cryptographic algorithm that is no longer considered sufficiently secure.
- CVE-2023-28043MEDIUMCVSS 6.5EG 6.52023-06-01
Dell SCG 5.14 contains an information disclosure vulnerability during the SRS to SCG upgrade path. A remote low privileged malicious user could potentially exploit this vulnerability to retrieve the plain text.
- CVE-2023-28053MEDIUMCVSS 5.3EG 5.32023-12-18
Dell NetWorker Virtual Edition versions 19.8 and below contain the use of deprecated cryptographic algorithms in the SSH component. A remote unauthenticated attacker could potentially exploit this vulnerability leading to some information…
- CVE-2023-28076MEDIUMCVSS 5.9EG 5.92023-05-16
CloudLink 7.1.2 and all prior versions contain a broken or risky cryptographic algorithm vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability leading to some information disclosure.
- CVE-2023-28244HIGHCVSS 8.1EG 8.12023-04-11
Windows Kerberos Elevation of Privilege Vulnerability
Map vulnerabilities like CWE-327 to your infrastructure
EchelonGraph correlates every CVE — across CWE-327 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →