CWE-330— Use of Insufficiently Random Values
334 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-330page 3 of 7
- CVE-2020-16271CRITICALCVSS 9.1EG 9.12020-08-03
The SRP-6a implementation in Kee Vault KeePassRPC before 1.12.0 generates insufficiently random numbers, which allows remote attackers to read and modify data in the KeePass database via a WebSocket connection.
- CVE-2020-1731CRITICALCVSS 9.1EG 9.12020-03-02
A flaw was found in all versions of the Keycloak operator, before version 8.0.2,(community only) where the operator generates a random admin password when installing Keycloak, however the password remains the same when deployed to the same…
- CVE-2020-17470MEDIUMCVSS 5.3EG 5.32020-12-11
An issue was discovered in FNET through 4.6.4. The code that initializes the DNS client interface structure does not set sufficiently random transaction IDs (they are always set to 1 in _fnet_dns_poll in fnet_dns.c). This significantly sim…
- CVE-2020-1759MEDIUMCVSS 6.4EG 6.42020-04-13
A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2 where, A nonce reuse vulnerability was discovered in the secure mode of the messenger v2 protocol, which can allow an attacker to forge auth ta…
- CVE-2020-1905LOWCVSS 3.3EG 3.32020-10-06
Media ContentProvider URIs used for opening attachments in other apps were generated sequentially prior to WhatsApp for Android v2.20.185, which could have allowed a malicious third party app chosen to open the file to guess the URIs for p…
- CVE-2020-2099HIGHCVSS 8.6EG 8.62020-01-29
Jenkins 2.213 and earlier, LTS 2.204.1 and earlier improperly reuses encryption key parameters in the Inbound TCP Agent Protocol/3, allowing unauthorized attackers with knowledge of agent names to obtain the connection secrets for those ag…
- CVE-2020-25705HIGHCVSS 7.4EG 7.42020-11-17
A flaw in ICMP packets in the Linux kernel may allow an attacker to quickly scan open UDP ports. This flaw allows an off-path remote attacker to effectively bypass source port UDP randomization. Software that relies on UDP source port rand…
- CVE-2020-26107HIGHCVSS 7.5EG 7.52020-09-25
cPanel before 88.0.3, upon an upgrade, establishes predictable PowerDNS API keys (SEC-561).
- CVE-2020-26550HIGHCVSS 7.5EG 7.52020-11-17
An issue was discovered in Aviatrix Controller before R5.3.1151. An encrypted file containing credentials to unrelated systems is protected by a three-character key.
- CVE-2020-27180HIGHCVSS 7.5EG 7.52020-10-27
konzept-ix publiXone before 2020.015 allows attackers to download files by iterating over the IXCopy fileID parameter.
- CVE-2020-27213HIGHCVSS 7.5EG 7.52023-10-10
An issue was discovered in Ethernut Nut/OS 5.1. The code that generates Initial Sequence Numbers (ISNs) for TCP connections derives the ISN from an insufficiently random source. As a result, an attacker may be able to determine the ISN of …
- CVE-2020-27264HIGHCVSS 8.8EG 8.82021-01-19
In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, the communication protocol of the insulin pump and its AnyDana-i and AnyDana-A mobile applications use deterministic keys, which allows unauthenticated, physically proxi…
- CVE-2020-27556MEDIUMCVSS 5.3EG 5.32020-11-17
A predictable device ID in BASETech GE-131 BT-1837836 firmware 20180921 allows unauthenticated remote attackers to connect to the device.
- CVE-2020-27630CRITICALCVSS 9.8EG 9.82023-10-10
In Silicon Labs uC/TCP-IP 3.6.0, TCP ISNs are improperly random.
- CVE-2020-27631CRITICALCVSS 9.8EG 9.82023-10-10
In Oryx CycloneTCP 1.9.6, TCP ISNs are improperly random.
- CVE-2020-27633CRITICALCVSS 9.1EG 9.12023-10-10
In FNET 4.6.3, TCP ISNs are improperly random.
- CVE-2020-27634CRITICALCVSS 9.1EG 9.12023-10-10
In Contiki 4.5, TCP ISNs are improperly random.
- CVE-2020-27635CRITICALCVSS 9.1EG 9.12023-10-10
In PicoTCP 1.7.0, TCP ISNs are improperly random.
- CVE-2020-27636CRITICALCVSS 9.1EG 9.12023-10-10
In Microchip MPLAB Net 3.6.1, TCP ISNs are improperly random.
- CVE-2020-27743CRITICALCVSS 9.8EG 9.82020-10-26
libtac in pam_tacplus through 1.5.1 lacks a check for a failure of RAND_bytes()/RAND_pseudo_bytes(). This could lead to use of a non-random/predictable session_id.
- CVE-2020-35163MEDIUMCVSS 5.3EG 9.82022-07-11
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain a Use of Insufficiently Random Values Vulnerability.
- CVE-2020-35685CRITICALCVSS 9.1EG 9.12021-08-19
An issue was discovered in HCC Nichestack 3.0. The code that generates Initial Sequence Numbers (ISNs) for TCP connections derives the ISN from an insufficiently random source. As a result, an attacker may be able to determine the ISN of c…
- CVE-2020-35926CRITICALCVSS 9.8EG 9.82020-12-31
An issue was discovered in the nanorand crate before 0.5.1 for Rust. It caused any random number generator (even ChaCha) to return all zeroes because integer truncation was mishandled.
- CVE-2020-36252MEDIUMCVSS 6.8EG 5.72021-02-19
ownCloud Server 10.x before 10.3.1 allows an attacker, who has one outgoing share from a victim, to access any version of any file by sending a request for a predictable ID number.
- CVE-2020-36732MEDIUMCVSS 5.3EG 5.32023-06-12
The crypto-js package before 3.2.1 for Node.js generates random numbers by concatenating the string "0." with an integer, which makes the output more predictable than necessary.
- CVE-2020-4188MEDIUMCVSS 5.3EG 5.32020-06-23
IBM Security Guardium 10.6 and 11.1 may use insufficiently random numbers or values in a security context that depends on unpredictable numbers. IBM X-Force ID: 174807.
- CVE-2020-5365MEDIUMCVSS 5.3EG 5.32020-05-20
Dell EMC Isilon versions 8.2.2 and earlier contain a remotesupport vulnerability. The pre-configured support account, remotesupport, is bundled in the Dell EMC Isilon OneFS installation. This account is used for diagnostics and other suppo…
- CVE-2020-5408MEDIUMCVSS 6.5EG 6.52020-05-14
Spring Security versions 5.3.x prior to 5.3.2, 5.2.x prior to 5.2.4, 5.1.x prior to 5.1.10, 5.0.x prior to 5.0.16 and 4.2.x prior to 4.2.16 use a fixed null initialization vector with CBC Mode in the implementation of the queryable text en…
- CVE-2020-7241HIGHCVSS 7.5EG 7.52020-01-20
The WP Database Backup plugin through 5.5 for WordPress stores downloads by default locally in the directory wp-content/uploads/db-backup/. This might allow attackers to read ZIP archives by guessing random ID numbers, guessing date string…
- CVE-2020-7548CRITICALCVSS 9.8EG 9.82020-12-01
A CWE-330 - Use of Insufficiently Random Values vulnerability exists in Smartlink, PowerTag, and Wiser Series Gateways (see security notification for version information) that could allow unauthorized users to login.
- CVE-2020-8631MEDIUMCVSS 5.5EG 5.52020-02-05
cloud-init through 19.4 relies on Mersenne Twister for a random password, which makes it easier for attackers to predict passwords, because rand_str in cloudinit/util.py calls the random.choice function.
- CVE-2020-8792MEDIUMCVSS 5.3EG 5.32020-05-04
The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) has an information-exposure issue. In the mobile app, an attempt to add an already-bound lock by its barcode reveals the email address of the account to wh…
- CVE-2020-8988MEDIUMCVSS 5.9EG 5.92020-02-13
The Voatz application 2020-01-01 for Android allows only 100 million different PINs, which makes it easier for attackers (after using root access to make a copy of the local database) to discover login credentials and voting history via an…
- CVE-2020-9449HIGHCVSS 8.8EG 8.82020-02-28
An insecure random number generation vulnerability in BlaB! AX, BlaB! AX Pro, BlaB! WS (client), and BlaB! WS Pro (client) version 19.11 allows an attacker (with a guest or user session cookie) to escalate privileges by retrieving the cook…
- CVE-2020-9502CRITICALCVSS 9.8EG 9.82020-05-13
Some Dahua products with Build time before December 2019 have Session ID predictable vulnerabilities. During normal user access, an attacker can use the predicted Session ID to construct a data packet to attack the device.
- CVE-2021-0375MEDIUMCVSS 5.5EG 5.52021-03-10
In onPackageModified of VoiceInteractionManagerService.java, there is a possible change of default applications due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges need…
- CVE-2021-0417MEDIUMCVSS 5.5EG 5.52021-08-18
In memory management driver, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Pat…
- CVE-2021-0466HIGHCVSS 7.5EG 7.52021-06-11
In startIpClient of ClientModeImpl.java, there is a possible identifier which could be used to track a device. This could lead to remote information disclosure to a proximal attacker, with no additional execution privileges needed. User in…
- CVE-2021-20322HIGHCVSS 7.4EG 7.42022-02-18
A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Linux kernel functionality was found to allow the ability to quickly scan open UDP ports. This flaw allows an off-path remote user to effectiv…
- CVE-2021-21352MEDIUMCVSS 6.8EG 6.82021-03-03
Anuko Time Tracker is an open source, web-based time tracking application written in PHP. In TimeTracker before version 1.19.24.5415 tokens used in password reset feature in Time Tracker are based on system time and, therefore, are predict…
- CVE-2021-21729MEDIUMCVSS 6.5EG 6.52021-04-13
Some ZTE products have CSRF vulnerability. Because some pages lack CSRF random value verification, attackers could perform illegal authorization operations by constructing messages.This affects: ZXHN H168N V3.5.0_EG1T5_TE, V2.5.5, ZXHN H10…
- CVE-2021-22038HIGHCVSS 8.8EG 8.82021-10-29
On Windows, the uninstaller binary copies itself to a fixed temporary location, which is then executed (the originally called uninstaller exits, so it does not block the installation directory). This temporary location is not randomized an…
- CVE-2021-22309HIGHCVSS 7.5EG 7.52021-03-22
There is insecure algorithm vulnerability in Huawei products. A module uses less random input in a secure mechanism. Attackers can exploit this vulnerability by brute forcing to obtain sensitive message. This can lead to information leak. …
- CVE-2021-22968HIGHCVSS 7.2EG 7.22021-11-19
A bypass of adding remote files in Concrete CMS (previously concrete5) File Manager leads to remote code execution in Concrete CMS (concrete5) versions 8.5.6 and below.The external file upload feature stages files in the public directory e…
- CVE-2021-23020MEDIUMCVSS 5.5EG 5.52021-06-01
The NAAS 3.x before 3.10.0 API keys were generated using an insecure pseudo-random string and hashing algorithm which could lead to predictable keys.
- CVE-2021-23451MEDIUMCVSS 6.5EG 6.52022-07-25
The package otp-generator before 3.0.0 are vulnerable to Insecure Randomness due to insecure generation of random one-time passwords, which may allow a brute-force attack.
- CVE-2021-24998HIGHCVSS 7.5EG 7.52021-12-27
The Simple JWT Login WordPress plugin before 3.3.0 can be used to create new WordPress user accounts with a randomly generated password. The password is generated using the str_shuffle PHP function that "does not generate cryptographicall…
- CVE-2021-25375MEDIUMCVSS 6.5EG 6.52021-04-09
Using predictable index for attachments in Samsung Email prior to version 6.1.41.0 allows remote attackers to get attachments of another emails when users open the malicious attachment.
- CVE-2021-25444MEDIUMCVSS 5.5EG 5.52021-08-05
An IV reuse vulnerability in keymaster prior to SMR AUG-2021 Release 1 allows decryption of custom keyblob with privileged process.
- CVE-2021-25677MEDIUMCVSS 5.3EG 5.32021-04-22
A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V3.5.5), APOGEE PXC Compact (P2 Ethernet) (All versions < V2.8.20), APOGEE PXC Modular (BACnet) (All versions < V3.5.5), APOGEE PXC Modular (P2 Ethernet) (A…
Map vulnerabilities like CWE-330 to your infrastructure
EchelonGraph correlates every CVE — across CWE-330 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →