CWE-330— Use of Insufficiently Random Values
The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.— MITRE CWE catalog
382 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-330page 3 of 8
- CVE-2019-8919HIGHCVSS 7.5EG 7.52019-02-18
The seadroid (aka Seafile Android Client) application through 2.2.13 for Android always uses the same Initialization Vector (IV) with Cipher Block Chaining (CBC) Mode to encrypt private data, making it easier to conduct chosen-plaintext at…
- CVE-2019-9102HIGHCVSS 8.8EG 8.82020-03-11
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. A predictable mechanism of generating tokens allows remote attacker…
- CVE-2019-9860HIGHCVSS 7.5EG 7.52019-03-27
Due to unencrypted signal communication and predictability of rolling codes, an attacker can "desynchronize" an ABUS Secvest wireless remote control (FUBE50014 or FUBE50015) relative to its controlled Secvest wireless alarm system FUAA5000…
- CVE-2019-9863CRITICALCVSS 9.8EG 9.82019-03-27
Due to the use of an insecure algorithm for rolling codes in the ABUS Secvest wireless alarm system FUAA50000 3.01.01 and its remote controls FUBE50014 and FUBE50015, an attacker is able to predict valid future rolling codes, and can thus …
- CVE-2019-9898CRITICALCVSS 9.8EG 9.82019-03-21
Potential recycling of random numbers used in cryptography exists within PuTTY before 0.71.
- CVE-2020-0407MEDIUMCVSS 4.4EG 4.42020-09-17
In various functions in fscrypt_ice.c and related files in some implementations of f2fs encryption that use encryption hardware which only supports 32-bit IVs (Initialization Vectors), 64-bit IVs are used and later are truncated to 32 bits…
- CVE-2020-0644HIGHCVSS 7.8EG 7.82020-01-14
An elevation of privilege vulnerability exists when Microsoft Windows implements predictable memory section names, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0635.
- CVE-2020-10274HIGHCVSS 7.1EG 7.12020-06-24
The access tokens for the REST API are directly derived (sha256 and base64 encoding) from the publicly available default credentials from the Control Dashboard (refer to CVE-2020-10270 for related flaws). This flaw in combination with CVE-…
- CVE-2020-10729MEDIUMCVSS 5.5EG 5.52021-05-27
A flaw was found in the use of insufficiently random values in Ansible. Two random password lookups of the same length generate the equal value as the template caching action for the same file since no re-evaluation happens. The highest th…
- CVE-2020-10870MEDIUMCVSS 5.5EG 5.52020-03-23
Zim through 0.72.1 creates temporary directories with predictable names. A malicious user could predict and create Zim's temporary directories and prevent other users from being able to start Zim, resulting in a denial of service.
- CVE-2020-11501HIGHCVSS 7.4EG 7.42020-04-03
GnuTLS 3.6.x before 3.6.13 uses incorrect cryptography for DTLS. The earliest affected version is 3.6.3 (2018-07-16) because of an error in a 2017-10-06 commit. The DTLS client always uses 32 '\0' bytes instead of a random value, and thus …
- CVE-2020-11551HIGHCVSS 8.8EG 8.82020-05-18
An issue was discovered on NETGEAR Orbi Tri-Band Business WiFi Add-on Satellite (SRS60) AC3000 V2.5.1.106, Outdoor Satellite (RBS50Y) V2.5.1.106, and Pro Tri-Band Business WiFi Router (SRR60) AC3000 V2.5.1.106. The administrative SOAP inte…
- CVE-2020-11585MEDIUMCVSS 4.3EG 4.32020-04-06
There is an information disclosure issue in DNN (formerly DotNetNuke) 9.5 within the built-in Activity-Feed/Messaging/Userid/ Message Center module. A registered user is able to enumerate any file in the Admin File Manager (other than ones…
- CVE-2020-11877HIGHCVSS 7.5EG 7.52020-04-17
airhost.exe in Zoom Client for Meetings 4.6.11 uses 3423423432325249 as the Initialization Vector (IV) for AES-256 CBC encryption. NOTE: the vendor states that this IV is used only within unreachable code
- CVE-2020-11901CRITICALCVSS 9.0EG 9.02020-06-17
The Treck TCP/IP stack before 6.0.1.66 allows Remote Code execution via a single invalid DNS response.
- CVE-2020-12270MEDIUMCVSS 6.5EG 6.52020-04-27
React Native Bluetooth Scan in Bluezone 1.0.0 uses six-character alphanumeric IDs, which might make it easier for remote attackers to interfere with COVID-19 contact tracing by using many IDs. NOTE: the vendor disputes the relevance of thi…
- CVE-2020-12712HIGHCVSS 7.5EG 7.52020-06-11
A vulnerability based on insecure user/password encryption in the JOE (job editor) component of SOS JobScheduler 1.12 and 1.13 allows attackers to decrypt the user/password that is optionally stored with a user's profile.
- CVE-2020-12858HIGHCVSS 7.5EG 7.52020-05-18
Non-reinitialisation of random data in the advertising payload in COVIDSafe v1.0.15 and v1.0.16 allows a remote attacker to re-identify Android devices running COVIDSafe by scanning for their advertising beacons.
- CVE-2020-13304LOWCVSS 3.8EG 3.82020-09-14
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Same 2 factor Authentication secret code was generated which resulted an attacker to maintain access under certain conditions.
- CVE-2020-13817HIGHCVSS 7.4EG 7.42020-06-04
ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows remote attackers to cause a denial of service (daemon exit or system time change) by predicting transmit timestamps for use in spoofed packets. The victim must be relying on unaut…
- CVE-2020-13860HIGHCVSS 7.5EG 7.52021-02-01
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. The one-time password algorithm for the undocumented system account mofidev generates a predictable six-digit password.
- CVE-2020-14422MEDIUMCVSS 5.9EG 5.92020-06-18
Lib/ipaddress.py in Python through 3.8.3 improperly computes hash values in the IPv4Interface and IPv6Interface classes, which might allow a remote attacker to cause a denial of service if an application is affected by the performance of a…
- CVE-2020-14423MEDIUMCVSS 5.3EG 5.32020-06-18
Convos before 4.20 does not properly generate a random secret in Core/Settings.pm and Util.pm. This leads to a predictable CONVOS_LOCAL_SECRET value, affecting password resets and invitations.
- CVE-2020-1472CRITICALCVSS 10.0EG 10.0⚠ KEV2020-08-17
An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successfully exploited the vu…
- CVE-2020-15023MEDIUMCVSS 5.9EG 5.92020-12-11
Askey AP5100W devices through AP5100W_Dual_SIG_1.01.097 are affected by WPS PIN offline brute-force cracking. This arises because of issues with the random number selection for the Diffie-Hellman exchange. By capturing an attempted (and ev…
- CVE-2020-16166LOWCVSS 3.7EG 3.72020-07-30
The Linux kernel through 5.7.11 allows remote attackers to make observations that help to obtain sensitive information about the internal state of the network RNG, aka CID-f227e3ec3b5c. This is related to drivers/char/random.c and kernel/t…
- CVE-2020-16271CRITICALCVSS 9.1EG 9.12020-08-03
The SRP-6a implementation in Kee Vault KeePassRPC before 1.12.0 generates insufficiently random numbers, which allows remote attackers to read and modify data in the KeePass database via a WebSocket connection.
- CVE-2020-1731CRITICALCVSS 9.1EG 9.12020-03-02
A flaw was found in all versions of the Keycloak operator, before version 8.0.2,(community only) where the operator generates a random admin password when installing Keycloak, however the password remains the same when deployed to the same…
- CVE-2020-17470MEDIUMCVSS 5.3EG 5.32020-12-11
An issue was discovered in FNET through 4.6.4. The code that initializes the DNS client interface structure does not set sufficiently random transaction IDs (they are always set to 1 in _fnet_dns_poll in fnet_dns.c). This significantly sim…
- CVE-2020-1759MEDIUMCVSS 6.4EG 6.42020-04-13
A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2 where, A nonce reuse vulnerability was discovered in the secure mode of the messenger v2 protocol, which can allow an attacker to forge auth ta…
- CVE-2020-1905LOWCVSS 3.3EG 3.32020-10-06
Media ContentProvider URIs used for opening attachments in other apps were generated sequentially prior to WhatsApp for Android v2.20.185, which could have allowed a malicious third party app chosen to open the file to guess the URIs for p…
- CVE-2020-2099HIGHCVSS 8.6EG 8.62020-01-29
Jenkins 2.213 and earlier, LTS 2.204.1 and earlier improperly reuses encryption key parameters in the Inbound TCP Agent Protocol/3, allowing unauthorized attackers with knowledge of agent names to obtain the connection secrets for those ag…
- CVE-2020-25705HIGHCVSS 7.4EG 7.42020-11-17
A flaw in ICMP packets in the Linux kernel may allow an attacker to quickly scan open UDP ports. This flaw allows an off-path remote attacker to effectively bypass source port UDP randomization. Software that relies on UDP source port rand…
- CVE-2020-26107HIGHCVSS 7.5EG 7.52020-09-25
cPanel before 88.0.3, upon an upgrade, establishes predictable PowerDNS API keys (SEC-561).
- CVE-2020-26550HIGHCVSS 7.5EG 7.52020-11-17
An issue was discovered in Aviatrix Controller before R5.3.1151. An encrypted file containing credentials to unrelated systems is protected by a three-character key.
- CVE-2020-27180HIGHCVSS 7.5EG 7.52020-10-27
konzept-ix publiXone before 2020.015 allows attackers to download files by iterating over the IXCopy fileID parameter.
- CVE-2020-27213HIGHCVSS 7.5EG 7.52023-10-10
An issue was discovered in Ethernut Nut/OS 5.1. The code that generates Initial Sequence Numbers (ISNs) for TCP connections derives the ISN from an insufficiently random source. As a result, an attacker may be able to determine the ISN of …
- CVE-2020-27264HIGHCVSS 8.8EG 8.82021-01-19
In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, the communication protocol of the insulin pump and its AnyDana-i and AnyDana-A mobile applications use deterministic keys, which allows unauthenticated, physically proxi…
- CVE-2020-27556MEDIUMCVSS 5.3EG 5.32020-11-17
A predictable device ID in BASETech GE-131 BT-1837836 firmware 20180921 allows unauthenticated remote attackers to connect to the device.
- CVE-2020-27630CRITICALCVSS 9.8EG 9.82023-10-10
In Silicon Labs uC/TCP-IP 3.6.0, TCP ISNs are improperly random.
- CVE-2020-27631CRITICALCVSS 9.8EG 9.82023-10-10
In Oryx CycloneTCP 1.9.6, TCP ISNs are improperly random.
- CVE-2020-27633CRITICALCVSS 9.1EG 9.12023-10-10
In FNET 4.6.3, TCP ISNs are improperly random.
- CVE-2020-27634CRITICALCVSS 9.1EG 9.12023-10-10
In Contiki 4.5, TCP ISNs are improperly random.
- CVE-2020-27635CRITICALCVSS 9.1EG 9.12023-10-10
In PicoTCP 1.7.0, TCP ISNs are improperly random.
- CVE-2020-27636CRITICALCVSS 9.1EG 9.12023-10-10
In Microchip MPLAB Net 3.6.1, TCP ISNs are improperly random.
- CVE-2020-27743CRITICALCVSS 9.8EG 9.82020-10-26
libtac in pam_tacplus through 1.5.1 lacks a check for a failure of RAND_bytes()/RAND_pseudo_bytes(). This could lead to use of a non-random/predictable session_id.
- CVE-2020-35163CRITICALCVSS 5.3EG 9.82022-07-11
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain a Use of Insufficiently Random Values Vulnerability.
- CVE-2020-35685CRITICALCVSS 9.1EG 9.12021-08-19
An issue was discovered in HCC Nichestack 3.0. The code that generates Initial Sequence Numbers (ISNs) for TCP connections derives the ISN from an insufficiently random source. As a result, an attacker may be able to determine the ISN of c…
- CVE-2020-35926CRITICALCVSS 9.8EG 9.82020-12-31
An issue was discovered in the nanorand crate before 0.5.1 for Rust. It caused any random number generator (even ChaCha) to return all zeroes because integer truncation was mishandled.
- CVE-2020-36252MEDIUMCVSS 6.8EG 6.82021-02-19
ownCloud Server 10.x before 10.3.1 allows an attacker, who has one outgoing share from a victim, to access any version of any file by sending a request for a predictable ID number.
Map vulnerabilities like CWE-330 to your infrastructure
EchelonGraph correlates every CVE — across CWE-330 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →