CWE-330— Use of Insufficiently Random Values
The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.— MITRE CWE catalog
382 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-330page 4 of 8
- CVE-2020-36732MEDIUMCVSS 5.3EG 5.32023-06-12
The crypto-js package before 3.2.1 for Node.js generates random numbers by concatenating the string "0." with an integer, which makes the output more predictable than necessary.
- CVE-2020-4188MEDIUMCVSS 5.3EG 5.32020-06-23
IBM Security Guardium 10.6 and 11.1 may use insufficiently random numbers or values in a security context that depends on unpredictable numbers. IBM X-Force ID: 174807.
- CVE-2020-5365MEDIUMCVSS 5.3EG 5.32020-05-20
Dell EMC Isilon versions 8.2.2 and earlier contain a remotesupport vulnerability. The pre-configured support account, remotesupport, is bundled in the Dell EMC Isilon OneFS installation. This account is used for diagnostics and other suppo…
- CVE-2020-5408MEDIUMCVSS 6.5EG 6.52020-05-14
Spring Security versions 5.3.x prior to 5.3.2, 5.2.x prior to 5.2.4, 5.1.x prior to 5.1.10, 5.0.x prior to 5.0.16 and 4.2.x prior to 4.2.16 use a fixed null initialization vector with CBC Mode in the implementation of the queryable text en…
- CVE-2020-7241HIGHCVSS 7.5EG 7.52020-01-20
The WP Database Backup plugin through 5.5 for WordPress stores downloads by default locally in the directory wp-content/uploads/db-backup/. This might allow attackers to read ZIP archives by guessing random ID numbers, guessing date string…
- CVE-2020-7548CRITICALCVSS 9.8EG 9.82020-12-01
A CWE-330 - Use of Insufficiently Random Values vulnerability exists in Smartlink, PowerTag, and Wiser Series Gateways (see security notification for version information) that could allow unauthorized users to login.
- CVE-2020-8631MEDIUMCVSS 5.5EG 5.52020-02-05
cloud-init through 19.4 relies on Mersenne Twister for a random password, which makes it easier for attackers to predict passwords, because rand_str in cloudinit/util.py calls the random.choice function.
- CVE-2020-8792MEDIUMCVSS 5.3EG 5.32020-05-04
The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) has an information-exposure issue. In the mobile app, an attempt to add an already-bound lock by its barcode reveals the email address of the account to wh…
- CVE-2020-8988MEDIUMCVSS 5.9EG 5.92020-02-13
The Voatz application 2020-01-01 for Android allows only 100 million different PINs, which makes it easier for attackers (after using root access to make a copy of the local database) to discover login credentials and voting history via an…
- CVE-2020-9449HIGHCVSS 8.8EG 8.82020-02-28
An insecure random number generation vulnerability in BlaB! AX, BlaB! AX Pro, BlaB! WS (client), and BlaB! WS Pro (client) version 19.11 allows an attacker (with a guest or user session cookie) to escalate privileges by retrieving the cook…
- CVE-2020-9502CRITICALCVSS 9.8EG 9.82020-05-13
Some Dahua products with Build time before December 2019 have Session ID predictable vulnerabilities. During normal user access, an attacker can use the predicted Session ID to construct a data packet to attack the device.
- CVE-2021-0375MEDIUMCVSS 5.5EG 5.52021-03-10
In onPackageModified of VoiceInteractionManagerService.java, there is a possible change of default applications due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges need…
- CVE-2021-0417MEDIUMCVSS 5.5EG 5.52021-08-18
In memory management driver, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Pat…
- CVE-2021-0466HIGHCVSS 7.5EG 7.52021-06-11
In startIpClient of ClientModeImpl.java, there is a possible identifier which could be used to track a device. This could lead to remote information disclosure to a proximal attacker, with no additional execution privileges needed. User in…
- CVE-2021-20322HIGHCVSS 7.4EG 7.42022-02-18
A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Linux kernel functionality was found to allow the ability to quickly scan open UDP ports. This flaw allows an off-path remote user to effectiv…
- CVE-2021-21352MEDIUMCVSS 6.8EG 6.82021-03-03
Anuko Time Tracker is an open source, web-based time tracking application written in PHP. In TimeTracker before version 1.19.24.5415 tokens used in password reset feature in Time Tracker are based on system time and, therefore, are predict…
- CVE-2021-21729MEDIUMCVSS 6.5EG 6.52021-04-13
Some ZTE products have CSRF vulnerability. Because some pages lack CSRF random value verification, attackers could perform illegal authorization operations by constructing messages.This affects: ZXHN H168N V3.5.0_EG1T5_TE, V2.5.5, ZXHN H10…
- CVE-2021-22038HIGHCVSS 8.8EG 8.82021-10-29
On Windows, the uninstaller binary copies itself to a fixed temporary location, which is then executed (the originally called uninstaller exits, so it does not block the installation directory). This temporary location is not randomized an…
- CVE-2021-22309HIGHCVSS 7.5EG 7.52021-03-22
There is insecure algorithm vulnerability in Huawei products. A module uses less random input in a secure mechanism. Attackers can exploit this vulnerability by brute forcing to obtain sensitive message. This can lead to information leak. …
- CVE-2021-22968HIGHCVSS 7.2EG 7.22021-11-19
A bypass of adding remote files in Concrete CMS (previously concrete5) File Manager leads to remote code execution in Concrete CMS (concrete5) versions 8.5.6 and below.The external file upload feature stages files in the public directory e…
- CVE-2021-23020MEDIUMCVSS 5.5EG 5.52021-06-01
The NAAS 3.x before 3.10.0 API keys were generated using an insecure pseudo-random string and hashing algorithm which could lead to predictable keys.
- CVE-2021-23451MEDIUMCVSS 6.5EG 6.52022-07-25
The package otp-generator before 3.0.0 are vulnerable to Insecure Randomness due to insecure generation of random one-time passwords, which may allow a brute-force attack.
- CVE-2021-24998HIGHCVSS 7.5EG 7.52021-12-27
The Simple JWT Login WordPress plugin before 3.3.0 can be used to create new WordPress user accounts with a randomly generated password. The password is generated using the str_shuffle PHP function that "does not generate cryptographicall…
- CVE-2021-25375MEDIUMCVSS 6.5EG 6.52021-04-09
Using predictable index for attachments in Samsung Email prior to version 6.1.41.0 allows remote attackers to get attachments of another emails when users open the malicious attachment.
- CVE-2021-25444MEDIUMCVSS 5.5EG 5.52021-08-05
An IV reuse vulnerability in keymaster prior to SMR AUG-2021 Release 1 allows decryption of custom keyblob with privileged process.
- CVE-2021-25677MEDIUMCVSS 5.3EG 5.32021-04-22
A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V3.5.5), APOGEE PXC Compact (P2 Ethernet) (All versions < V2.8.20), APOGEE PXC Modular (BACnet) (All versions < V3.5.5), APOGEE PXC Modular (P2 Ethernet) (A…
- CVE-2021-26098MEDIUMCVSS 5.3EG 5.32021-08-04
An instance of small space of random values in the RPC API of FortiSandbox before 4.0.0 may allow an attacker in possession of a few information pieces about the state of the device to possibly predict valid session IDs.
- CVE-2021-26322HIGHCVSS 7.5EG 7.52021-11-16
Persistent platform private key may not be protected with a random IV leading to a potential “two time pad attack”.
- CVE-2021-26407MEDIUMCVSS 5.5EG 5.52023-01-11
A randomly generated Initialization Vector (IV) may lead to a collision of IVs with the same key potentially resulting in information disclosure.
- CVE-2021-26726HIGHCVSS 8.8EG 8.82022-02-16
A remote code execution vulnerability affecting a Valmet DNA service listening on TCP port 1517, allows an attacker to execute commands with SYSTEM privileges This issue affects: Valmet DNA versions from Collection 2012 until Collection 20…
- CVE-2021-26909MEDIUMCVSS 3.7EG 5.32021-04-23
Automox Agent prior to version 31 uses an insufficiently protected S3 bucket endpoint for storing sensitive files, which could be brute-forced by an attacker to subvert an organization's security program. The issue has since been fixed in …
- CVE-2021-27200CRITICALCVSS 9.8EG 9.82021-06-11
In WoWonder 3.0.4, remote attackers can take over any account due to the weak cryptographic algorithm in recover.php. The code parameter is easily predicted from the time of day.
- CVE-2021-27393MEDIUMCVSS 5.3EG 5.32021-04-22
A vulnerability has been identified in Nucleus NET (All versions), Nucleus ReadyStart V3 (All versions < V2013.08), Nucleus Source Code (Versions including affected DNS modules). The DNS client does not properly randomize UDP port numbers …
- CVE-2021-27499MEDIUMCVSS 5.9EG 5.92021-08-02
Ypsomed mylife Cloud, mylife Mobile Application, Ypsomed mylife Cloud: All versions prior to 1.7.2, Ypsomed mylife App: All versions prior to 1.7.5,The application layer encryption of the communication protocol between the Ypsomed mylife A…
- CVE-2021-27884MEDIUMCVSS 5.1EG 5.12021-03-01
Weak JSON Web Token (JWT) signing secret generation in YMFE YApi through 1.9.2 allows recreation of other users' JWT tokens. This occurs because Math.random in Node.js is used.
- CVE-2021-28024CRITICALCVSS 9.8EG 9.82021-11-08
Unauthorized system access in the login form in ServiceTonic Helpdesk software version < 9.0.35937 allows attacker to login without using a password.
- CVE-2021-28055MEDIUMCVSS 6.5EG 6.52021-04-15
An issue was discovered in Centreon-Web in Centreon Platform 20.10.0. The anti-CSRF token generation is predictable, which might allow CSRF attacks that add an admin user.
- CVE-2021-28099MEDIUMCVSS 4.4EG 4.42021-03-23
In Netflix OSS Hollow, since the Files.exists(parent) is run before creating the directories, an attacker can pre-create these directories with wide permissions. Additionally, since an insecure source of randomness is used, the file names …
- CVE-2021-28674MEDIUMCVSS 5.4EG 5.42021-07-30
The node management page in SolarWinds Orion Platform before 2020.2.5 HF1 allows an attacker to create or delete a node (outside of the attacker's perimeter) via an account with write permissions. This occurs because node IDs are predictab…
- CVE-2021-29480MEDIUMCVSS 4.4EG 4.42021-06-29
Ratpack is a toolkit for creating web applications. In versions prior to 1.9.0, the client side session module uses the application startup time as the signing key by default. This means that if an attacker can determine this time, and if …
- CVE-2021-29499HIGHCVSS 7.5EG 7.52021-05-07
SIF is an open source implementation of the Singularity Container Image Format. The `siftool new` command and func siftool.New() produce predictable UUID identifiers due to insecure randomness in the version of the `github.com/satori/go.uu…
- CVE-2021-31228HIGHCVSS 7.5EG 7.52021-08-19
An issue was discovered in HCC embedded InterNiche 4.0.1. This vulnerability allows the attacker to predict a DNS query's source port in order to send forged DNS response packets that will be accepted as valid answers to the DNS client's r…
- CVE-2021-32791MEDIUMCVSS 5.9EG 5.92021-07-26
mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. In mod_auth_openidc before version 2.4.9,…
- CVE-2021-3446MEDIUMCVSS 5.5EG 5.52021-03-25
A flaw was found in libtpms in versions before 0.8.2. The commonly used integration of libtpms with OpenSSL contained a vulnerability related to the returned IV (initialization vector) when certain symmetric ciphers were used. Instead of r…
- CVE-2021-34646CRITICALCVSS 9.8EG 9.82021-08-30
Versions up to, and including, 5.4.3, of the Booster for WooCommerce WordPress plugin are vulnerable to authentication bypass via the process_email_verification function due to a random token generation weakness in the reset_and_mail_activ…
- CVE-2021-36166CRITICALCVSS 9.8EG 9.82022-03-01
An improper authentication vulnerability in FortiMail before 7.0.1 may allow a remote attacker to efficiently guess one administrative account's authentication token by means of the observation of certain system's properties.
- CVE-2021-36294CRITICALCVSS 9.8EG 9.82022-01-25
Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authentication bypass vulnerability. A remote unauthenticated attacker may exploit this vulnerability by forging a cookie to login as any user.
- CVE-2021-3689HIGHCVSS 7.5EG 7.52021-08-10
yii2 is vulnerable to Use of Predictable Algorithm in Random Number Generator
- CVE-2021-3692MEDIUMCVSS 5.3EG 5.32021-08-10
yii2 is vulnerable to Use of Predictable Algorithm in Random Number Generator
- CVE-2021-37186MEDIUMCVSS 5.4EG 5.42021-09-14
A vulnerability has been identified in LOGO! CMR2020 (All versions < V2.2), LOGO! CMR2040 (All versions < V2.2), SIMATIC RTU3010C (All versions < V4.0.9), SIMATIC RTU3030C (All versions < V4.0.9), SIMATIC RTU3031C (All versions < V4.0.9), …
Map vulnerabilities like CWE-330 to your infrastructure
EchelonGraph correlates every CVE — across CWE-330 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →