CWE-330— Use of Insufficiently Random Values
334 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-330page 5 of 7
- CVE-2022-25047MEDIUMCVSS 5.9EG 5.92022-07-07
The password reset token in CWP v0.9.8.1126 is generated using known or predictable values.
- CVE-2022-25752CRITICALCVSS 9.8EG 9.82022-04-12
A vulnerability has been identified in SCALANCE X302-7 EEC (230V), SCALANCE X302-7 EEC (230V, coated), SCALANCE X302-7 EEC (24V), SCALANCE X302-7 EEC (24V, coated), SCALANCE X302-7 EEC (2x 230V), SCALANCE X302-7 EEC (2x 230V, coated), SCAL…
- CVE-2022-26071HIGHCVSS 7.4EG 7.52022-05-05
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, a flaw in the way reply ICMP packets are limited …
- CVE-2022-26080MEDIUMCVSS 6.3EG 4.32023-03-16
Use of Insufficiently Random Values vulnerability in ABB Pulsar Plus System Controller NE843_S, ABB Infinity DC Power Plant.This issue affects Pulsar Plus System Controller NE843_S : comcode 150042936; Infinity DC Power Plant: H5692448 G10…
- CVE-2022-26306HIGHCVSS 7.5EG 7.52022-07-25
LibreOffice supports the storage of passwords for web connections in the user’s configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in LibreOffice existed where the required in…
- CVE-2022-26317MEDIUMCVSS 6.5EG 6.52022-03-08
A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.29). When returning the result of a completed Microflow execution call the affected framework does not correctly verify, if the request was ini…
- CVE-2022-26320CRITICALCVSS 9.1EG 9.12022-03-14
The Rambus SafeZone Basic Crypto Module before 10.4.0, as used in certain Fujifilm (formerly Fuji Xerox) devices before 2022-03-01, Canon imagePROGRAF and imageRUNNER devices through 2022-03-14, and potentially many other devices, generate…
- CVE-2022-26647HIGHCVSS 8.8EG 9.82022-07-12
A vulnerability has been identified in SCALANCE X200-4P IRT (All versions < V5.5.2), SCALANCE X201-3P IRT (All versions < V5.5.2), SCALANCE X201-3P IRT PRO (All versions < V5.5.2), SCALANCE X202-2IRT (All versions < V5.5.2), SCALANCE X202-…
- CVE-2022-26851CRITICALCVSS 9.1EG 9.12022-04-08
Dell PowerScale OneFS, 8.2.2-9.3.x, contains a predictable file name from observable state vulnerability. An unprivileged network attacker could potentially exploit this vulnerability, leading to data loss.
- CVE-2022-27577CRITICALCVSS 9.1EG 9.12022-04-11
The vulnerability in the MSC800 in all versions before 4.15 allows for an attacker to predict the TCP initial sequence number. When the TCP sequence is predictable, an attacker can send packets that are forged to appear to come from a trus…
- CVE-2022-28355HIGHCVSS 7.5EG 7.52022-04-02
randomUUID in Scala.js before 1.10.0 generates predictable values.
- CVE-2022-29035LOWCVSS 3.3EG 2.72022-04-11
In JetBrains Ktor Native before version 2.0.0 random values used for nonce generation weren't using SecureRandom implementations
- CVE-2022-29330MEDIUMCVSS 4.9EG 4.92022-06-24
Missing access control in the backup system of Telesoft VitalPBX before 3.2.1 allows attackers to access the PJSIP and SIP extension credentials, cryptographic keys and voicemails files via unspecified vectors.
- CVE-2022-29808HIGHCVSS 7.5EG 7.52022-08-02
In Quest KACE Systems Management Appliance (SMA) through 12.0, predictable token generation occurs when appliance linking is enabled.
- CVE-2022-29930HIGHCVSS 8.7EG 4.92022-05-12
SHA1 implementation in JetBrains Ktor Native 2.0.0 was returning the same value. The issue was fixed in Ktor version 2.0.1.
- CVE-2022-30295MEDIUMCVSS 6.5EG 6.52022-05-06
uClibc-ng through 1.0.40 and uClibc through 0.9.33.2 use predictable DNS transaction IDs that may lead to DNS cache poisoning. This is related to a reset of a value to 0x2.
- CVE-2022-30629LOWCVSS 3.1EG 7.52022-08-10
Non-random values for ticket_age_add in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker that can observe TLS handshakes to correlate successive connections by comparing ticket ages during session resumption.
- CVE-2022-30782HIGHCVSS 7.5EG 7.52022-05-16
Openmoney API through 2020-06-29 uses the JavaScript Math.random function, which does not provide cryptographically secure random numbers.
- CVE-2022-30935CRITICALCVSS 9.1EG 9.12022-09-28
An authorization bypass in b2evolution allows remote, unauthenticated attackers to predict password reset tokens for any user through the use of a bad randomness function. This allows the attacker to get valid sessions for arbitrary users,…
- CVE-2022-31008MEDIUMCVSS 5.5EG 5.52022-10-06
RabbitMQ is a multi-protocol messaging and streaming broker. In affected versions the shovel and federation plugins perform URI obfuscation in their worker (link) state. The encryption key used to encrypt the URI was seeded with a predicta…
- CVE-2022-31034HIGHCVSS 8.3EG 8.32022-06-27
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting with v0.11.0 are vulnerable to a variety of attacks when an SSO login is initiated from the Argo CD CLI or UI. The vulnerabilities a…
- CVE-2022-31157HIGHCVSS 7.5EG 7.52022-07-15
LTI 1.3 Tool Library is a library used for building IMS-certified LTI 1.3 tool providers in PHP. Prior to version 5.0, the function used to generate random nonces was not sufficiently cryptographically complex. Users should upgrade to vers…
- CVE-2022-32284HIGHCVSS 7.5EG 7.52022-07-04
Use of insufficiently random values vulnerability exists in Vnet/IP communication module VI461 of YOKOGAWA Wide Area Communication Router (WAC Router) AW810D, which may allow a remote attacker to cause denial-of-service (DoS) condition by …
- CVE-2022-32296LOWCVSS 3.3EG 3.32022-06-05
The Linux kernel before 5.17.9 allows TCP servers to identify clients by observing what source ports are used. This occurs because of use of Algorithm 4 ("Double-Hash Port Selection Algorithm") of RFC 6056.
- CVE-2022-33707MEDIUMCVSS 5.3EG 5.32022-07-12
Improper identifier creation logic in Find My Mobile prior to version 7.2.24.12 allows attacker to identify the device.
- CVE-2022-34295MEDIUMCVSS 6.5EG 6.52022-06-23
totd before 1.5.3 does not properly randomize mesg IDs.
- CVE-2022-36022MEDIUMCVSS 5.3EG 5.32022-11-10
Deeplearning4J is a suite of tools for deploying and training deep learning models using the JVM. Packages org.deeplearning4j:dl4j-examples and org.deeplearning4j:platform-tests through version 1.0.0-M2.1 may use some unclaimed S3 buckets …
- CVE-2022-36045CRITICALCVSS 9.0EG 9.02022-08-31
NodeBB Forum Software is powered by Node.js and supports either Redis, MongoDB, or a PostgreSQL database. It utilizes web sockets for instant interactions and real-time notifications. `utils.generateUUID`, a helper function available in es…
- CVE-2022-36536CRITICALCVSS 9.8EG 9.82022-09-16
An issue in the component post_applogin.php of Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below allows attackers to escalate privileges via creating crafted session tokens.
- CVE-2022-37400HIGHCVSS 8.8EG 8.82022-08-15
Apache OpenOffice supports the storage of passwords for web connections in the user's configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in OpenOffice existed where the required…
- CVE-2022-38970MEDIUMCVSS 6.5EG 6.52022-09-26
ieGeek IG20 hipcam RealServer V1.0 is vulnerable to Incorrect Access Control. The algorithm used to generate device IDs (UIDs) for devices that utilize Shenzhen Yunni Technology iLnkP2P suffers from a predictability flaw that allows remote…
- CVE-2022-39216HIGHCVSS 7.4EG 7.42023-03-14
Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, the reset password token is generated without any randomness parameter. This may lead to account takeover. The issue is fixed in…
- CVE-2022-3959LOWCVSS 3.1EG 5.32022-11-11
A vulnerability, which was classified as problematic, has been found in drogon up to 1.8.1. Affected by this issue is some unknown functionality of the component Session Hash Handler. The manipulation leads to small space of random values.…
- CVE-2022-40299HIGHCVSS 7.8EG 7.82022-09-09
In Singular before 4.3.1, a predictable /tmp pathname is used (e.g., by sdb.cc), which allows local users to gain the privileges of other users via a procedure in a file under /tmp. NOTE: this CVE Record is about sdb.cc and similar files i…
- CVE-2022-42787HIGHCVSS 8.8EG 9.82022-11-10
Multiple W&T products of the Comserver Series use a small number space for allocating sessions ids. After login of an user an unathenticated remote attacker can brute force the users session id and get access to his account on the the devi…
- CVE-2022-43485MEDIUMCVSS 6.2EG 6.22023-05-30
Use of Insufficiently Random Values in Honeywell OneWireless. This vulnerability may allow attacker to manipulate claims in client's JWT token. This issue affects OneWireless version 322.1
- CVE-2022-43501CRITICALCVSS 9.1EG 9.12023-02-10
KASAGO TCP/IP stack provided by Zuken Elmic generates ISNs(Initial Sequence Number) for TCP connections from an insufficiently random source. An attacker may be able to determine the ISN of the current or future TCP connections and either …
- CVE-2022-43636HIGHCVSS 8.8EG 8.82023-03-29
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of TP-Link TL-WR940N 6_211111 3.20.1(US) routers. Authentication is not required to exploit this vulnerability. The specific flaw exist…
- CVE-2022-44795MEDIUMCVSS 6.5EG 6.52022-11-07
An issue was discovered in Object First Ootbi BETA build 1.0.7.712. A flaw was found in the Web Service, which could lead to local information disclosure. The command that creates the URL for the support bundle uses an insecure RNG. That c…
- CVE-2022-44938CRITICALCVSS 9.8EG 9.82022-12-08
Weak reset token generation in SeedDMS v6.0.20 and v5.1.7 allows attackers to execute a full account takeover via a brute force attack.
- CVE-2022-46353CRITICALCVSS 9.8EG 9.82022-12-13
A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (HSR) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP) (All versions < V3.2.7), …
- CVE-2023-0343MEDIUMCVSS 6.5EG 7.52023-03-31
Akuvox E11 contains a function that encrypts messages which are then forwarded. The IV vector and the key are static, and this may allow an attacker to decrypt messages.
- CVE-2023-1385HIGHCVSS 7.1EG 7.12023-05-03
Improper JPAKE implementation allows offline PIN brute-forcing due to the initialization of random values to a known value, which leads to unauthorized authentication to amzn.lightning services. This issue affects: Amazon Fire TV Stick 3…
- CVE-2023-1898CRITICALCVSS 9.4EG 9.42023-06-12
Atlas Copco Power Focus 6000 web server uses a small amount of session ID numbers. An attacker could enter a session ID number to retrieve data for an active user’s session.
- CVE-2023-20016MEDIUMCVSS 6.3EG 6.52023-02-23
A vulnerability in the backup configuration feature of Cisco UCS Manager Software and in the configuration export feature of Cisco FXOS Software could allow an unauthenticated attacker with access to a backup file to decrypt sensitive info…
- CVE-2023-20185HIGHCVSS 7.4EG 7.42023-07-12
A vulnerability in the Cisco ACI Multi-Site CloudSec encryption feature of Cisco Nexus 9000 Series Fabric Switches in ACI mode could allow an unauthenticated, remote attacker to read or modify intersite encrypted traffic. This vulnerabi…
- CVE-2023-22601CRITICALCVSS 10.0EG 8.62023-01-12
InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-S-V2.3.0.r5542, contain vulnerability CWE-330: Use of Insufficiently Random Values. They do not properly randomize MQTT ClientI…
- CVE-2023-22746HIGHCVSS 8.6EG 8.62023-02-03
CKAN is an open-source DMS (data management system) for powering data hubs and data portals. When creating a new container based on one of the Docker images listed below, the same secret key was being used by default. If the users didn't s…
- CVE-2023-22912MEDIUMCVSS 5.3EG 5.32023-01-20
An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. CheckUser TokenManager insecurely uses AES-CTR encryption with a repeated (aka re-used) nonce, allowing an adversary to decr…
- CVE-2023-2418LOWCVSS 3.1EG 3.12023-04-29
A vulnerability was found in Konga 2.8.3 on Kong. It has been classified as problematic. This affects an unknown part of the component Login API. The manipulation leads to insufficiently random values. The complexity of an attack is rather…
Map vulnerabilities like CWE-330 to your infrastructure
EchelonGraph correlates every CVE — across CWE-330 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →