CWE-330— Use of Insufficiently Random Values
The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.— MITRE CWE catalog
383 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-330page 6 of 8
- CVE-2022-33707MEDIUMCVSS 5.3EG 5.32022-07-12
Improper identifier creation logic in Find My Mobile prior to version 7.2.24.12 allows attacker to identify the device.
- CVE-2022-34295MEDIUMCVSS 6.5EG 6.52022-06-23
totd before 1.5.3 does not properly randomize mesg IDs.
- CVE-2022-36022MEDIUMCVSS 5.3EG 5.32022-11-10
Deeplearning4J is a suite of tools for deploying and training deep learning models using the JVM. Packages org.deeplearning4j:dl4j-examples and org.deeplearning4j:platform-tests through version 1.0.0-M2.1 may use some unclaimed S3 buckets …
- CVE-2022-36045CRITICALCVSS 9.0EG 9.02022-08-31
NodeBB Forum Software is powered by Node.js and supports either Redis, MongoDB, or a PostgreSQL database. It utilizes web sockets for instant interactions and real-time notifications. `utils.generateUUID`, a helper function available in es…
- CVE-2022-36536CRITICALCVSS 9.8EG 9.82022-09-16
An issue in the component post_applogin.php of Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below allows attackers to escalate privileges via creating crafted session tokens.
- CVE-2022-37400HIGHCVSS 8.8EG 8.82022-08-15
Apache OpenOffice supports the storage of passwords for web connections in the user's configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in OpenOffice existed where the required…
- CVE-2022-38970MEDIUMCVSS 6.5EG 6.52022-09-26
ieGeek IG20 hipcam RealServer V1.0 is vulnerable to Incorrect Access Control. The algorithm used to generate device IDs (UIDs) for devices that utilize Shenzhen Yunni Technology iLnkP2P suffers from a predictability flaw that allows remote…
- CVE-2022-39216HIGHCVSS 7.4EG 7.42023-03-14
Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, the reset password token is generated without any randomness parameter. This may lead to account takeover. The issue is fixed in…
- CVE-2022-3959MEDIUMCVSS 3.1EG 5.32022-11-11
A vulnerability, which was classified as problematic, has been found in drogon up to 1.8.1. Affected by this issue is some unknown functionality of the component Session Hash Handler. The manipulation leads to small space of random values.…
- CVE-2022-40299HIGHCVSS 7.8EG 7.82022-09-09
In Singular before 4.3.1, a predictable /tmp pathname is used (e.g., by sdb.cc), which allows local users to gain the privileges of other users via a procedure in a file under /tmp. NOTE: this CVE Record is about sdb.cc and similar files i…
- CVE-2022-42787CRITICALCVSS 8.8EG 9.82022-11-10
Multiple W&T products of the Comserver Series use a small number space for allocating sessions ids. After login of an user an unathenticated remote attacker can brute force the users session id and get access to his account on the the devi…
- CVE-2022-43485MEDIUMCVSS 6.2EG 6.22023-05-30
Use of Insufficiently Random Values in Honeywell OneWireless. This vulnerability may allow attacker to manipulate claims in client's JWT token. This issue affects OneWireless version 322.1
- CVE-2022-43501CRITICALCVSS 9.1EG 9.12023-02-10
KASAGO TCP/IP stack provided by Zuken Elmic generates ISNs(Initial Sequence Number) for TCP connections from an insufficiently random source. An attacker may be able to determine the ISN of the current or future TCP connections and either …
- CVE-2022-43636HIGHCVSS 8.8EG 8.82023-03-29
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of TP-Link TL-WR940N 6_211111 3.20.1(US) routers. Authentication is not required to exploit this vulnerability. The specific flaw exist…
- CVE-2022-44795MEDIUMCVSS 6.5EG 6.52022-11-07
An issue was discovered in Object First Ootbi BETA build 1.0.7.712. A flaw was found in the Web Service, which could lead to local information disclosure. The command that creates the URL for the support bundle uses an insecure RNG. That c…
- CVE-2022-44938CRITICALCVSS 9.8EG 9.82022-12-08
Weak reset token generation in SeedDMS v6.0.20 and v5.1.7 allows attackers to execute a full account takeover via a brute force attack.
- CVE-2022-46353CRITICALCVSS 9.8EG 9.82022-12-13
A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (HSR) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP) (All versions < V3.2.7), …
- CVE-2023-0343HIGHCVSS 6.5EG 7.52023-03-31
Akuvox E11 contains a function that encrypts messages which are then forwarded. The IV vector and the key are static, and this may allow an attacker to decrypt messages.
- CVE-2023-1385HIGHCVSS 7.1EG 7.12023-05-03
Improper JPAKE implementation allows offline PIN brute-forcing due to the initialization of random values to a known value, which leads to unauthorized authentication to amzn.lightning services. This issue affects: Amazon Fire TV Stick 3…
- CVE-2023-1898CRITICALCVSS 9.4EG 9.42023-06-12
Atlas Copco Power Focus 6000 web server uses a small amount of session ID numbers. An attacker could enter a session ID number to retrieve data for an active user’s session.
- CVE-2023-20016MEDIUMCVSS 6.3EG 6.52023-02-23
A vulnerability in the backup configuration feature of Cisco UCS Manager Software and in the configuration export feature of Cisco FXOS Software could allow an unauthenticated attacker with access to a backup file to decrypt sensitive info…
- CVE-2023-20185HIGHCVSS 7.4EG 7.42023-07-12
A vulnerability in the Cisco ACI Multi-Site CloudSec encryption feature of Cisco Nexus 9000 Series Fabric Switches in ACI mode could allow an unauthenticated, remote attacker to read or modify intersite encrypted traffic. This vulnerabi…
- CVE-2023-22601CRITICALCVSS 10.0EG 10.02023-01-12
InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-S-V2.3.0.r5542, contain vulnerability CWE-330: Use of Insufficiently Random Values. They do not properly randomize MQTT ClientI…
- CVE-2023-22746HIGHCVSS 8.6EG 8.62023-02-03
CKAN is an open-source DMS (data management system) for powering data hubs and data portals. When creating a new container based on one of the Docker images listed below, the same secret key was being used by default. If the users didn't s…
- CVE-2023-22912MEDIUMCVSS 5.3EG 5.32023-01-20
An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. CheckUser TokenManager insecurely uses AES-CTR encryption with a repeated (aka re-used) nonce, allowing an adversary to decr…
- CVE-2023-2418LOWCVSS 3.1EG 3.12023-04-29
A vulnerability was found in Konga 2.8.3 on Kong. It has been classified as problematic. This affects an unknown part of the component Login API. The manipulation leads to insufficiently random values. The complexity of an attack is rather…
- CVE-2023-24478MEDIUMCVSS 5.5EG 5.52023-08-15
Use of insufficiently random values for some Intel Agilex(R) software included as part of Intel(R) Quartus(R) Prime Pro Edition for linux before version 22.4 may allow an authenticated user to potentially enable information disclosure via …
- CVE-2023-26451HIGHCVSS 7.5EG 7.52023-08-02
Functions with insufficient randomness were used to generate authorization tokens of the integrated oAuth Authorization Service. Authorization codes were predictable for third parties and could be used to intercept and take over the client…
- CVE-2023-26855HIGHCVSS 7.5EG 7.52023-04-04
The hashing algorithm of ChurchCRM v4.5.3 utilizes a non-random salt value which allows attackers to use precomputed hash tables or dictionary attacks to crack the hashed passwords.
- CVE-2023-2729MEDIUMCVSS 5.9EG 5.92023-06-13
Use of insufficiently random values vulnerability in User Management Functionality in Synology DiskStation Manager (DSM) before 7.2-64561 allows remote attackers to obtain user credential via unspecified vectors.
- CVE-2023-2884CRITICALCVSS 9.8EG 9.82023-05-25
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG), Use of Insufficiently Random Values vulnerability in CBOT Chatbot allows Signature Spoofing by Key Recreation. This issue affects Chatbot: before Core: v4.0.3.4 Panel: v…
- CVE-2023-29332HIGHCVSS 7.5EG 7.52023-09-12
Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
- CVE-2023-30797HIGHCVSS 7.5EG 7.52023-04-19
Netflix Lemur before version 1.3.2 used insufficiently random values when generating default credentials. The insufficiently random values may allow an attacker to guess the credentials and gain access to resources managed by Lemur.
- CVE-2023-31124LOWCVSS 3.7EG 3.72023-05-25
c-ares is an asynchronous resolver library. When cross-compiling c-ares and using the autotools build system, CARES_RANDOM_FILE will not be set, as seen when cross compiling aarch64 android. This will downgrade to using rand() as a fallba…
- CVE-2023-31147MEDIUMCVSS 5.9EG 5.92023-05-25
c-ares is an asynchronous resolver library. When /dev/urandom or RtlGenRandom() are unavailable, c-ares uses rand() to generate random numbers used for DNS query ids. This is not a CSPRNG, and it is also not seeded by srand() so will gener…
- CVE-2023-3247LOWCVSS 2.6EG 2.62023-07-22
In PHP versions 8.0.* before 8.0.29, 8.1.* before 8.1.20, 8.2.* before 8.2.7 when using SOAP HTTP Digest Authentication, random value generator was not checked for failure, and was using narrower range of values than it should have. In cas…
- CVE-2023-32831MEDIUMCVSS 5.5EG 5.52024-01-02
In wlan driver, there is a possible PIN crack due to use of insufficiently random values. This could lead to local information disclosure with no execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR…
- CVE-2023-3373MEDIUMCVSS 5.9EG 5.92023-08-04
Predictable Exact Value from Previous Values vulnerability in Mitsubishi Electric Corporation GOT2000 Series GT21 model versions 01.49.000 and prior and GOT SIMPLE Series GS21 model versions 01.49.000 and prior allows a remote unauthentica…
- CVE-2023-34353HIGHCVSS 7.5EG 7.52023-09-05
An authentication bypass vulnerability exists in the OAS Engine authentication functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted network sniffing can lead to decryption of sensitive information. An att…
- CVE-2023-3803LOWCVSS 2.6EG 2.62023-07-21
A vulnerability classified as problematic has been found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0. This affects an unknown part of the file /Service/ImageStationDataService.asmx of the component File Name Handler. …
- CVE-2023-39979CRITICALCVSS 9.8EG 9.82023-09-02
There is a vulnerability in MXsecurity versions prior to 1.0.1 that can be exploited to bypass authentication. A remote attacker might access the system if the web service authenticator has insufficient random values.
- CVE-2023-41879HIGHCVSS 7.5EG 7.52023-09-11
Magento LTS is the official OpenMage LTS codebase. Guest orders may be viewed without authentication using a "guest-view" cookie which contains the order's "protect_code". This code is 6 hexadecimal characters which is arguably not enough …
- CVE-2023-4344CRITICALCVSS 9.8EG 9.82023-08-15
Broadcom RAID Controller web interface is vulnerable to insufficient randomness due to improper use of ssl.rnd to setup CIM connection
- CVE-2023-4462MEDIUMCVSS 5.9EG 5.92023-12-29
A vulnerability classified as problematic has been found in Poly Trio 8300, Trio 8500, Trio 8800, Trio C60, CCX 350, CCX 400, CCX 500, CCX 505, CCX 600, CCX 700, EDGE E100, EDGE E220, EDGE E300, EDGE E320, EDGE E350, EDGE E400, EDGE E450, …
- CVE-2023-46740CRITICALCVSS 9.8EG 9.82024-01-03
CubeFS is an open-source cloud-native file storage system. Prior to version 3.3.1, CubeFS used an insecure random string generator to generate user-specific, sensitive keys used to authenticate users in a CubeFS deployment. This could allo…
- CVE-2023-48056HIGHCVSS 7.5EG 7.52023-11-16
PyPinkSign v0.5.1 uses a non-random or static IV for Cipher Block Chaining (CBC) mode in AES encryption. This vulnerability can lead to the disclosure of information and communications.
- CVE-2023-6376HIGHCVSS 7.5EG 7.52023-11-30
Henschen & Associates court document management software does not sufficiently randomize file names of cached documents, allowing a remote, unauthenticated attacker to access restricted documents.
- CVE-2023-6799MEDIUMCVSS 5.9EG 5.92024-04-09
The WP Reset – Most Advanced WordPress Reset Tool plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0 via the use of insufficiently random snapshot names. This makes it possible …
- CVE-2024-0761HIGHCVSS 8.1EG 8.12024-02-05
The File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.2.1 due to insufficient randomness in the backup filenames, which use a timestamp plus 4 random digits. This make…
- CVE-2024-10082HIGHCVSS 8.7EG 8.72024-11-06
CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication method confusion allows logging in as the built-in root user from an external service. The built-in root…
Map vulnerabilities like CWE-330 to your infrastructure
EchelonGraph correlates every CVE — across CWE-330 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →