CWE-310
377 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-310page 5 of 8
- CVE-2018-5458HIGHCVSS 7.5EG 7.52018-03-26
Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have a vulnerability using SSL legacy encryption that could allow an attacker to gain unauthorized access to resources and information.
- CVE-2014-10069HIGHCVSS 7.5EG 7.52018-01-07
Hitron CVE-30360 devices use a 578A958E3DD933FC DES key that is shared across different customers' installations, which makes it easier for attackers to obtain sensitive information by decrypting a backup configuration file, as demonstrate…
- CVE-2014-7808HIGHCVSS 7.5EG 7.52017-09-15
Apache Wicket before 1.5.13, 6.x before 6.19.0, and 7.x before 7.0.0-M5 make it easier for attackers to defeat a cryptographic protection mechanism and predict encrypted URLs by leveraging use of CryptoMapper as the default encryption prov…
- CVE-2017-6766HIGHCVSS 7.5EG 7.52017-08-07
A vulnerability in the Secure Sockets Layer (SSL) Decryption and Inspection feature of Cisco Firepower System Software 5.4.0, 5.4.1, 6.0.0, 6.1.0, 6.2.0, 6.2.1, and 6.2.2 could allow an unauthenticated, remote attacker to bypass the SSL po…
- CVE-2015-8013HIGHCVSS 7.5EG 7.52017-07-25
s2k.js in OpenPGP.js will decrypt arbitrary messages regardless of passphrase for crafted PGP keys which allows remote attackers to bypass authentication if message decryption is used as an authentication mechanism via a crafted symmetrica…
- CVE-2016-4457HIGHCVSS 7.5EG 7.52017-06-08
CloudForms Management Engine before 5.8 includes a default SSL/TLS certificate.
- CVE-2016-7270HIGHCVSS 7.5EG 7.52016-12-20
The Data Provider for SQL Server in Microsoft .NET Framework 4.6.2 mishandles a developer-supplied key, which allows remote attackers to bypass the Always Encrypted protection mechanism and obtain sensitive cleartext information by leverag…
- CVE-2016-5084HIGHCVSS 7.5EG 7.52016-10-05
Johnson & Johnson Animas OneTouch Ping devices do not use encryption for certain data, which might allow remote attackers to obtain sensitive information by sniffing the network.
- CVE-2016-5957HIGHCVSS 7.5EG 7.52016-09-26
IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 allows remote attackers to defeat cryptographic protection mechanisms and obtain sensitive information by leveraging a weak algorithm.
- CVE-2016-4754HIGHCVSS 7.5EG 7.52016-09-25
ServerDocs Server in Apple OS X Server before 5.2 supports the RC4 cipher, which might allow remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.
- CVE-2016-6899HIGHCVSS 7.5EG 7.52016-09-07
The Intelligent Baseboard Management Controller (iBMC) in Huawei RH1288 V3 servers with software before V100R003C00SPC613, RH2288 V3 servers with software before V100R003C00SPC617, RH2288H V3 servers with software before V100R003C00SPC515,…
- CVE-2016-6838HIGHCVSS 7.5EG 7.52016-09-07
Huawei X6800 and XH620 V3 servers with software before V100R003C00SPC606, RH1288 V3 servers with software before V100R003C00SPC613, RH2288 V3 servers with software before V100R003C00SPC617, CH140 V3 and CH226 V3 servers with software befor…
- CVE-2016-5419HIGHCVSS 7.5EG 7.52016-08-10
curl and libcurl before 7.50.1 do not prevent TLS session resumption when the client certificate has changed, which allows remote attackers to bypass intended restrictions by resuming a session.
- CVE-2016-2364HIGHCVSS 7.5EG 7.52016-06-20
The Chrome HUDweb plugin before 2016-05-05 for Fonality (previously trixbox Pro) 12.6 through 14.1i uses the same hardcoded private key across different customers' installations, which allows remote attackers to defeat cryptographic protec…
- CVE-2016-1902HIGHCVSS 7.5EG 7.52016-06-01
The nextBytes function in the SecureRandom class in Symfony before 2.3.37, 2.6.x before 2.6.13, and 2.7.x before 2.7.9 does not properly generate random numbers when used with PHP 5.x without the paragonie/random_compat library and the ope…
- CVE-2015-8867HIGHCVSS 7.5EG 7.52016-05-22
The openssl_random_pseudo_bytes function in ext/openssl/openssl.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 incorrectly relies on the deprecated RAND_pseudo_bytes function, which makes it easier for remote attacker…
- CVE-2014-9742HIGHCVSS 7.5EG 7.52016-05-13
The Miller-Rabin primality check in Botan before 1.10.8 and 1.11.x before 1.11.9 improperly uses a single random base, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a DH group.
- CVE-2000-1254HIGHCVSS 7.5EG 7.52016-05-05
crypto/rsa/rsa_gen.c in OpenSSL before 0.9.6 mishandles C bitwise-shift operations that exceed the size of an expression, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging improper RSA k…
- CVE-2016-2333HIGHCVSS 7.5EG 7.52016-04-25
SysLINK SL-1000 Machine-to-Machine (M2M) Modular Gateway devices with firmware before 01A.8 use the same hardcoded encryption key across different customers' installations, which allows attackers to defeat cryptographic protection mechanis…
- CVE-2016-2306HIGHCVSS 7.5EG 7.52016-04-22
The HMI web server in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to obtain sensitive cleartext information by sniffing the network.
- CVE-2016-3071HIGHCVSS 7.5EG 7.52016-04-18
Libreswan 3.16 might allow remote attackers to cause a denial of service (daemon restart) via an IKEv2 aes_xcbc transform.
- CVE-2016-3125HIGHCVSS 7.5EG 7.52016-04-05
The mod_tls module in ProFTPD before 1.3.5b and 1.3.6 before 1.3.6rc2 does not properly handle the TLSDHParamFile directive, which might cause a weaker than intended Diffie-Hellman (DH) key to be used and consequently allow attackers to ha…
- CVE-2016-1777HIGHCVSS 7.5EG 7.52016-03-24
Web Server in Apple OS X Server before 5.1 supports the RC4 algorithm, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.
- CVE-2015-5012HIGHCVSS 7.5EG 7.52016-02-15
The SSH implementation on IBM Security Access Manager for Web appliances 7.0 before 7.0.0 FP19, 8.0 before 8.0.1.3 IF3, and 9.0 before 9.0.0.0 IF1 does not properly restrict the set of MAC algorithms, which makes it easier for remote attac…
- CVE-2015-8281HIGHCVSS 7.5EG 7.52016-01-15
Web Viewer 1.0.0.193 on Samsung SRN-1670D devices allows attackers to bypass filesystem encryption via XOR calculations.
- CVE-2019-6576HIGHCVSS 6.5EG 7.52019-05-14
A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V15.1 Update 1), SIMATIC HMI Comfort Outdoor Panels 7" & 15" (All versions < V15.1 Update 1), SIMATIC HMI KTP Mobile Panels KTP400F, KTP700, KTP700F…
- CVE-2017-1268HIGHCVSS 5.9EG 7.52018-12-13
IBM Security Guardium 10 and 10.5 uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the software does not also use a salt as part of the input. IBM X-Force ID: 124743.
- CVE-2021-4258HIGHCVSS 3.7EG 7.52022-12-19
A vulnerability was found in whohas. It has been rated as problematic. This issue affects some unknown processing of the component Package Information Handler. The manipulation leads to cleartext transmission of sensitive information. The …
- CVE-2003-1389HIGHCVSS v2 7.5EG 7.52003-12-31
RTS CryptoBuddy 1.2 and earlier truncates long passphrases without warning the user, which may make it easier to conduct certain brute force guessing attacks.
- CVE-2003-1390HIGHCVSS v2 7.5EG 7.52003-12-31
RTS CryptoBuddy 1.2 and earlier stores bytes 53 through 55 of a 55-byte passphrase in plaintext, which makes it easier for local users to guess the passphrase.
- CVE-2003-1391HIGHCVSS v2 7.5EG 7.52003-12-31
RTS CryptoBuddy 1.0 and 1.2 uses a weak encryption algorithm for the passphrase and generates predictable keys, which makes it easier for attackers to guess the passphrase.
- CVE-2001-1463HIGHCVSS v2 7.5EG 7.52001-11-19
The remote administration client for RhinoSoft Serv-U 3.0 sends the user password in plaintext even when S/KEY One-Time Password (OTP) authentication is enabled, which allows remote attackers to sniff passwords.
- CVE-2001-1473HIGHCVSS v2 7.5EG 7.52001-01-18
The SSH-1 protocol allows remote servers to conduct man-in-the-middle attacks and replay a client challenge response to a target server by creating a Session ID that matches the Session ID of the target, but which uses a public key pair th…
- CVE-2000-0589HIGHCVSS v2 7.5EG 7.52000-06-26
SawMill 5.0.21 uses weak encryption to store passwords, which allows attackers to easily decrypt the password and modify the SawMill configuration.
- CVE-2026-2618HIGHCVSS 7.4EG 7.42026-02-17
A vulnerability was determined in Beetel 777VR1 up to 01.00.09. This impacts an unknown function of the component SSH Service. This manipulation causes risky cryptographic algorithm. The attack is possible to be carried out remotely. The a…
- CVE-2017-12151HIGHCVSS 7.4EG 7.42018-07-27
A flaw was found in the way samba client before samba 4.4.16, samba 4.5.14 and samba 4.6.8 used encryption with the max protocol set as SMB3. The connection could lose the requirement for signing and encrypting to any DFS redirects, allowi…
- CVE-2016-1000352HIGHCVSS 7.4EG 7.42018-06-04
In the Bouncy Castle JCE Provider version 1.55 and earlier the ECIES implementation allowed the use of ECB mode. This mode is regarded as unsafe and support for it has been removed from the provider.
- CVE-2016-1000344HIGHCVSS 7.4EG 7.42018-06-04
In the Bouncy Castle JCE Provider version 1.55 and earlier the DHIES implementation allowed the use of ECB mode. This mode is regarded as unsafe and support for it has been removed from the provider.
- CVE-2015-5039HIGHCVSS 7.4EG 7.42018-03-26
The Remote Client and change management integrations in IBM Rational ClearCase 7.1.x, 8.0.0.x before 8.0.0.18, and 8.0.1.x before 8.0.1.11 do not properly validate hostnames in X.509 certificates from SSL servers, which allows remote attac…
- CVE-2016-2113HIGHCVSS 7.4EG 7.42016-04-25
Samba 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not verify X.509 certificates from TLS servers, which allows man-in-the-middle attackers to spoof LDAPS and HTTPS servers and obtain sensitive information via a craft…
- CVE-2022-40675HIGHCVSS 6.5EG 7.42023-02-16
Some cryptographic issues in Fortinet FortiNAC versions 9.4.0 through 9.4.1, 9.2.0 through 9.2.7, 9.1.0 through 9.1.8, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow an attacker to decr…
- CVE-2013-4035HIGHCVSS 7.3EG 7.32018-05-01
IBM Sterling Connect:Direct for OpenVMS 3.4.00, 3.4.01, 3.5.00, 3.6.0, and 3.6.0.1 allow remote attackers to have unspecified impact by leveraging failure to reject client requests for an unencrypted session when used as the server in a TC…
- CVE-2022-23719HIGHCVSS 7.2EG 7.22022-06-30
PingID Windows Login prior to 2.8 does not authenticate communication with a local Java service used to capture security key requests. An attacker with the ability to execute code on the target machine maybe able to exploit and spoof the l…
- CVE-2025-21482HIGHCVSS 7.1EG 7.12025-09-24
Cryptographic issue while performing RSA PKCS padding decoding.
- CVE-2025-21422HIGHCVSS 7.1EG 7.12025-07-08
Cryptographic issue while processing crypto API calls, missing checks may lead to corrupted key usage or IV reuses.
- CVE-2023-33037HIGHCVSS 7.1EG 7.12024-01-02
Cryptographic issue in Automotive while unwrapping the key secs2d and verifying with RPMB data.
- CVE-2022-22076HIGHCVSS 7.1EG 7.12023-06-06
information disclosure due to cryptographic issue in Core during RPMB read request.
- CVE-2026-49000HIGHCVSS 7.0EG 7.02026-05-27
An insecure password scheme refers to vulnerabilities arising from improper selection of encryption algorithms, inadequate key management, or flawed code implementation, which may lead to data leakage or tampering, such as hard-coded keys …
- CVE-2016-7585MEDIUMCVSS 6.8EG 6.82017-04-02
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves mishandling of DMA in the "EFI" component. It allows physically proximate attackers to discover the FileVault 2 encryption password via…
- CVE-2016-4763MEDIUMCVSS 6.8EG 6.82016-09-25
WKWebView in WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 does not properly verify X.509 certificates from HTTPS servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitiv…
Map vulnerabilities like CWE-310 to your infrastructure
EchelonGraph correlates every CVE — across CWE-310 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →