CWE-310
377 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-310page 6 of 8
- CVE-2016-2268MEDIUMCVSS 6.8EG 6.82016-02-08
Dell SecureWorks app before 2.1 for iOS does not validate SSL certificates, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
- CVE-2017-7526MEDIUMCVSS 6.1EG 6.82018-07-26
libgcrypt before version 1.7.8 is vulnerable to a cache side-channel attack resulting into a complete break of RSA-1024 while using the left-to-right method for computing the sliding-window expansion. The same attack is believed to work on…
- CVE-2015-4056MEDIUMCVSS 6.7EG 6.72017-02-21
The System Library in VCE Vision Intelligent Operations before 2.6.5 does not properly implement cryptography, which makes it easier for local users to discover credentials by leveraging administrative access.
- CVE-2021-41994MEDIUMCVSS 6.6EG 6.62022-04-30
A misconfiguration of RSA in PingID iOS app prior to 1.19 is vulnerable to pre-computed dictionary attacks, leading to an offline MFA bypass when using PingID Windows Login.
- CVE-2021-41993MEDIUMCVSS 6.6EG 6.62022-04-30
A misconfiguration of RSA in PingID Android app prior to 1.19 is vulnerable to pre-computed dictionary attacks, leading to an offline MFA bypass when using PingID Windows Login.
- CVE-2003-1392MEDIUMCVSS v2 6.6EG 6.62003-12-31
CryptoBuddy 1.0 and 1.2 does not use the user-supplied passphrase to encrypt data, which could allow local users to use their own passphrase to decrypt the data.
- CVE-2024-20690MEDIUMCVSS 6.5EG 6.52024-01-09
Windows Nearby Sharing Spoofing Vulnerability
- CVE-2019-3740MEDIUMCVSS 6.5EG 6.52019-09-18
RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to an Information Exposure Through Timing Discrepancy vulnerabilities during DSA key generation. A malicious remote attacker could potentially exploit those vulnerabilities to recov…
- CVE-2019-3739MEDIUMCVSS 6.5EG 6.52019-09-18
RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to Information Exposure Through Timing Discrepancy vulnerabilities during ECDSA key generation. A malicious remote attacker could potentially exploit those vulnerabilities to recove…
- CVE-2016-10555MEDIUMCVSS 6.5EG 6.52018-05-31
Since "algorithm" isn't enforced in jwt.decode()in jwt-simple 0.3.0 and earlier, a malicious user could choose what algorithm is sent sent to the server. If the server is expecting RSA but is sent HMAC-SHA with RSA's public key, the server…
- CVE-2016-6257MEDIUMCVSS 6.5EG 6.52016-08-02
The firmware in Lenovo Ultraslim dongles, as used with Lenovo Liteon SK-8861, Ultraslim Wireless, and Silver Silk keyboards and Liteon ZTM600 and Ultraslim Wireless mice, does not enforce incrementing AES counters, which allows remote atta…
- CVE-2016-4524MEDIUMCVSS 6.5EG 6.52016-06-10
ABB PCM600 before 2.7 improperly stores OPC Server IEC61850 passwords in unspecified temporary circumstances, which allows local users to obtain sensitive information via unknown vectors.
- CVE-2013-7449MEDIUMCVSS 6.5EG 6.52016-04-21
The ssl_do_connect function in common/server.c in HexChat before 2.10.2, XChat, and XChat-GNOME does not verify that the server hostname matches a domain name in the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL …
- CVE-2016-1938MEDIUMCVSS 6.5EG 6.52016-01-31
The s_mp_div function in lib/freebl/mpi/mpi.c in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, improperly divides numbers, which might make it easier for remote attackers to defeat cryptograph…
- CVE-2016-1618MEDIUMCVSS 6.5EG 6.52016-01-25
Blink, as used in Google Chrome before 48.0.2564.82, does not ensure that a proper cryptographicallyRandomValues random number generator is used, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via …
- CVE-2017-3226MEDIUMCVSS 6.4EG 6.42018-07-24
Das U-Boot is a device bootloader that can read its configuration from an AES encrypted file. Devices that make use of Das U-Boot's AES-CBC encryption feature using environment encryption (i.e., setting the configuration parameter CONFIG_E…
- CVE-2003-1483MEDIUMCVSS v2 6.4EG 6.42003-12-31
FlashFXP 1.4 uses a weak encryption algorithm for user passwords, which allows attackers to decrypt the passwords and gain access.
- CVE-2016-8889MEDIUMCVSS 6.2EG 6.22016-10-28
In Bitcoin Knots v0.11.0.ljr20150711 through v0.13.0.knots20160814 (fixed in v0.13.1.knots20161027), the debug console stores sensitive information including private keys and the wallet passphrase in its persistent command history.
- CVE-2016-5433MEDIUMCVSS 6.1EG 6.12016-06-17
Citrix iOS Receiver before 7.0 allows attackers to cause TLS certificates to be incorrectly validated via unspecified vectors.
- CVE-2025-9828MEDIUMCVSS 5.9EG 5.92025-09-02
A vulnerability was determined in Tenda CP6 11.10.00.243. The affected element is the function sub_2B7D04 of the component uhttp. Executing manipulation can lead to risky cryptographic algorithm. The attack may be launched remotely. This a…
- CVE-2025-8741MEDIUMCVSS 5.9EG 5.92025-08-08
A vulnerability was found in macrozheng mall up to 1.0.3. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/login. The manipulation leads to cleartext transmission of sensiti…
- CVE-2025-48823MEDIUMCVSS 5.9EG 5.92025-07-08
Cryptographic issues in Windows Cryptographic Services allows an unauthorized attacker to disclose information over a network.
- CVE-2021-22947MEDIUMCVSS 5.9EG 5.92021-09-29
When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS to upgrade to TLS security, the server can respond and send back multiple responses at once that curl caches. curl would then upgrade to T…
- CVE-2019-1940MEDIUMCVSS 5.9EG 5.92019-07-17
A vulnerability in the Web Services Management Agent (WSMA) feature of Cisco Industrial Network Director (IND) could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data using an invalid X.509 certif…
- CVE-2019-9191MEDIUMCVSS 5.9EG 5.92019-02-26
The ETSI Enterprise Transport Security (ETS, formerly known as eTLS) protocol does not provide per-session forward secrecy.
- CVE-2018-16870MEDIUMCVSS 5.9EG 5.92019-01-03
It was found that wolfssl before 3.15.7 is vulnerable to a new variant of the Bleichenbacher attack to perform downgrade attacks against TLS. This may lead to leakage of sensible data.
- CVE-2018-19653MEDIUMCVSS 5.9EG 5.92018-12-09
HashiCorp Consul 0.5.1 through 1.4.0 can use cleartext agent-to-agent RPC communication because the verify_outgoing setting is improperly documented. NOTE: the vendor has provided reconfiguration steps that do not require a software upgrad…
- CVE-2017-17305MEDIUMCVSS 5.9EG 5.92018-08-21
Some Huawei Firewall products USG2205BSR V300R001C10SPC600; USG2220BSR V300R001C00; USG5120BSR V300R001C00; USG5150BSR V300R001C00 have a Bleichenbacher Oracle vulnerability in the IPSEC IKEv1 implementations. Remote attackers can decrypt …
- CVE-2017-17174MEDIUMCVSS 5.9EG 5.92018-07-31
Some Huawei products RSE6500 V500R002C00; SoftCo V200R003C20SPCb00; VP9660 V600R006C10; eSpace U1981 V100R001C20; V200R003C20; V200R003C30; V200R003C50 have a weak algorithm vulnerability. To exploit the vulnerability, a remote, unauthenti…
- CVE-2011-4190MEDIUMCVSS 5.9EG 5.92018-06-08
The kdump implementation is missing the host key verification in the kdump and mkdumprd OpenSSH integration of kdump prior to version 2012-01-20. This is similar to CVE-2011-3588, but different in that the kdump implementation is specific …
- CVE-2016-10630MEDIUMCVSS 5.9EG 5.92018-06-01
install-g-test downloads resources over HTTP, which leaves it vulnerable to MITM attacks.
- CVE-2016-10613MEDIUMCVSS 5.9EG 5.92018-06-01
bionode-sra is a Node.js wrapper for SRA Toolkit. bionode-sra downloads data resources over HTTP, which leaves it vulnerable to MITM attacks.
- CVE-2016-10535MEDIUMCVSS 5.9EG 5.92018-05-31
csrf-lite is a cross-site request forgery protection library for framework-less node sites. csrf-lite uses `===`, a fail first string comparison, instead of a time constant string comparison This enables an attacker to guess the secret in …
- CVE-2016-10530MEDIUMCVSS 5.9EG 5.92018-05-31
The airbrake module 0.3.8 and earlier defaults to sending environment variables over HTTP. Environment variables can often times contain secret keys and other sensitive values. A malicious user could be on the same network as a regular use…
- CVE-2014-2903MEDIUMCVSS 5.9EG 5.92017-10-06
CyaSSL does not check the key usage extension in leaf certificates, which allows remote attackers to spoof servers via a crafted server certificate not authorized for use in an SSL/TLS handshake.
- CVE-2015-7256MEDIUMCVSS 5.9EG 5.92017-09-28
ZyXEL NWA1100-N, NWA1100-NH, NWA1121-NI, NWA1123-AC, and NWA1123-NI access points; P-660HN-51, P-663HN-51, VMG1312-B10A, VMG1312-B30A, VMG1312-B30B, VMG4380-B10A, VMG8324-B10A, VMG8924-B10A, VMG8924-B30A, and VSG1435-B101 DSL CPEs; PMG5318…
- CVE-2014-8878MEDIUMCVSS 5.9EG 5.92017-09-28
KDE KMail does not encrypt attachments in emails when "automatic encryption" is enabled, which allows remote attackers to obtain sensitive information by sniffing the network.
- CVE-2011-4667MEDIUMCVSS 5.9EG 5.92017-09-25
The encryption library in Cisco IOS Software 15.2(1)T, 15.2(1)T1, and 15.2(2)T, Cisco NX-OS in Cisco MDS 9222i Multiservice Modular Switch, Cisco MDS 9000 18/4-Port Multiservice Module, and Cisco MDS 9000 Storage Services Node module befor…
- CVE-2016-6329MEDIUMCVSS 5.9EG 5.92017-01-31
OpenVPN, when using a 64-bit block cipher, makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTP-over-OpenVPN session using Blowfish in CBC…
- CVE-2016-1411MEDIUMCVSS 5.9EG 5.92016-12-14
A vulnerability in the update functionality of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA), Cisco Web Security Appliance (WSA), and Cisco Content Management Security Appliance (SMA) could allow an unauthenticated, remot…
- CVE-2012-6702MEDIUMCVSS 5.9EG 5.92016-06-16
Expat, when used in a parser that has not called XML_SetHashSalt or passed it a seed of 0, makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms via vectors involving use of the srand function.
- CVE-2016-1273MEDIUMCVSS 5.9EG 5.92016-04-15
Juniper Junos OS before 13.2X51-D40, 14.x before 14.1X53-D30, and 15.x before 15.1X53-D20 on QFX5100 and QFX10002 switches do not have sufficient entropy, which makes it easier for remote attackers to defeat cryptographic encryption and au…
- CVE-2016-1788MEDIUMCVSS 5.9EG 5.92016-03-24
Messages in Apple iOS before 9.3, OS X before 10.11.4, and watchOS before 2.2 does not properly implement a cryptographic protection mechanism, which allows remote attackers to read message attachments via vectors related to duplicate mess…
- CVE-2016-1731MEDIUMCVSS 5.9EG 5.92016-03-14
Apple Software Update before 2.2 on Windows does not use HTTPS, which makes it easier for man-in-the-middle attackers to spoof updates by modifying the client-server data stream.
- CVE-2015-3197MEDIUMCVSS 5.9EG 5.92016-02-15
ssl/s2_srvr.c in OpenSSL 1.0.1 before 1.0.1r and 1.0.2 before 1.0.2f does not prevent use of disabled ciphers, which makes it easier for man-in-the-middle attackers to defeat cryptographic protection mechanisms by performing computations o…
- CVE-2018-0283MEDIUMCVSS 5.8EG 5.82018-05-02
A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to restart an instance of the Snort detection engine on an affected device, resulting in a brief denial of service (…
- CVE-2018-0281MEDIUMCVSS 5.8EG 5.82018-05-02
A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to restart an instance of the Snort detection engine on an affected device, resulting in a brief denial of service (…
- CVE-2018-7839MEDIUMCVSS 5.5EG 5.52019-02-06
A Cryptographic Issue (CWE-310) vulnerability exists in IIoT Monitor 3.1.38 which could allow information disclosure.
- CVE-2017-18327MEDIUMCVSS 5.5EG 5.52019-01-03
Security keys are logged when any WCDMA call is configured or reconfigured in snapdragon automobile, snapdragon mobile and snapdragon wear in versions MDM9607, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, MSM8996AU, SD 210/SD 21…
- CVE-2015-8234MEDIUMCVSS 5.5EG 5.52017-03-29
The image signature algorithm in OpenStack Glance 11.0.0 allows remote attackers to bypass the signature verification process via a crafted image, which triggers an MD5 collision.
Map vulnerabilities like CWE-310 to your infrastructure
EchelonGraph correlates every CVE — across CWE-310 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →