CWE-325— Missing Cryptographic Step
The product does not implement a required step in a cryptographic algorithm, resulting in weaker encryption than advertised by the algorithm.— MITRE CWE catalog
66 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-325page 1 of 2
- CVE-2022-24116CRITICALCVSS 9.8EG 9.82022-12-26
Certain General Electric Renewable Energy products have inadequate encryption strength. This affects iNET and iNET II before 8.3.0.
- CVE-2020-15086CRITICALCVSS 9.8EG 9.82020-07-29
In TYPO3 installations with the "mediace" extension from version 7.6.2 and before version 7.6.5, it has been discovered that an internal verification mechanism can be used to generate arbitrary checksums. The allows to inject arbitrary dat…
- CVE-2026-17666CRITICALCVSS 9.1EG 9.12026-07-30
Cryptographic Flaw in Enterprise in Google Chrome prior to 151.0.7922.72 allowed an attacker in a privileged network position to bypass discretionary access control via malicious network traffic. (Chromium security severity: High)
- CVE-2026-4601CRITICALCVSS 9.1EG 9.12026-03-23
Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.signWithMessageHash process in the DSA signing implementation. An attacker can recover the private key by forcing r or s t…
- CVE-2020-15098HIGHCVSS 8.8EG 8.82020-07-29
In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.20, and greater than or equal to 10.0.0 and less than 10.4.6, it has been discovered that an internal verification mechanism can be used to generate arbitrary checksums. This al…
- CVE-2026-16000HIGHCVSS 8.7EG 8.72026-10-02
Missing cryptographic step in the DSTU 7624 CCM mode implementation (KCcmBlockCipher) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can observe encrypted messages of known or chosen content to forge ciph…
- CVE-2026-76784HIGHCVSS 8.7EG 8.72026-08-26
Multiple TP-Link Kasa smart home devices contain insufficient cryptographic protections in the local device communication protocol. An adjacent network attacker may intercept, replay or forge locally exchanged control messages, potentially…
- CVE-2025-30147HIGHCVSS 8.7EG 8.72025-05-07
Besu Native contains scripts and tooling that is used to build and package the native libraries used by the Ethereum client Hyperledger Besu. Besu 24.7.1 through 25.2.2, corresponding to besu-native versions 0.9.0 through 1.2.1, have a pot…
- CVE-2026-100798HIGHCVSS 8.1EG 8.12026-09-29
Cryptography misuse in Storage: Quota Manager component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157.
- CVE-2026-81235HIGHCVSS 4.9EG 8.02026-09-15
Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain a Missing Cryptographic Step vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information tampering.
- CVE-2026-45445HIGHCVSS 7.5EG 7.52026-06-09
Issue summary: When an application drives an AES-OCB context through the public EVP_Cipher() one-shot interface, the application-supplied initialisation vector (IV) is silently discarded. Impact summary: Every message encrypted under the …
- CVE-2026-41395HIGHCVSS 7.5EG 7.52026-04-28
OpenClaw before 2026.3.28 contains a webhook replay vulnerability in Plivo V3 signature verification that canonicalizes query ordering for signatures but hashes raw URLs for replay detection. Attackers can reorder query parameters to bypas…
- CVE-2026-4258HIGHCVSS 7.5EG 7.52026-03-17
Versions of the package sjcl before 1.0.9 are vulnerable to Improper Verification of Cryptographic Signature due to missing point-on-curve validation in sjcl.ecc.basicKey.publicKey(). An attacker can recover a victim's ECDH private key by …
- CVE-2026-28498HIGHCVSS 7.5EG 7.52026-03-16
Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a library-level vulnerability was identified in the Authlib Python library concerning the validation of OpenID Connect (OIDC) ID Tokens. Spe…
- CVE-2026-22863HIGHCVSS 7.5EG 7.52026-01-15
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Before 2.6.0, node:crypto doesn't finalize cipher. The vulnerability allows an attacker to have infinite encryptions. This can lead to naive attempts at brute forcing, as well as m…
- CVE-2025-60704HIGHCVSS 7.5EG 7.52025-11-11
Missing cryptographic step in Windows Kerberos allows an unauthorized attacker to elevate privileges over a network.
- CVE-2023-46129HIGHCVSS 7.5EG 7.52023-10-31
NATS.io is a high performance open source pub-sub distributed communication technology, built for the cloud, on-premise, IoT, and edge computing. The cryptographic key handling library, nkeys, recently gained support for encryption, not ju…
- CVE-2021-22946HIGHCVSS 7.5EG 7.52021-09-29
A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (`--ssl-reqd` on the command line or`CURLOPT_USE_SSL` set to `CURLUSESSL_CONTROL` or `CURLUSESSL_ALL` withlibc…
- CVE-2021-33560HIGHCVSS 7.5EG 7.52021-06-08
Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm, and the window size is not chosen appropriately. This, for example, affects u…
- CVE-2022-1279HIGHCVSS 6.5EG 7.52022-04-14
A vulnerability in the encryption implementation of EBICS messages in the open source librairy ebics-java/ebics-java-client allows an attacker sniffing network traffic to decrypt EBICS payloads. This issue affects: ebics-java/ebics-java-cl…
- CVE-2026-49440HIGHCVSS 7.4EG 7.42026-06-16
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, node:crypto.checkPrime(candidate[, options][, callback]) and crypto.checkPrimeSync(candidate[, options]) ran no Miller-Rabin rounds at all when the caller left opti…
- CVE-2026-42246HIGHCVSS 7.4EG 7.42026-05-09
Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4, a man-in-the-middle attacker can cause Net::IMAP#starttls to return "successfully", without sta…
- CVE-2022-20742HIGHCVSS 7.4EG 7.42022-05-03
A vulnerability in an IPsec VPN library of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to read or modify data within an IPsec IKEv2 VPN …
- CVE-2026-40542HIGHCVSS 7.3EG 7.32026-04-22
Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication verification. Users are recommended to upgrade to version 5…
- CVE-2025-47383HIGHCVSS 7.2EG 7.22026-03-02
Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.
- CVE-2026-55144HIGHCVSS 7.1EG 7.12026-07-14
Missing cryptographic step in Windows CryptoAPI allows an authorized attacker to perform tampering locally.
- CVE-2026-9266HIGHCVSS 7.0EG 7.02026-06-12
A Missing Required Cryptographic Step vulnerability has been identified in Moxa's embedded Linux firmware for industrial computers and controllers. This vulnerability represents an incomplete remediation of CVE-2026-0714. The firmware intr…
- CVE-2023-28999MEDIUMCVSS 6.9EG 6.92023-04-04
Nextcloud is an open-source productivity platform. In Nextcloud Desktop client 3.0.0 until 3.8.0, Nextcloud Android app 3.13.0 until 3.25.0, and Nextcloud iOS app 3.0.5 until 4.8.0, a malicious server administrator can gain full access to …
- CVE-2026-59776MEDIUMCVSS 6.8EG 6.82026-07-21
Missing Cryptographic Step (CWE-325) vulnerability exists in certain FeliCa IC chips shipped in or before 2017. If the vulnerability is exploited, information stored in the IC chip may be read or tampered with.
- CVE-2025-3938MEDIUMCVSS 6.8EG 6.82025-05-22
Missing Cryptographic Step vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Cryptanalysis. This issue affects Niagara Framework: before 4.14.2, before 4.15…
- CVE-2022-20793MEDIUMCVSS 6.8EG 6.82024-11-15
A vulnerability in pairing process of Cisco TelePresence CE Software and RoomOS Software for Cisco Touch 10 Devices could allow an unauthenticated, remote attacker to impersonate a legitimate device and pair with an affected devi…
- CVE-2020-26244MEDIUMCVSS 6.8EG 6.82020-12-02
Python oic is a Python OpenID Connect implementation. In Python oic before version 1.2.1, there are several related cryptographic issues affecting client implementations that use the library. The issues are: 1) The IdToken signature algori…
- CVE-2018-5383MEDIUMCVSS 6.8EG 6.82018-08-07
Bluetooth firmware or operating system software drivers in macOS versions before 10.13, High Sierra and iOS versions before 11.4, and Android versions before the 2018-06-05 patch may not sufficiently validate elliptic curve parameters used…
- CVE-2023-28998MEDIUMCVSS 6.7EG 6.72023-04-04
The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server. Starting with version 3.0.0 and prior to version 3.6.5, a malicious server administrator can gain full access to an end-to-end encrypted folder. They can de…
- CVE-2026-48480MEDIUMCVSS 6.6EG 6.62026-06-04
The netty incubator codec.bhttp is a java language binary http parser. Prior to version 0.0.22.FInal, the codec-ohttp implementation of draft-ietf-ohai-chunked-ohttp does not verify that a cryptographically-signed final chunk was received …
- CVE-2024-43547MEDIUMCVSS 6.5EG 6.52024-10-08
Windows Kerberos Information Disclosure Vulnerability
- CVE-2019-3738MEDIUMCVSS 6.5EG 6.52019-09-18
RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to a Missing Required Cryptographic Step vulnerability. A malicious remote attacker could potentially exploit this vulnerability to coerce two parties into computing the same predic…
- CVE-2026-107785MEDIUMCVSS 6.3EG 6.32026-10-09
Crux Agent from 1.9.0 before 2.0.3 uses the full SKA bilocation key as the WireGuard preshared key. When a peering session negotiates use of SHA-512, the key produced is 64 bytes instead of the 32 bytes WireGuard requires. The agent does n…
- CVE-2023-34471MEDIUMCVSS 6.3EG 6.32023-07-05
AMI SPx contains a vulnerability in the BMC where a user may cause a missing cryptographic step by generating a hash-based message authentication code (HMAC). A successful exploit of this vulnerability may lead to the loss confidentialit…
- CVE-2022-29229MEDIUMCVSS 6.3EG 6.32022-05-18
CaSS is a Competency and Skills System. CaSS Library, (npm:cassproject) has a missing cryptographic step when storing cryptographic keys that can allow a server administrator access to an account’s cryptographic keys. This affects CaSS s…
- CVE-2026-25250MEDIUMCVSS 6.0EG 6.02026-08-27
EAZ EazyFix 12.9 allows a Security Feature Bypass related to a "Missing Cryptographic Step" associated with "Secure Boot disable."
- CVE-2025-58359MEDIUMCVSS 6.0EG 6.02025-09-05
ZF FROST is a Rust implementation of FROST (Flexible Round-Optimised Schnorr Threshold signatures). In versions 2.0.0 through 2.1.0, refresh shares with smaller min_signers will reduce security of group. The inability to change min_signers…
- CVE-2026-58638MEDIUMCVSS 5.5EG 6.02026-07-14
Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.
- CVE-2026-0420MEDIUMCVSS 5.9EG 5.92026-06-09
An improper implementation of TLS certificate validation vulnerability found in NETGEAR's ReadyCloud client app which could allow an attacker to perform attacker-in-the-middle (MiTM) style attacks impacting the product's confidentiality. …
- CVE-2023-40012MEDIUMCVSS 5.9EG 5.92023-08-09
uthenticode is a small cross-platform library for partially verifying Authenticode digital signatures. Versions of uthenticode prior to the 2.x series did not check Extended Key Usages in certificates, in violation of the Authenticode X.50…
- CVE-2016-9574MEDIUMCVSS 5.9EG 5.92018-07-19
nss before version 3.30 is vulnerable to a remote denial of service during the session handshake when using SessionTicket extension and ECDHE-ECDSA.
- CVE-2020-10702MEDIUMCVSS 5.5EG 5.52020-06-04
A flaw was found in QEMU in the implementation of the Pointer Authentication (PAuth) support for ARM introduced in version 4.0 and fixed in version 5.0.0. A general failure of the signature generation process caused every PAuth-enforced po…
- CVE-2026-29142MEDIUMCVSS 5.3EG 5.32026-04-02
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to forge a GINA-encrypted email.
- CVE-2023-36539MEDIUMCVSS 5.3EG 5.32023-06-30
Exposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information.
- CVE-2021-31386MEDIUMCVSS 5.3EG 5.32021-10-19
A Protection Mechanism Failure vulnerability in the J-Web HTTP service of Juniper Networks Junos OS allows a remote unauthenticated attacker to perform Person-in-the-Middle (PitM) attacks against the device. This issue affects: Juniper Net…
Map vulnerabilities like CWE-325 to your infrastructure
EchelonGraph correlates every CVE — across CWE-325 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →