CWE-326— Inadequate Encryption Strength
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.— MITRE CWE catalog
562 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-326page 1 of 12
- CVE-2001-1546HIGHCVSS 7.8EG 7.82001-12-31
Pathways Homecare 6.5 uses weak encryption for user names and passwords, which allows local users to gain privileges by recovering the passwords from the pwhc.ini file.
- CVE-2002-1682MEDIUMCVSS 5.5EG 5.52002-12-31
NewsReactor 1.0 uses a weak encryption scheme, which could allow local users to decrypt the passwords and gain access to other users' newsgroup accounts.
- CVE-2002-1697HIGHCVSS 7.5EG 7.52002-12-31
Electronic Code Book (ECB) mode in VTun 2.0 through 2.5 uses a weak encryption algorithm that produces the same ciphertext from the same plaintext blocks, which could allow remote attackers to gain sensitive information.
- CVE-2002-1739MEDIUMCVSS 5.5EG 5.52002-12-31
Alt-N Technologies Mdaemon 5.0 through 5.0.6 uses a weak encryption algorithm to store user passwords, which allows local users to crack passwords.
- CVE-2002-1872HIGHCVSS 7.5EG 7.52002-12-31
Microsoft SQL Server 6.0 through 2000, with SQL Authentication enabled, uses weak password encryption (XOR), which allows remote attackers to sniff and decrypt the password.
- CVE-2002-1910HIGHCVSS 7.5EG 7.52002-12-31
Click2Learn Ingenium Learning Management System 5.1 and 6.1 uses weak encryption for passwords (reversible algorithm), which allows attackers to obtain passwords.
- CVE-2002-1946MEDIUMCVSS 5.5EG 5.52002-12-31
Videsh Sanchar Nigam Limited (VSNL) Integrated Dialer Software 1.2.000, when the "Save Password" option is used, stores the password with a weak encryption scheme (one-to-one mapping) in a registry key, which allows local users to obtain a…
- CVE-2002-1975MEDIUMCVSS 5.5EG 5.52002-12-31
Sharp Zaurus PDA SL-5000D and SL-5500 uses a salt of "A0" to encrypt the screen-locking password as stored in the Security.conf file, which makes it easier for local users to guess the password via brute force methods.
- CVE-2004-2172HIGHCVSS 7.5EG 7.52004-12-31
EarlyImpact ProductCart uses a weak encryption scheme to encrypt passwords, which allows remote attackers to obtain the password via a chosen plaintext attack.
- CVE-2005-0366MEDIUMCVSS v2 5.0EG 5.02005-05-02
The integrity check feature in OpenPGP, when handling a message that was encrypted using cipher feedback (CFB) mode, allows remote attackers to recover part of the plaintext via a chosen-ciphertext attack when the first 2 bytes of a messag…
- CVE-2005-2281HIGHCVSS 7.5EG 7.52005-07-18
WebEOC before 6.0.2 uses a weak encryption scheme for passwords, which makes it easier for attackers to crack passwords.
- CVE-2005-4900MEDIUMCVSS 5.9EG 5.92016-10-14
SHA-1 is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of SHA-1 in TLS 1.2. NOTE: this CVE exists to provide a common identifier for refer…
- CVE-2008-3188HIGHCVSS 7.5EG 7.52008-07-22
libxcrypt in SUSE openSUSE 11.0 uses the DES algorithm when the configuration specifies the MD5 algorithm, which makes it easier for attackers to conduct brute-force attacks against hashed passwords.
- CVE-2009-2474MEDIUMCVSS v2 5.8EG 5.82009-08-21
neon before 0.28.6, when OpenSSL or GnuTLS is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL…
- CVE-2010-3670MEDIUMCVSS 4.8EG 4.82019-11-05
TYPO3 before 4.3.4 and 4.4.x before 4.4.1 contains insecure randomness during generation of a hash with the "forgot password" function.
- CVE-2011-3389MEDIUMCVSS v2 4.3EG 4.32011-09-06
The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which…
- CVE-2011-3629HIGHCVSS 7.5EG 7.52020-02-04
Joomla! core 1.7.1 allows information disclosure due to weak encryption
- CVE-2011-4121CRITICALCVSS 9.8EG 9.82019-11-26
The OpenSSL extension of Ruby (Git trunk) versions after 2011-09-01 up to 2011-11-03 always generated an exponent value of '1' to be used for private RSA key generation. A remote attacker could use this flaw to bypass or corrupt integrity …
- CVE-2012-2130HIGHCVSS 7.4EG 7.42019-12-06
A Security Bypass vulnerability exists in PolarSSL 0.99pre4 through 1.1.1 due to a weak encryption error when generating Diffie-Hellman values and RSA keys.
- CVE-2012-6707HIGHCVSS 7.5EG 7.52017-10-19
WordPress through 4.8.2 uses a weak MD5-based password hashing algorithm, which makes it easier for attackers to determine cleartext values by leveraging access to the hash values. NOTE: the approach to changing this may not be fully compa…
- CVE-2013-0764HIGHCVSS v2 9.3EG 9.32013-01-13
The nsSOCKSSocketInfo::ConnectToProxy function in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 17.x before 17.0.2, and SeaMonkey before 2.15 does not ensure thread safety for SSL s…
- CVE-2013-2166CRITICALCVSS 9.8EG 9.82019-12-10
python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass
- CVE-2013-2566CRITICALCVSS 5.9EG 9.02013-03-15
The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct plaintext-recovery attacks via statistical analysis of ciphertext in a large number of sess…
- CVE-2013-4104HIGHCVSS 7.5EG 7.52019-11-04
Cryptocat before 2.0.22 has weak encryption in the Socialist Millionnaire Protocol
- CVE-2013-4508HIGHCVSS 7.5EG 7.52013-11-08
lighttpd before 1.4.34, when SNI is enabled, configures weak SSL ciphers, which makes it easier for remote attackers to hijack sessions by inserting packets into the client-server data stream or obtain sensitive information by sniffing the…
- CVE-2013-7286HIGHCVSS 7.5EG 7.52020-02-12
MobileIron VSP < 5.9.1 and Sentry < 5.0 has a weak password obfuscation algorithm
- CVE-2013-7287CRITICALCVSS 9.8EG 9.82020-02-13
MobileIron VSP < 5.9.1 and Sentry < 5.0 has an insecure encryption scheme.
- CVE-2013-7469HIGHCVSS 7.5EG 7.52019-02-21
Seafile through 6.2.11 always uses the same Initialization Vector (IV) with Cipher Block Chaining (CBC) Mode to encrypt private data, making it easier to conduct chosen-plaintext attacks or dictionary attacks.
- CVE-2013-7484HIGHCVSS 7.5EG 7.52019-11-30
Zabbix before 5.0 represents passwords in the users table with unsalted MD5.
- CVE-2014-0224CRITICALCVSS 7.4EG 9.02014-06-05
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL…
- CVE-2014-0841MEDIUMCVSS 5.3EG 5.32018-04-27
IBM Rational Focal Point 6.4.0, 6.4.1, 6.5.1, 6.5.2, and 6.6.0 use a weak algorithm to hash passwords, which makes it easier for context-dependent attackers to obtain cleartext values via a brute-force attack. IBM X-Force ID: 90704.
- CVE-2014-1491MEDIUMCVSS v2 4.3EG 4.32014-02-06
Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, does not properly restrict public values in Di…
- CVE-2014-2380HIGHCVSS v2 7.8EG 7.82014-08-28
Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 uses weak encryption, which allows remote attackers to obtain sensitive information by reading a credential file.
- CVE-2014-2381LOWCVSS v2 2.1EG 2.12014-08-28
Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 uses weak encryption, which allows local users to obtain sensitive information by reading a credential file.
- CVE-2014-9199MEDIUMCVSS v2 5.0EG 5.02015-01-17
The Clorius Controls Java web client before 01.00.0009g allows remote attackers to discover credentials by sniffing the network for cleartext-equivalent traffic.
- CVE-2014-9975CRITICALCVSS 9.8EG 9.82017-08-18
In all Qualcomm products with Android releases from CAF using the Linux kernel, a rollback vulnerability potentially exists in Full Disk Encryption.
- CVE-2015-0575CRITICALCVSS 9.8EG 9.82017-08-18
In all Qualcomm products with Android releases from CAF using the Linux kernel, insecure ciphersuites were included in the default configuration.
- CVE-2015-4953MEDIUMCVSS 4.8EG 4.82018-03-29
IBM BigFix Remote Control before Interim Fix pack 9.1.2-TIV-IBRC912-IF0001 makes it easier for man-in-the-middle attackers to decrypt traffic by leveraging a weakness in its encryption protocol. IBM X-Force ID: 105197.
- CVE-2015-5361MEDIUMCVSS 6.5EG 6.52020-02-28
Background For regular, unencrypted FTP traffic, the FTP ALG can inspect the unencrypted control channel and open related sessions for the FTP data channel. These related sessions (gates) are specific to source and destination IPs and port…
- CVE-2015-7449LOWCVSS 3.3EG 3.32018-03-20
IBM Rational Collaborative Lifecycle Management (CLM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, 6.0.x before 6.0.1 iFix5, and 6.0.2 before iFix2; Rational Quality Manager (RQM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix…
- CVE-2015-8085MEDIUMCVSS 4.9EG 4.92016-10-03
Huawei AR routers with software before V200R007C00SPC100; Quidway S9300 routers with software before V200R009C00; S12700 routers with software before V200R008C00SPC500; S9300, Quidway S5300, and S5300 routers with software before V200R007C…
- CVE-2015-8086MEDIUMCVSS 4.9EG 4.92016-10-03
Huawei AR routers with software before V200R007C00SPC100; Quidway S9300 routers with software before V200R009C00; S12700 routers with software before V200R008C00SPC500; S9300, Quidway S5300, and S5300 routers with software before V200R007C…
- CVE-2016-10101HIGHCVSS 8.1EG 8.12017-01-23
Information Disclosure can occur in Hitek Software's Automize 10.x and 11.x passManager.jsd. Users have the Read attribute, which allows an attacker to recover the encrypted password to access the Password Manager.
- CVE-2016-10102HIGHCVSS 8.1EG 8.12017-01-23
hitek.jar in Hitek Software's Automize uses weak encryption when encrypting SSH/SFTP and Encryption profile passwords. This allows an attacker to retrieve the encrypted passwords from sshProfiles.jsd and encryptionProfiles.jsd and decrypt …
- CVE-2016-10103HIGHCVSS 8.1EG 8.12017-01-23
Information Disclosure can occur in encryptionProfiles.jsd in Hitek Software's Automize because of the Read attribute being set for Users. This allows an attacker to recover encrypted passwords for GPG Encryption profiles. Verified in all …
- CVE-2016-10104MEDIUMCVSS 5.9EG 5.92017-01-23
Information Disclosure can occur in sshProfiles.jsd in Hitek Software's Automize because of the Read attribute being set for Users. This allows an attacker to recover encrypted passwords for SSH/SFTP profiles. Verified in all 10.x versions…
- CVE-2016-11043HIGHCVSS 7.5EG 7.52020-04-07
An issue was discovered on Samsung mobile devices with M(6.0) software. The S/MIME implementation in EAS uses DES (where 3DES is intended). The Samsung ID is SVE-2016-5871 (June 2016).
- CVE-2016-2379HIGHCVSS 8.8EG 8.82017-03-29
The Mxit protocol uses weak encryption when encrypting user passwords, which might allow attackers to (1) decrypt hashed passwords by leveraging knowledge of client registration codes or (2) gain login access by eavesdropping on login mess…
- CVE-2016-2879HIGHCVSS 7.8EG 7.82017-03-01
IBM QRadar 7.2 uses outdated hashing algorithms to hash certain passwords, which could allow a local user to obtain and decrypt user credentials. IBM Reference #: 1997341.
- CVE-2016-3019MEDIUMCVSS 6.5EG 6.52017-06-07
IBM Security Access Manager for Web 9.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 114462.
Map vulnerabilities like CWE-326 to your infrastructure
EchelonGraph correlates every CVE — across CWE-326 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →