CWE-326— Inadequate Encryption Strength
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.— MITRE CWE catalog
562 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-326page 2 of 12
- CVE-2016-3034MEDIUMCVSS 4.4EG 4.42017-02-01
IBM AppScan Source uses a one-way hash without salt to encrypt highly sensitive information, which could allow a local attacker to decrypt information more easily.
- CVE-2016-4685MEDIUMCVSS 5.9EG 5.92017-02-20
An issue was discovered in certain Apple products. iOS before 10.1 is affected. The issue involves the "iTunes Backup" component, which improperly hashes passwords, making it easier to decrypt files.
- CVE-2016-4693HIGHCVSS 7.5EG 7.52017-02-20
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "Security" component, which makes it easier for attackers to bypass …
- CVE-2016-5056HIGHCVSS 7.5EG 7.52017-04-10
OSRAM SYLVANIA Osram Lightify Pro before 2016-07-26 uses only 8 hex digits for a PSK.
- CVE-2016-5804CRITICALCVSS 9.8EG 9.82016-07-15
Moxa MGate MB3180 before 1.8, MGate MB3280 before 2.7, MGate MB3480 before 2.6, MGate MB3170 before 2.5, and MGate MB3270 before 2.7 use weak encryption, which allows remote attackers to bypass authentication via a brute-force series of gu…
- CVE-2016-5919HIGHCVSS 7.5EG 7.52017-02-16
IBM Security Access Manager for Web 7.0.0, 8.0.0, and 9.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM Reference #: 1996868.
- CVE-2016-6225MEDIUMCVSS 5.9EG 5.92017-03-23
xbcrypt in Percona XtraBackup before 2.3.6 and 2.4.x before 2.4.5 does not properly set the initialization vector (IV) for encryption, which makes it easier for context-dependent attackers to obtain sensitive information from encrypted bac…
- CVE-2016-7798HIGHCVSS 7.5EG 7.52017-01-30
The openssl gem for Ruby uses the same initialization vector (IV) in GCM Mode (aes-*-gcm) when the IV is set before the key, which makes it easier for context-dependent attackers to bypass the encryption protection mechanism.
- CVE-2016-9121CRITICALCVSS 9.1EG 9.12017-03-28
go-jose before 1.0.4 suffers from an invalid curve attack for the ECDH-ES algorithm. When deriving a shared key using ECDH-ES for an encrypted message, go-jose neglected to check that the received public key on a message is on the same cur…
- CVE-2017-1000486CRITICALCVSS 9.8EG 9.8⚠ KEV2018-01-03
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
- CVE-2017-11317CRITICALCVSS 9.8EG 9.8⚠ KEV2017-08-23
Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload encryption, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.
- CVE-2017-1179MEDIUMCVSS 5.9EG 5.92017-06-08
IBM BigFix Compliance Analytics 1.9.79 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 123431.
- CVE-2017-1224HIGHCVSS 7.5EG 7.52017-07-19
IBM Tivoli Endpoint Manager uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 123903.
- CVE-2017-1255HIGHCVSS 7.5EG 7.52018-05-02
IBM Security Guardium 10.0, 10.0.1, and 10.1 through 10.1.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 124675.
- CVE-2017-1271HIGHCVSS 7.5EG 7.52017-12-07
IBM Security Guardium 9.0, 9.1, and 9.5 supports interaction between multiple actors and allows those actors to negotiate which algorithm should be used as a protection mechanism such as encryption or authentication, but it does not select…
- CVE-2017-12871MEDIUMCVSS 5.9EG 5.92017-09-01
The aesEncrypt method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.x through 1.14.11 makes it easier for context-dependent attackers to bypass the encryption protection mechanism by leveraging use of the first 16 bytes of the s…
- CVE-2017-1319HIGHCVSS 7.5EG 7.52017-06-08
IBM Tivoli Federated Identity Manager 6.2 is affected by a vulnerability due to a missing secure attribute in encrypted session (SSL) cookie. IBM X-Force ID: 125731.
- CVE-2017-1366HIGHCVSS 5.9EG 7.52018-08-06
IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 126859.
- CVE-2017-13699HIGHCVSS 7.5EG 7.52017-11-23
An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. The password encryption method can be retrieved from the firmware. This encryption method is based on a chall value that is sent in cleartext as a POST parameter. An att…
- CVE-2017-1375HIGHCVSS 7.5EG 7.52017-10-24
IBM System Storage Storwize V7000 Unified (V7000U) 1.5 and 1.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 126868.
- CVE-2017-14090CRITICALCVSS 9.1EG 9.12017-12-16
A vulnerability in Trend Micro ScanMail for Exchange 12.0 exists in which some communications to the update servers are not encrypted.
- CVE-2017-14262HIGHCVSS 8.1EG 8.12017-09-11
On Samsung NVR devices, remote attackers can read the MD5 password hash of the 'admin' account via certain szUserName JSON data to cgi-bin/main-cgi, and login to the device with that hash in the szUserPasswd parameter.
- CVE-2017-1473HIGHCVSS 7.5EG 7.52018-04-23
IBM Security Access Manager Appliance 8.0.0 through 8.0.1.6 and 9.0.0 through 9.0.3.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 128605.
- CVE-2017-14797HIGHCVSS 7.5EG 7.52017-10-01
Lack of Transport Encryption in the public API in Philips Hue Bridge BSB002 SW 1707040932 allows remote attackers to read API keys (and consequently bypass the pushlink protection mechanism, and obtain complete control of the connected acc…
- CVE-2017-16632HIGHCVSS 7.5EG 7.52021-08-11
In SapphireIMS 4097_1, the password in the database is stored in Base64 format.
- CVE-2017-1664MEDIUMCVSS 5.9EG 5.92018-01-04
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 133557.
- CVE-2017-1665MEDIUMCVSS 5.9EG 5.92018-01-04
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 133559.
- CVE-2017-16726CRITICALCVSS 9.1EG 9.12018-06-27
Beckhoff TwinCAT supports communication over ADS. ADS is a protocol for industrial automation in protected environments. ADS has not been designed to achieve security purposes and therefore does not include any encryption algorithms becaus…
- CVE-2017-1695HIGHCVSS 5.9EG 7.52019-02-15
IBM QRadar SIEM 7.2 and 7.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 134177.
- CVE-2017-1701HIGHCVSS 8.8EG 8.82018-04-23
IBM Team Concert (RTC) 5.0, 5.0.1, 5.0.2, 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, and 6.0.5 stores credentials for users using a weak encryption algorithm, which could allow an authenticated user to obtain highly sensitive information. IBM X-Forc…
- CVE-2017-1712MEDIUMCVSS 5.9EG 5.92020-07-01
"A vulnerability in the TLS protocol implementation of the Domino server could allow an unauthenticated, remote attacker to access sensitive information, aka a Return of Bleichenbacher's Oracle Threat (ROBOT) attack. An attacker could iter…
- CVE-2017-1713MEDIUMCVSS 5.9EG 5.92019-03-21
IBM InfoSphere Streams 4.2.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 134632.
- CVE-2017-17436HIGHCVSS 8.8EG 8.82017-12-07
An issue was discovered in the software on Vaultek Gun Safe VT20i products. There is no encryption of the session between the Android application and the safe. The website and marketing materials advertise that this communication channel i…
- CVE-2017-17543HIGHCVSS 7.5EG 7.52018-04-26
Users' VPN authentication credentials are unsafely encrypted in Fortinet FortiClient for Windows 5.6.0 and below versions, FortiClient for Mac OSX 5.6.0 and below versions and FortiClient SSLVPN Client for Linux 4.4.2335 and below versions…
- CVE-2017-20001HIGHCVSS 7.5EG 7.52021-01-01
The AES encryption project 7.x and 8.x for Drupal does not sufficiently prevent attackers from decrypting data, aka SA-CONTRIB-2017-027. NOTE: This project is not covered by Drupal's security advisory policy.
- CVE-2017-2380HIGHCVSS 7.5EG 7.52017-04-02
An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves the Simple Certificate Enrollment Protocol (SCEP) implementation in the "Profiles" component. It allows remote attackers to bypass crypto…
- CVE-2017-2391MEDIUMCVSS 5.3EG 5.32017-04-02
An issue was discovered in certain Apple products. Pages before 6.1, Numbers before 4.1, and Keynote before 7.1 on macOS and Pages before 3.1, Numbers before 3.1, and Keynote before 3.1 on iOS are affected. The issue involves the "Export" …
- CVE-2017-2399MEDIUMCVSS 4.6EG 4.62017-04-02
An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves the "Pasteboard" component. It allows physically proximate attackers to read the pasteboard by leveraging the use of an encryption key deriv…
- CVE-2017-2598MEDIUMCVSS 4.3EG 4.32018-05-23
Jenkins before versions 2.44, 2.32.2 uses AES ECB block cipher mode without IV for encrypting secrets which makes Jenkins and the stored secrets vulnerable to unnecessary risks (SECURITY-304).
- CVE-2017-3971HIGHCVSS 8.2EG 8.22018-04-04
Cryptanalysis vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows attackers to view confidential information via insecure use of RC4 encryption cyphers.
- CVE-2017-5160MEDIUMCVSS 5.3EG 5.32017-04-20
An Inadequate Encryption Strength issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. The software will connect via Transport Layer Security without verifying the peer's SSL certificate …
- CVE-2017-5239HIGHCVSS 7.5EG 7.52017-03-27
Due to a lack of standard encryption when transmitting sensitive information over the internet to a centralized monitoring service, the Eview EV-07S GPS Tracker discloses personally identifying information, such as GPS data and IMEI number…
- CVE-2017-5535MEDIUMCVSS 6.8EG 6.82018-05-01
The GridServer Broker, GridServer Driver, and GridServer Engine components of TIBCO Software Inc. TIBCO DataSynapse GridServer Manager contain vulnerabilities related to both the improper use of encryption mechanisms and the use of weak ci…
- CVE-2017-5999HIGHCVSS 7.5EG 7.52017-03-06
An issue was discovered in sysPass 2.x before 2.1, in which an algorithm was never sufficiently reviewed by cryptographers. The fact that inc/SP/Core/Crypt.class is using the MCRYPT_RIJNDAEL_256() function (the 256-bit block version of Rij…
- CVE-2017-6284MEDIUMCVSS 5.5EG 5.52018-03-06
NVIDIA Security Engine contains a vulnerability in the Deterministic Random Bit Generator (DRBG) where the DRBG does not properly initialize and store or transmits sensitive data using a weakened encryption scheme that is unable to protect…
- CVE-2017-7229CRITICALCVSS 9.1EG 9.12017-05-03
PGP/MIME encrypted messages injected into a Vaultive O365 (before 4.5.21) frontend via IMAP or SMTP have their Content-Type changed from 'Content-Type: multipart/encrypted; protocol="application/pgp-encrypted"; boundary="abc123abc123"' to …
- CVE-2017-7673CRITICALCVSS 9.8EG 9.82017-07-17
Apache OpenMeetings 1.0.0 uses not very strong cryptographic storage, captcha is not used in registration and forget password dialogs and auth forms missing brute force protection.
- CVE-2017-7888CRITICALCVSS 9.8EG 9.82017-05-10
Dolibarr ERP/CRM 4.0.4 stores passwords with the MD5 algorithm, which makes brute-force attacks easier.
- CVE-2017-7903CRITICALCVSS 9.8EG 9.82017-06-30
A Weak Password Requirements issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-logic controllers 1763-L16AWA, Series A and B, Version 16.00 and prior versions; 1763-L16BBB, Series A and B, Version 16.00…
- CVE-2017-7905CRITICALCVSS 9.8EG 9.82017-06-30
A Weak Cryptography for Passwords issue was discovered in General Electric (GE) Multilin SR 750 Feeder Protection Relay, firmware versions prior to Version 7.47; SR 760 Feeder Protection Relay, firmware versions prior to Version 7.47; SR 4…
Map vulnerabilities like CWE-326 to your infrastructure
EchelonGraph correlates every CVE — across CWE-326 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →