CWE-330— Use of Insufficiently Random Values
The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.— MITRE CWE catalog
412 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-330page 4 of 9
- CVE-2023-41879HIGHCVSS 7.5EG 7.52023-09-11
Magento LTS is the official OpenMage LTS codebase. Guest orders may be viewed without authentication using a "guest-view" cookie which contains the order's "protect_code". This code is 6 hexadecimal characters which is arguably not enough …
- CVE-2023-34353HIGHCVSS 7.5EG 7.52023-09-05
An authentication bypass vulnerability exists in the OAS Engine authentication functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted network sniffing can lead to decryption of sensitive information. An att…
- CVE-2023-26451HIGHCVSS 7.5EG 7.52023-08-02
Functions with insufficient randomness were used to generate authorization tokens of the integrated oAuth Authorization Service. Authorization codes were predictable for third parties and could be used to intercept and take over the client…
- CVE-2023-30797HIGHCVSS 7.5EG 7.52023-04-19
Netflix Lemur before version 1.3.2 used insufficiently random values when generating default credentials. The insufficiently random values may allow an attacker to guess the credentials and gain access to resources managed by Lemur.
- CVE-2023-26855HIGHCVSS 7.5EG 7.52023-04-04
The hashing algorithm of ChurchCRM v4.5.3 utilizes a non-random salt value which allows attackers to use precomputed hash tables or dictionary attacks to crack the hashed passwords.
- CVE-2022-29808HIGHCVSS 7.5EG 7.52022-08-02
In Quest KACE Systems Management Appliance (SMA) through 12.0, predictable token generation occurs when appliance linking is enabled.
- CVE-2022-26306HIGHCVSS 7.5EG 7.52022-07-25
LibreOffice supports the storage of passwords for web connections in the user’s configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in LibreOffice existed where the required in…
- CVE-2022-31157HIGHCVSS 7.5EG 7.52022-07-15
LTI 1.3 Tool Library is a library used for building IMS-certified LTI 1.3 tool providers in PHP. Prior to version 5.0, the function used to generate random nonces was not sufficiently cryptographically complex. Users should upgrade to vers…
- CVE-2022-32284HIGHCVSS 7.5EG 7.52022-07-04
Use of insufficiently random values vulnerability exists in Vnet/IP communication module VI461 of YOKOGAWA Wide Area Communication Router (WAC Router) AW810D, which may allow a remote attacker to cause denial-of-service (DoS) condition by …
- CVE-2022-23138HIGHCVSS 7.5EG 7.52022-06-09
ZTE's MF297D product has cryptographic issues vulnerability. Due to the use of weak random values, the security of the device is reduced, and it may face the risk of attack.
- CVE-2019-25061HIGHCVSS 7.5EG 7.52022-05-18
The random_password_generator (aka RandomPasswordGenerator) gem through 1.0.0 for Ruby uses Kernel#rand to generate passwords, which, due to its cyclic nature, can facilitate password prediction.
- CVE-2022-30782HIGHCVSS 7.5EG 7.52022-05-16
Openmoney API through 2020-06-29 uses the JavaScript Math.random function, which does not provide cryptographically secure random numbers.
- CVE-2022-22517HIGHCVSS 7.5EG 7.52022-04-07
An unauthenticated, remote attacker can disrupt existing communication channels between CODESYS products by guessing a valid channel ID and injecting packets. This results in the communication channel to be closed.
- CVE-2022-28355HIGHCVSS 7.5EG 7.52022-04-02
randomUUID in Scala.js before 1.10.0 generates predictable values.
- CVE-2021-45458HIGHCVSS 7.5EG 7.52022-01-06
Apache Kylin provides encryption classes PasswordPlaceholderConfigurer to help users encrypt their passwords. In the encryption algorithm used by this encryption class, the cipher is initialized with a hardcoded key and IV. If users use cl…
- CVE-2021-24998HIGHCVSS 7.5EG 7.52021-12-27
The Simple JWT Login WordPress plugin before 3.3.0 can be used to create new WordPress user accounts with a randomly generated password. The password is generated using the str_shuffle PHP function that "does not generate cryptographicall…
- CVE-2021-45488HIGHCVSS 7.5EG 7.52021-12-25
In NetBSD through 9.2, there is an information leak in the TCP ISN (ISS) generation algorithm.
- CVE-2021-45487HIGHCVSS 7.5EG 7.52021-12-25
In NetBSD through 9.2, the IPv4 ID generation algorithm does not use appropriate cryptographic measures.
- CVE-2021-44151HIGHCVSS 7.5EG 7.52021-12-13
An issue was discovered in Reprise RLM 14.2. As the session cookies are small, an attacker can hijack any existing sessions by bruteforcing the 4 hex-character session cookie on the Windows version (the Linux version appears to have 8 char…
- CVE-2021-26322HIGHCVSS 7.5EG 7.52021-11-16
Persistent platform private key may not be protected with a random IV leading to a potential “two time pad attack”.
- CVE-2021-41829HIGHCVSS 7.5EG 7.52021-09-30
Zoho ManageEngine Remote Access Plus before 10.1.2121.1 relies on the application's build number to calculate a certain encryption key.
- CVE-2021-31228HIGHCVSS 7.5EG 7.52021-08-19
An issue was discovered in HCC embedded InterNiche 4.0.1. This vulnerability allows the attacker to predict a DNS query's source port in order to send forged DNS response packets that will be accepted as valid answers to the DNS client's r…
- CVE-2021-3689HIGHCVSS 7.5EG 7.52021-08-10
yii2 is vulnerable to Use of Predictable Algorithm in Random Number Generator
- CVE-2021-0466HIGHCVSS 7.5EG 7.52021-06-11
In startIpClient of ClientModeImpl.java, there is a possible identifier which could be used to track a device. This could lead to remote information disclosure to a proximal attacker, with no additional execution privileges needed. User in…
- CVE-2021-29499HIGHCVSS 7.5EG 7.52021-05-07
SIF is an open source implementation of the Singularity Container Image Format. The `siftool new` command and func siftool.New() produce predictable UUID identifiers due to insecure randomness in the version of the `github.com/satori/go.uu…
- CVE-2021-22309HIGHCVSS 7.5EG 7.52021-03-22
There is insecure algorithm vulnerability in Huawei products. A module uses less random input in a secure mechanism. Attackers can exploit this vulnerability by brute forcing to obtain sensitive message. This can lead to information leak. …
- CVE-2020-13860HIGHCVSS 7.5EG 7.52021-02-01
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. The one-time password algorithm for the undocumented system account mofidev generates a predictable six-digit password.
- CVE-2020-26550HIGHCVSS 7.5EG 7.52020-11-17
An issue was discovered in Aviatrix Controller before R5.3.1151. An encrypted file containing credentials to unrelated systems is protected by a three-character key.
- CVE-2020-27180HIGHCVSS 7.5EG 7.52020-10-27
konzept-ix publiXone before 2020.015 allows attackers to download files by iterating over the IXCopy fileID parameter.
- CVE-2020-26107HIGHCVSS 7.5EG 7.52020-09-25
cPanel before 88.0.3, upon an upgrade, establishes predictable PowerDNS API keys (SEC-561).
- CVE-2020-12712HIGHCVSS 7.5EG 7.52020-06-11
A vulnerability based on insecure user/password encryption in the JOE (job editor) component of SOS JobScheduler 1.12 and 1.13 allows attackers to decrypt the user/password that is optionally stored with a user's profile.
- CVE-2020-12858HIGHCVSS 7.5EG 7.52020-05-18
Non-reinitialisation of random data in the advertising payload in COVIDSafe v1.0.15 and v1.0.16 allows a remote attacker to re-identify Android devices running COVIDSafe by scanning for their advertising beacons.
- CVE-2020-11877HIGHCVSS 7.5EG 7.52020-04-17
airhost.exe in Zoom Client for Meetings 4.6.11 uses 3423423432325249 as the Initialization Vector (IV) for AES-256 CBC encryption. NOTE: the vendor states that this IV is used only within unreachable code
- CVE-2020-7241HIGHCVSS 7.5EG 7.52020-01-20
The WP Database Backup plugin through 5.5 for WordPress stores downloads by default locally in the directory wp-content/uploads/db-backup/. This might allow attackers to read ZIP archives by guessing random ID numbers, guessing date string…
- CVE-2012-1562HIGHCVSS 7.5EG 7.52020-01-15
Joomla! core before 2.5.3 allows unauthorized password change.
- CVE-2019-18850HIGHCVSS 7.5EG 7.52019-12-04
TrevorC2 v1.1/v1.2 fails to prevent fingerprinting primarily via a discrepancy between response headers when responding to different HTTP methods, also via predictible responses when accessing and interacting with the "SITE_PATH_QUERY".
- CVE-2019-5232HIGHCVSS 7.5EG 7.52019-11-29
There is a use of insufficiently random values vulnerability in Huawei ViewPoint products. An unauthenticated, remote attacker can guess information by a large number of attempts. Successful exploitation may cause information leak.
- CVE-2019-10084HIGHCVSS 7.5EG 7.52019-11-05
In Apache Impala 2.7.0 to 3.2.0, an authenticated user with access to the IDs of active Impala queries or sessions can interact with those sessions or queries via a specially-constructed request and thereby potentially bypass authorization…
- CVE-2019-7886HIGHCVSS 7.5EG 7.52019-08-02
A cryptograhic flaw exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. A weak cryptograhic mechanism is used to generate the intialization vector in multiple security relevant contexts.
- CVE-2019-11641HIGHCVSS 7.5EG 7.52019-05-01
Anomali Agave (formerly Drupot) through 1.0.0 fails to avoid fingerprinting by including predictable data and minimal variation in size within HTML templates, giving attackers the ability to detect and avoid this system.
- CVE-2019-9860HIGHCVSS 7.5EG 7.52019-03-27
Due to unencrypted signal communication and predictability of rolling codes, an attacker can "desynchronize" an ABUS Secvest wireless remote control (FUBE50014 or FUBE50015) relative to its controlled Secvest wireless alarm system FUAA5000…
- CVE-2019-5885HIGHCVSS 7.5EG 7.52019-03-21
Matrix Synapse before 0.34.0.1, when the macaroon_secret_key authentication parameter is not set, uses a predictable value to derive a secret key and other secrets which could allow remote attackers to impersonate users.
- CVE-2019-1997HIGHCVSS 7.5EG 7.52019-02-28
In random_get_bytes of random.c, there is a possible degradation of randomness due to an insecure default value. This could lead to local information disclosure via an insecure wireless connection with no additional execution privileges ne…
- CVE-2018-20025HIGHCVSS 7.5EG 7.52019-02-19
Use of Insufficiently Random Values exists in CODESYS V3 products versions prior V3.5.14.0.
- CVE-2019-8919HIGHCVSS 7.5EG 7.52019-02-18
The seadroid (aka Seafile Android Client) application through 2.2.13 for Android always uses the same Initialization Vector (IV) with Cipher Block Chaining (CBC) Mode to encrypt private data, making it easier to conduct chosen-plaintext at…
- CVE-2018-17987HIGHCVSS 7.5EG 7.52018-12-26
The determineWinner function of a smart contract implementation for HashHeroes Tiles, an Ethereum game, uses a certain blockhash value in an attempt to generate a random number for the case where NUM_TILES equals the number of people who p…
- CVE-2017-16031HIGHCVSS 7.5EG 7.52018-06-04
Socket.io is a realtime application framework that provides communication via websockets. Because socket.io 0.9.6 and earlier depends on `Math.random()` to create socket IDs, the IDs are predictable. An attacker is able to guess the socket…
- CVE-2017-10874HIGHCVSS 7.5EG 7.52017-12-01
PWR-Q200 does not use random values for source ports of DNS query packets, which allows remote attackers to conduct DNS cache poisoning attacks.
- CVE-2017-0897HIGHCVSS 7.5EG 7.52017-06-22
ExpressionEngine version 2.x < 2.11.8 and version 3.x < 3.5.5 create an object signing token with weak entropy. Successfully guessing the token can lead to remote code execution.
- CVE-2013-7463HIGHCVSS 7.5EG 7.52017-04-19
The aescrypt gem 1.0.0 for Ruby does not randomize the CBC IV for use with the AESCrypt.encrypt and AESCrypt.decrypt functions, which allows attackers to defeat cryptographic protection mechanisms via a chosen plaintext attack.
Map vulnerabilities like CWE-330 to your infrastructure
EchelonGraph correlates every CVE — across CWE-330 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →