CWE-331— Insufficient Entropy
The product uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.— MITRE CWE catalog
147 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-331page 1 of 3
- CVE-2026-13639CRITICALCVSS 9.8EG 9.82026-09-18
An insufficient entropy vulnerability in login logic in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-ser…
- CVE-2026-38447CRITICALCVSS 9.8EG 9.82026-08-03
osTicket 1.18.3 generates API keys using a predictable construction based on MD5 hashing. The use of MD5, combined with predictable inputs such as the current timestamp and client IP address, significantly reduces entropy. An attacker can …
- CVE-2020-36925CRITICALCVSS 9.8EG 9.82026-01-06
Arteco Web Client DVR/NVR contains a session hijacking vulnerability with insufficient session ID complexity that allows remote attackers to bypass authentication. Attackers can brute force session IDs within a specific numeric range to ob…
- CVE-2025-67504CRITICALCVSS 9.8EG 9.82025-12-09
WBCE CMS is a content management system. Versions 1.6.4 and below use function GenerateRandomPassword() to create passwords using PHP's rand(). rand() is not cryptographically secure, which allows password sequences to be predicted or brut…
- CVE-2025-66565CRITICALCVSS 9.8EG 9.82025-12-09
Fiber Utils is a collection of common functions created for Fiber. In versions 2.0.0-rc.3 and below, when the system's cryptographic random number generator (crypto/rand) fails, both functions silently fall back to returning predictable UU…
- CVE-2025-47781CRITICALCVSS 9.8EG 9.82025-05-14
Rallly is an open-source scheduling and collaboration tool. Versions up to and including 3.22.1 of the application features token based authentication. When a user attempts to login to the application, they insert their email and a 6 digit…
- CVE-2024-47945CRITICALCVSS 9.8EG 9.82024-10-15
The devices are vulnerable to session hijacking due to insufficient entropy in its session ID generation algorithm. The session IDs are predictable, with only 32,768 possible values per user, which allows attackers to pre-generate valid…
- CVE-2024-25730CRITICALCVSS 9.8EG 9.82024-02-23
Hitron CODA-4582 and CODA-4589 devices have default PSKs that are generated from 5-digit hex values concatenated with a "Hitron" substring, resulting in insufficient entropy (only about one million possibilities).
- CVE-2023-49599CRITICALCVSS 9.8EG 9.82024-01-10
An insufficient entropy vulnerability exists in the salt generation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted series of HTTP requests can lead to privilege escalation. An attacker can gather system info…
- CVE-2023-4344CRITICALCVSS 9.8EG 9.82023-08-15
Broadcom RAID Controller web interface is vulnerable to insufficient randomness due to improper use of ssl.rnd to setup CIM connection
- CVE-2022-34294CRITICALCVSS 9.8EG 9.82022-08-15
totd 1.5.3 uses a fixed UDP source port in upstream queries sent to DNS resolvers. This allows DNS cache poisoning because there is not enough entropy to prevent traffic injection attacks.
- CVE-2021-41615CRITICALCVSS 9.8EG 9.82022-08-08
websda.c in GoAhead WebServer 2.1.8 has insufficient nonce entropy because the nonce calculation relies on the hardcoded onceuponatimeinparadise value, which does not follow the secret-data guideline for HTTP Digest Access Authentication i…
- CVE-2021-36294CRITICALCVSS 9.8EG 9.82022-01-25
Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authentication bypass vulnerability. A remote unauthenticated attacker may exploit this vulnerability by forging a cookie to login as any user.
- CVE-2021-22727CRITICALCVSS 9.8EG 9.82021-07-21
A CWE-331: Insufficient Entropy vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart Wallbox (EVB1A all versio…
- CVE-2021-33027CRITICALCVSS 9.8EG 9.82021-07-19
Sylabs Singularity Enterprise through 1.6.2 has Insufficient Entropy in a nonce.
- CVE-2020-10285CRITICALCVSS 9.8EG 9.82020-07-15
The authentication implementation on the xArm controller has very low entropy, making it vulnerable to a brute-force attack. There is no mechanism in place to mitigate or lockout automated attempts to gain access.
- CVE-2020-12735CRITICALCVSS 9.8EG 9.82020-05-08
reset.php in DomainMOD 4.13.0 uses insufficient entropy for password reset requests, leading to account takeover.
- CVE-2013-2260CRITICALCVSS 9.8EG 9.82019-11-04
Cryptocat before 2.0.22: Cryptocat.random() Function Array Key has Entropy Weakness
- CVE-2018-1000620CRITICALCVSS 9.8EG 9.82018-07-09
Eran Hammer cryptiles version 4.1.1 earlier contains a CWE-331: Insufficient Entropy vulnerability in randomDigits() method that can result in An attacker is more likely to be able to brute force something that was supposed to be random.. …
- CVE-2026-7210CRITICALCVSS 7.5EG 9.82026-05-11
`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating li…
- CVE-2021-36320CRITICALCVSS 7.5EG 9.82021-11-20
Dell Networking X-Series firmware versions prior to 3.0.1.8 contain an authentication bypass vulnerability. A remote unauthenticated attacker may potentially hijack a session and access the webserver by forging the session ID.
- CVE-2020-29508CRITICALCVSS 5.3EG 9.82022-07-11
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Improper Input Validation Vulnerability.
- CVE-2024-36400CRITICALCVSS 9.4EG 9.42024-06-04
nano-id is a unique string ID generator for Rust. Affected versions of the nano-id crate incorrectly generated IDs using a reduced character set in the `nano_id::base62` and `nano_id::base58` functions. Specifically, the `base62` function …
- CVE-2026-42155CRITICALCVSS 9.3EG 9.32026-05-15
Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Prior to 20.18.0, the XML-RPC / SOAP API s…
- CVE-2024-58040CRITICALCVSS 9.1EG 9.12025-09-30
Crypt::RandomEncryption for Perl version 0.01 uses insecure rand() function during encryption.
- CVE-2024-3411CRITICALCVSS 9.1EG 9.12024-04-30
Implementations of IPMI Authenticated sessions does not provide enough randomness to protect from session hijacking, allowing an attacker to use either predictable IPMI Session ID or weak BMC Random Number to bypass security controls using…
- CVE-2021-4238CRITICALCVSS 9.1EG 9.12022-12-27
Randomly-generated alphanumeric strings contain significantly less entropy than expected. The RandomAlphaNumeric and CryptoRandomAlphaNumeric functions always return strings containing at least one digit from 0 to 9. This significantly red…
- CVE-2017-18883CRITICALCVSS 9.1EG 9.12020-06-19
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2, when serving as an OAuth 2.0 Service Provider. There is low entropy for authorization data.
- CVE-2026-71851CRITICALCVSS 9.0EG 9.02026-08-07
crypto-js is a JavaScript library of crypto standards. Versions of crypto-js prior to 4.0.0 generate randomness in CryptoJS.lib.WordArray.random() using a custom variation of the Multiply-With-Carry pseudorandom number generator, seeded fr…
- CVE-2008-1447CRITICALCVSS 6.8EG 9.02008-07-08
The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2; and other implementations allow remote attackers to spoof DNS…
- CVE-2025-50122HIGHCVSS 8.9EG 8.92025-07-11
A CWE-331: Insufficient Entropy vulnerability exists that could cause root password discovery when the password generation algorithm is reverse engineered with access to installation or upgrade artifacts.
- CVE-2026-2336HIGHCVSS 8.8EG 8.82026-04-16
A privilege escalation vulnerability in Microchip IStaX allows an authenticated low-privileged user to recover a shared per-device cookie secret from their own webstax_auth session cookie and forge a new cookie with administrative privileg…
- CVE-2025-13399HIGHCVSS 8.8EG 8.82026-01-29
A weakness in the web interface’s application layer encryption in VX800v v1.0 allows an adjacent attacker to brute force the weak AES key and decrypt intercepted traffic. Successful exploitation requires network proximity but no authenti…
- CVE-2025-15387HIGHCVSS 8.8EG 8.82025-12-31
VPN Firewall developed by QNO Technology has a Insufficient Entropy vulnerability, allowing unauthenticated remote attackers to obtain any logged-in user session through brute-force attacks and subsequently log into the system.
- CVE-2025-1828HIGHCVSS 8.8EG 8.82025-03-11
Crypt::Random Perl package 1.05 through 1.55 may use rand() function, which is not cryptographically strong, for cryptographic functions. If the Provider is not specified and /dev/urandom or an Entropy Gathering Daemon (egd) service is…
- CVE-2022-37401HIGHCVSS 8.8EG 8.82022-08-15
Apache OpenOffice supports the storage of passwords for web connections in the user's configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in OpenOffice existed where master key w…
- CVE-2026-4827HIGHCVSS 8.7EG 8.72026-05-12
CWE‑331: Insufficient Entropy vulnerability exists that could lead to unauthorized access when an attacker on the network can exploit weaknesses in session‑management protections.
- CVE-2025-52464HIGHCVSS 8.3EG 8.32025-06-19
Meshtastic is an open source mesh networking solution. In versions from 2.5.0 to before 2.6.11, the flashing procedure of several hardware vendors was resulting in duplicated public/private keys. Additionally, the Meshtastic was failing to…
- CVE-2022-31034HIGHCVSS 8.3EG 8.32022-06-27
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting with v0.11.0 are vulnerable to a variety of attacks when an SSO login is initiated from the Argo CD CLI or UI. The vulnerabilities a…
- CVE-2023-46648HIGHCVSS 7.5EG 8.32023-12-21
An insufficient entropy vulnerability was identified in GitHub Enterprise Server (GHES) that allowed an attacker to brute force a user invitation to the GHES Management Console. To exploit this vulnerability, an attacker would need knowled…
- CVE-2026-34236HIGHCVSS 8.2EG 8.22026-04-01
Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. From version 8.0.0 to before version 8.19.0, in applications built with the Auth0 PHP SDK, cookies are encrypted with insufficient entropy, which may result in threat act…
- CVE-2023-37822HIGHCVSS 8.2EG 8.22024-10-03
The Eufy Homebase 2 before firmware version 3.3.4.1h creates a dedicated wireless network for its ecosystem, which serves as a proxy to the end user's primary network. The WPA2-PSK generation of this dedicated network is flawed and solely …
- CVE-2018-18326HIGHCVSS 7.5EG 8.22019-07-03
DNN (aka DotNetNuke) 9.2 through 9.2.2 incorrectly converts encryption key source values, resulting in lower than expected entropy. NOTE: this issue exists because of an incomplete fix for CVE-2018-15812.
- CVE-2026-90562HIGHCVSS 8.1EG 8.12026-09-13
LangBot before 4.10.11 generates password recovery keys with only 24 bits of entropy and applies no rate limiting to the unauthenticated reset-password endpoint. Remote attackers knowing the administrator email can exhaust the keyspace thr…
- CVE-2024-58134HIGHCVSS 8.1EG 8.12025-05-03
Mojolicious versions from 0.999922 for Perl uses a hard coded string, or the application's class name, as an HMAC session cookie secret by default. These predictable default secrets can be exploited by an attacker to forge session cookies…
- CVE-2023-3325HIGHCVSS 8.1EG 8.12023-06-20
The CMS Commander plugin for WordPress is vulnerable to authorization bypass due to the use of an insufficiently unique cryptographic signature on the 'cmsc_add_site' function in versions up to, and including, 2.287. This makes it possible…
- CVE-2014-8422HIGHCVSS 8.1EG 8.12018-04-12
The web-based management (WBM) interface in Unify (former Siemens) OpenStage SIP and OpenScape Desk Phone IP V3 devices before R3.32.0 generates session cookies with insufficient entropy, which makes it easier for remote attackers to hijac…
- CVE-2017-13992HIGHCVSS 8.1EG 8.12017-10-05
An Insufficient Entropy issue was discovered in LOYTEC LVIS-3ME versions prior to 6.2.0. The application does not utilize sufficiently random number generation for the web interface authentication mechanism, which could allow remote code e…
- CVE-2020-1773HIGHCVSS 7.3EG 8.12020-03-27
An attacker with the ability to generate session IDs or password reset tokens, either by being able to authenticate or by exploiting OSA-2020-09, may be able to predict other users session IDs, password reset tokens and automatically gener…
- CVE-2024-6508HIGHCVSS 8.0EG 8.02024-08-21
An insufficient entropy vulnerability was found in the Openshift Console. In the authorization code type and implicit grant type, the OAuth2 protocol is vulnerable to a Cross-Site Request Forgery (CSRF) attack if the state parameter is use…
Map vulnerabilities like CWE-331 to your infrastructure
EchelonGraph correlates every CVE — across CWE-331 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →