CWE-331— Insufficient Entropy
The product uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.— MITRE CWE catalog
147 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-331page 2 of 3
- CVE-2018-15812HIGHCVSS 7.5EG 8.02019-07-03
DNN (aka DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, resulting in lower than expected entropy.
- CVE-2025-1860HIGHCVSS 7.7EG 7.72025-03-28
Data::Entropy for Perl 0.007 and earlier use the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions.
- CVE-2012-4687HIGHCVSS v2 7.6EG 7.62012-12-08
Post Oak AWAM Bluetooth Reader Traffic System does not use a sufficient source of entropy for private keys, which makes it easier for man-in-the-middle attackers to spoof a device by predicting a key value.
- CVE-2026-27490HIGHCVSS 7.5EG 7.52026-08-21
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, inline images that are accessible without being authenticated are protected by a weak 24-bit pseudo-random secret. This issue has been fixed in version 3.2.3.
- CVE-2025-15629HIGHCVSS 7.5EG 7.52026-08-03
A cryptographic weakness exists in the Omada adoption protocol where session encryption keys used to protect communications between controllers and managed devices may be predictable due to insufficient entropy in session key generation. …
- CVE-2026-11403HIGHCVSS 7.5EG 7.52026-07-14
A vulnerability in Sonatype Nexus Repository Manager's format-specific API key generation may allow a remote attacker to gain unauthorized access to repository operations as a targeted user. A format-specific API key realm (NuGet API Key, …
- CVE-2026-46473HIGHCVSS 7.5EG 7.52026-05-21
Authen::TOTP versions before 0.1.1 for Perl generate secrets using rand. Secrets were generated using Perl's built-in rand function, which is predictable and unsuitable for security usage.
- CVE-2026-46474HIGHCVSS 7.5EG 7.52026-05-15
Trog::TOTP versions before 1.006 for Perl generate secrets using rand. Secrets were generated using Perl's built-in rand function, which is predictable and unsuitable for security usage.
- CVE-2026-41080HIGHCVSS 7.5EG 7.52026-04-16
libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.
- CVE-2026-22698HIGHCVSS 7.5EG 7.52026-01-10
RustCrypto: Elliptic Curves is general purpose Elliptic Curve Cryptography (ECC) support, including types and traits for representing various elliptic curve forms, scalars, points, and public/secret keys composed thereof. In versions 0.14.…
- CVE-2025-29311HIGHCVSS 7.5EG 7.52025-03-24
Limited secret space in LLDP packets used in onos v2.7.0 allows attackers to obtain the private key via a bruteforce attack. Attackers are able to leverage this vulnerability into creating crafted LLDP packets.
- CVE-2024-53522HIGHCVSS 7.5EG 7.52025-01-07
Bangkok Medical Software HOSxP XE v4.64.11.3 was discovered to contain a hardcoded IDEA Key-IV pair in the HOSxPXE4.exe and HOS-WIN32.INI components. This allows attackers to access sensitive information.
- CVE-2018-9426HIGHCVSS 7.5EG 7.52024-12-02
In RsaKeyPairGenerator::getNumberOfIterations of RSAKeyPairGenerator.java, an incorrect implementation could cause weak RSA key pairs being generated. This could lead to crypto vulnerability with no additional execution privileges nee…
- CVE-2024-25407HIGHCVSS 7.5EG 7.52024-02-13
SteVe v3.6.0 was discovered to use predictable transaction ID's when receiving a StartTransaction request. This vulnerability can allow attackers to cause a Denial of Service (DoS) by using the predicted transaction ID's to terminate other…
- CVE-2023-31176HIGHCVSS 7.5EG 7.52023-11-30
An Insufficient Entropy vulnerability in the Schweitzer Engineering Laboratories SEL-451 could allow an unauthenticated remote attacker to brute-force session tokens and bypass authentication. See product Instruction Manual Appendix A …
- CVE-2023-31582HIGHCVSS 7.5EG 7.52023-10-25
jose4j before v0.9.3 allows attackers to set a low iteration count of 1000 or less.
- CVE-2023-20107HIGHCVSS 7.5EG 7.52023-03-23
A vulnerability in the deterministic random bit generator (DRBG), also known as pseudorandom number generator (PRNG), in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software for Cisco ASA 5506-…
- CVE-2022-33738HIGHCVSS 7.5EG 7.52022-07-06
OpenVPN Access Server before 2.11 uses a weak random generator used to create user session token for the web portal
- CVE-2022-33756HIGHCVSS 7.5EG 7.52022-06-16
CA Automic Automation 12.2 and 12.3 contain an entropy weakness vulnerability in the Automic AutomationEngine that could allow a remote attacker to potentially access sensitive data.
- CVE-2020-25926HIGHCVSS 7.5EG 7.52021-08-18
The DNS client in InterNiche NicheStack TCP/IP 4.0.1 is affected by: Insufficient entropy in the DNS transaction id. The impact is: DNS cache poisoning (remote). The component is: dns_query_type(). The attack vector is: a specific DNS resp…
- CVE-2020-28924HIGHCVSS 7.5EG 7.52020-11-19
An issue was discovered in Rclone before 1.53.3. Due to the use of a weak random number generator, the password generator has been producing weak passwords with much less entropy than advertised. The suggested passwords depend deterministi…
- CVE-2020-11957HIGHCVSS 7.5EG 7.52020-06-09
The Bluetooth Low Energy implementation in Cypress PSoC Creator BLE 4.2 component versions before 3.64 generates a random number (Pairing Random) with significantly less entropy than the specified 128 bits during BLE pairing. This is the c…
- CVE-2019-10064HIGHCVSS 7.5EG 7.52020-02-28
hostapd before 2.6, in EAP mode, makes calls to the rand() and random() standard library functions without any preceding srand() or srandom() call, which results in inappropriate use of deterministic values. This was fixed in conjunction w…
- CVE-2015-8851HIGHCVSS 7.5EG 7.52020-01-30
node-uuid before 1.4.4 uses insufficiently random data to create a GUID, which could make it easier for attackers to have unspecified impact via brute force guessing.
- CVE-2019-15703HIGHCVSS 7.5EG 7.52019-10-24
An Insufficient Entropy in PRNG vulnerability in Fortinet FortiOS 6.2.1, 6.2.0, 6.0.8 and below for device not enable hardware TRNG token and models not support builtin TRNG seed allows attacker to theoretically recover the long term ECDSA…
- CVE-2019-15847HIGHCVSS 7.5EG 7.52019-09-02
The POWER9 backend in GNU Compiler Collection (GCC) before version 10 could optimize multiple calls of the __builtin_darn intrinsic into a single call, thus reducing the entropy of the random number generator. This occurred because a volat…
- CVE-2019-14806HIGHCVSS 7.5EG 7.52019-08-09
Pallets Werkzeug before 0.15.3, when used with Docker, has insufficient debugger PIN randomness because Docker containers share the same machine id.
- CVE-2015-7764HIGHCVSS 7.5EG 7.52017-08-09
Lemur 0.1.4 does not use sufficient entropy in its IV when encrypting AES in CBC mode.
- CVE-2015-3405HIGHCVSS 7.5EG 7.52017-08-09
ntp-keygen in ntp 4.2.8px before 4.2.8p2-RC2 and 4.3.x before 4.3.12 does not generate MD5 keys with sufficient entropy on big endian machines when the lowest order byte of the temp variable is between 0x20 and 0x7f and not #, which might …
- CVE-2017-0897HIGHCVSS 7.5EG 7.52017-06-22
ExpressionEngine version 2.x < 2.11.8 and version 3.x < 3.5.5 create an object signing token with weak entropy. Successfully guessing the token can lead to remote code execution.
- CVE-2001-0950HIGHCVSS 7.5EG 7.52001-12-04
ValiCert Enterprise Validation Authority (EVA) Administration Server 3.3 through 4.2.1 uses insufficiently random data to (1) generate session tokens for HSMs using the C rand function, or (2) generate certificates or keys using /dev/urand…
- CVE-2020-29505HIGHCVSS 7.1EG 7.52022-07-11
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain a Key Management Error Vulnerability.
- CVE-2026-62646HIGHCVSS 7.4EG 7.42026-09-08
A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A session identifier is generated using an algorithm with insufficient randomness, resulting in a token with low entropy that can be predicted or brute-forced wit…
- CVE-2025-6931HIGHCVSS 7.4EG 7.42025-06-30
A vulnerability classified as problematic was found in D-Link DCS-6517 and DCS-7517 up to 2.02.0. Affected by this vulnerability is the function generate_pass_from_mac of the file /bin/httpd of the component Root Password Generation Handle…
- CVE-2026-8700HIGHCVSS 7.3EG 7.32026-05-15
Crypt::DSA versions before 1.20 for Perl generate seeds using rand. Seeds were generated using Perl's built-in rand function, which is predictable and unsuitable for security usage.
- CVE-2018-10240HIGHCVSS 7.3EG 7.32018-05-16
SolarWinds Serv-U MFT before 15.1.6 HFv1 assigns authenticated users a low-entropy session token that can be included in requests to the application as a URL parameter in lieu of a session cookie. This session token's value can be brute-fo…
- CVE-2014-0691HIGHCVSS 7.3EG 7.32017-10-24
Cisco WebEx Meetings Server before 1.1 uses meeting IDs with insufficient entropy, which makes it easier for remote attackers to bypass authentication and join arbitrary meetings without a password, aka Bug ID CSCuc79643.
- CVE-2021-42138HIGHCVSS 7.2EG 7.22021-12-20
A user of a machine protected by SafeNet Agent for Windows Logon may leverage weak entropy to access the encrypted credentials of any or all the users on that machine.
- CVE-2026-4930HIGHCVSS 7.1EG 7.12026-06-25
SYMCRYPTO is the SiXG301's host side hardware engine accessed by PSA crypto library that accelerates symmetric cryptographic operations (AES encryption/decryption and hashing). DPA Countermeasures on SYMCRYPTO can be weakened (reduced en…
- CVE-2025-14261HIGHCVSS 7.1EG 7.12025-12-08
The Litmus platform uses JWT for authentication and authorization, but the secret being used for signing the JWT is only 6 bytes long at its core, which makes it extremely easy to crack.
- CVE-2022-43755HIGHCVSS 7.1EG 7.12023-02-07
A Insufficient Entropy vulnerability in SUSE Rancher allows attackers that gained knowledge of the cattle-token to continue abusing this even after the token was renewed. This issue affects: SUSE Rancher Rancher versions prior to 2.6.10; R…
- CVE-2025-54885MEDIUMCVSS 6.9EG 6.92025-08-07
Thinbus Javascript Secure Remote Password is a browser SRP6a implementation for zero-knowledge password authentication. In versions 2.0.0 and below, a protocol compliance bug causes the client to generate a fixed 252 bits of entropy instea…
- CVE-2026-1814MEDIUMCVSS 6.8EG 6.82026-02-03
Rapid7 Nexpose versions 6.4.50 and later are vulnerable to an insufficient entropy issue in the CredentialsKeyStorePassword.generateRandomPassword() method. When updating legacy keystore passwords, the application generates a new password …
- CVE-2024-22473MEDIUMCVSS 6.8EG 6.82024-02-21
TRNG is used before initialization by ECDSA signing driver when exiting EM2/EM3 on Virtual Secure Vault (VSE) devices. This defect may allow Signature Spoofing by Key Recreation.This issue affects Gecko SDK through v4.4.0.
- CVE-2024-20331MEDIUMCVSS 5.9EG 6.82024-10-23
A vulnerability in the session authentication functionality of the Remote Access SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote a…
- CVE-2025-59015MEDIUMCVSS 6.5EG 6.52025-09-09
A deterministic three‑character prefix in the Password Generation component of TYPO3 CMS versions 12.0.0–12.4.36 and 13.0.0–13.4.17 reduces entropy, allowing attackers to carry out brute‑force attacks more quickly.
- CVE-2024-56370MEDIUMCVSS 6.5EG 6.52025-04-05
Net::Xero 0.044 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions. Specifically Net::Xero uses the Data::Random library which specifically st…
- CVE-2015-3006MEDIUMCVSS 6.5EG 6.52020-02-28
On the QFX3500 and QFX3600 platforms, the number of bytes collected from the RANDOM_INTERRUPT entropy source when the device boots up is insufficient, possibly leading to weak or duplicate SSH keys or self-signed SSL/TLS certificates. Entr…
- CVE-2017-2625MEDIUMCVSS 6.5EG 6.52018-07-27
It was discovered that libXdmcp before 1.1.2 including used weak entropy to generate session keys. On a multi-user system using xdmcp, a local attacker could potentially use information available from the process list to brute force the ke…
- CVE-2017-6030MEDIUMCVSS 6.5EG 6.52017-06-30
A predictable value range from previous values issue was discovered in Schneider Electric Modicon PLCs Modicon M221, firmware versions prior to Version 1.5.0.0, Modicon M241, firmware versions prior to Version 4.0.5.11, and Modicon M251, f…
Map vulnerabilities like CWE-331 to your infrastructure
EchelonGraph correlates every CVE — across CWE-331 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →