CWE-332— Insufficient Entropy in PRNG
The lack of entropy available for, or used by, a Pseudo-Random Number Generator (PRNG) can be a stability and security threat.— MITRE CWE catalog
10 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-332page 1 of 1
- CVE-2014-0016MEDIUMCVSS v2 4.3EG 4.32014-03-24
stunnel before 5.00, when using fork threading, does not properly update the state of the OpenSSL pseudo-random number generator (PRNG), which causes subsequent children with the same process ID to use the same entropy pool and allows remo…
- CVE-2014-9690HIGHCVSS 7.5EG 7.52017-04-02
Huawei home gateways WS318 with software V100R001C01B022 and earlier versions are affected by the PIN offline brute force cracking vulnerability of the WPS protocol because the random number generator (RNG) used in the supplier's solution …
- CVE-2016-10743HIGHCVSS 7.5EG 7.52019-03-23
hostapd before 2.6 does not prevent use of the low-quality PRNG that is reached by an os_random() function call.
- CVE-2016-9154HIGHCVSS 7.5EG 7.52016-12-23
Siemens Desigo PX Web modules PXA40-W0, PXA40-W1, PXA40-W2 for Desigo PX automation controllers PXC00-E.D, PXC50-E.D, PXC100-E.D, PXC200-E.D (All firmware versions < V6.00.046) and Desigo PX Web modules PXA30-W0, PXA30-W1, PXA30-W2 for Des…
- CVE-2017-18486HIGHCVSS 7.2EG 7.22019-08-09
Jitbit Helpdesk before 9.0.3 allows remote attackers to escalate privileges because of mishandling of the User/AutoLogin userHash parameter. By inspecting the token value provided in a password reset link, a user can leverage a weak PRNG t…
- CVE-2017-9371MEDIUMCVSS 2.6EG 5.92017-11-14
In BlackBerry QNX Software Development Platform (SDP) 6.6.0 and 6.5.0 SP1 and earlier, a loss of integrity vulnerability in the default configuration of the QNX SDP could allow an attacker being able to reduce the entropy of the PRNG, maki…
- CVE-2018-9057CRITICALCVSS 9.8EG 9.82018-03-27
aws/resource_aws_iam_user_login_profile.go in the HashiCorp Terraform Amazon Web Services (AWS) provider through v1.12.0 has an inappropriate PRNG algorithm and seeding, which makes it easier for remote attackers to obtain access by levera…
- CVE-2019-1715HIGHCVSS 7.5EG 7.52019-05-03
A vulnerability in the Deterministic Random Bit Generator (DRBG), also known as Pseudorandom Number Generator (PRNG), used in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an…
- CVE-2023-20107HIGHCVSS 7.5EG 7.52023-03-23
A vulnerability in the deterministic random bit generator (DRBG), also known as pseudorandom number generator (PRNG), in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software for Cisco ASA 5506-…
- CVE-2026-3290HIGHCVSS 7.4EG 7.42026-05-14
Timing limitations of the HRNG in RS9116 when power save mode is enabled results in predictable values
Map vulnerabilities like CWE-332 to your infrastructure
EchelonGraph correlates every CVE — across CWE-332 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →