CWE-338— Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
The product uses a Pseudo-Random Number Generator (PRNG) in a security context, but the PRNG's algorithm is not cryptographically strong.— MITRE CWE catalog
226 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-338page 3 of 5
- CVE-2026-5087HIGHCVSS 7.5EG 7.52026-03-31
PAGI::Middleware::Session::Store::Cookie versions through 0.001003 for Perl generates random bytes insecurely. PAGI::Middleware::Session::Store::Cookie attempts to read bytes from the /dev/urandom device directly. If that fails (for examp…
- CVE-2025-40933HIGHCVSS 7.5EG 7.52025-09-17
Apache::AuthAny::Cookie v0.201 or earlier for Perl generates session ids insecurely. Session ids are generated using an MD5 hash of the epoch time and a call to the built-in rand function. The epoch time may be guessed, if it is not leake…
- CVE-2021-26091HIGHCVSS 7.5EG 7.52025-03-24
A use of a cryptographically weak pseudo-random number generator vulnerability in the authenticator of the Identity Based Encryption service of FortiMail 6.4.0 through 6.4.4, and 6.2.0 through 6.2.7 may allow an unauthenticated attacker to…
- CVE-2018-25107HIGHCVSS 7.5EG 7.52024-12-29
The Crypt::Random::Source package before 0.13 for Perl has a fallback to the built-in rand() function, which is not a secure source of random bits.
- CVE-2024-7315HIGHCVSS 7.5EG 7.52024-10-02
The Migration, Backup, Staging WordPress plugin before 0.9.106 does not use sufficient randomness in the filename that is created when generating a backup, which could be bruteforced by attackers to leak sensitive information about said b…
- CVE-2024-34538HIGHCVSS 7.5EG 7.52024-05-06
Mateso PasswordSafe through 8.13.9.26689 has Weak Cryptography.
- CVE-2024-25389HIGHCVSS 7.5EG 7.52024-03-27
RT-Thread through 5.0.2 generates random numbers with a weak algorithm of "seed = 214013L * seed + 2531011L; return (seed >> 16) & 0x7FFF;" in calc_random in drivers/misc/rt_random.c.
- CVE-2024-23660HIGHCVSS 7.5EG 7.52024-02-08
The Binance Trust Wallet app for iOS in commit 3cd6e8f647fbba8b5d8844fcd144365a086b629f, git tag 0.0.4 misuses the trezor-crypto library and consequently generates mnemonic words for which the device time is the only entropy source, leadin…
- CVE-2023-39910HIGHCVSS 7.5EG 7.52023-08-09
The cryptocurrency wallet entropy seeding mechanism used in Libbitcoin Explorer 3.0.0 through 3.6.0 is weak, aka the Milk Sad issue. The use of an mt19937 Mersenne Twister PRNG restricts the internal entropy to 32 bits regardless of settin…
- CVE-2022-40769HIGHCVSS 7.5EG 7.52022-09-18
profanity through 1.60 has only four billion possible RNG initializations. Thus, attackers can recover private keys from Ethereum vanity addresses and steal cryptocurrency, as exploited in the wild in June 2022.
- CVE-2022-33738HIGHCVSS 7.5EG 7.52022-07-06
OpenVPN Access Server before 2.11 uses a weak random generator used to create user session token for the web portal
- CVE-2022-0828HIGHCVSS 7.5EG 7.52022-04-11
The Download Manager WordPress plugin before 3.2.34 uses the uniqid php function to generate the master key for a download, allowing an attacker to brute force the key with reasonable resources giving direct download access regardless of r…
- CVE-2022-26779HIGHCVSS 7.5EG 7.52022-03-15
Apache CloudStack prior to 4.16.1.0 used insecure random number generation for project invitation tokens. If a project invite is created based only on an email address, a random token is generated. An attacker with knowledge of the project…
- CVE-2021-45489HIGHCVSS 7.5EG 7.52021-12-25
In NetBSD through 9.2, the IPv6 Flow Label generation algorithm employs a weak cryptographic PRNG.
- CVE-2021-45484HIGHCVSS 7.5EG 7.52021-12-25
In NetBSD through 9.2, the IPv6 fragment ID generation algorithm employs a weak cryptographic PRNG.
- CVE-2021-37553HIGHCVSS 7.5EG 7.52021-08-06
In JetBrains YouTrack before 2021.2.16363, an insecure PRNG was used.
- CVE-2021-34430HIGHCVSS 7.5EG 7.52021-07-08
Eclipse TinyDTLS through 0.9-rc1 relies on the rand function in the C library, which makes it easier for remote attackers to compute the master key and then decrypt DTLS traffic.
- CVE-2020-28924HIGHCVSS 7.5EG 7.52020-11-19
An issue was discovered in Rclone before 1.53.3. Due to the use of a weak random number generator, the password generator has been producing weak passwords with much less entropy than advertised. The suggested passwords depend deterministi…
- CVE-2020-11616HIGHCVSS 7.5EG 7.52020-10-29
NVIDIA DGX servers, all BMC firmware versions prior to 3.38.30, contain a vulnerability in the AMI BMC firmware in which the Pseudo-Random Number Generator (PRNG) algorithm used in the JSOL package that implements the IPMI protocol is not …
- CVE-2020-13784HIGHCVSS 7.5EG 7.52020-06-03
D-Link DIR-865L Ax 1.20B01 Beta devices have a predictable seed in a Pseudo-Random Number Generator.
- CVE-2019-15075HIGHCVSS 7.5EG 7.52020-03-20
An issue was discovered in iNextrix ASTPP before 4.0.1. web_interface/astpp/application/config/config.php does not have strong random keys, as demonstrated by use of the 8YSDaBtDHAB3EQkxPAyTz2I5DttzA9uR private key and the r)fddEw232f encr…
- CVE-2019-7860HIGHCVSS 7.5EG 7.52019-08-02
A cryptographically weak pseudo-rando number generator is used in multiple security relevant contexts in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.
- CVE-2019-11842HIGHCVSS 7.5EG 7.52019-05-09
An issue was discovered in Matrix Sydent before 1.0.3 and Synapse before 0.99.3.1. Random number generation is mishandled, which makes it easier for attackers to predict a Sydent authentication token or a Synapse random ID.
- CVE-2018-17968HIGHCVSS 7.5EG 7.52018-10-23
A gambling smart contract implementation for RuletkaIo, an Ethereum gambling game, generates a random value that is predictable by an external contract call. The developer wrote a random() function that uses a block timestamp and block has…
- CVE-2018-17877HIGHCVSS 7.5EG 7.52018-10-23
A lottery smart contract implementation for Greedy 599, an Ethereum gambling game, generates a random value that is predictable via an external contract call. The developer used the extcodesize() function to prevent a malicious contract fr…
- CVE-2018-12975HIGHCVSS 7.5EG 7.52018-09-24
The random() function of the smart contract implementation for CryptoSaga, an Ethereum game, generates a random value with publicly readable variables such as timestamp, the current block's blockhash, and a private variable (which can be r…
- CVE-2018-5837HIGHCVSS 7.5EG 7.52018-09-20
In Snapdragon (Automobile, Mobile, Wear) in version IPQ8074, MDM9206, MDM9607, MDM9640, MDM9650, MSM8996AU, QCA6574AU, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 820A, SD 835, SD 845, SD 850, SDA660, SDM429, S…
- CVE-2018-11291HIGHCVSS 7.5EG 7.52018-09-20
In Snapdragon (Automobile, Mobile, Wear) in version IPQ8074, MDM9206, MDM9607, MDM9640, MDM9650, MSM8996AU, QCA4531, QCA6174A, QCA6564, QCA6574, QCA6574AU, QCA6584, QCA6584AU, QCA9377, QCA9378, QCA9379, SD 425, SD 427, SD 430, SD 435, SD 4…
- CVE-2018-11290HIGHCVSS 7.5EG 7.52018-09-20
In Snapdragon (Automobile, Mobile, Wear) in version MDM9206, MDM9607, MDM9640, MDM9650, MSM8996AU, QCA6574AU, QCA6584, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 650/52, SD 820A, SD 845, SDM429, SDM439, SDM630…
- CVE-2018-17071HIGHCVSS 7.5EG 7.52018-09-18
The fallback function of a simple lottery smart contract implementation for Lucky9io, an Ethereum gambling game, generates a random value with the publicly readable variable entry_number. This variable is private, yet it is readable by eth…
- CVE-2018-15552HIGHCVSS 7.5EG 7.52018-09-07
The "PayWinner" function of a simplelottery smart contract implementation for The Ethereum Lottery, an Ethereum gambling game, generates a random value with publicly readable variable "maxTickets" (which is private, yet predictable and rea…
- CVE-2018-12056HIGHCVSS 7.5EG 7.52018-08-15
The maxRandom function of a smart contract implementation for All For One, an Ethereum gambling game, generates a random value with publicly readable variables because the _seed value can be retrieved with a getStorageAt call. Therefore, i…
- CVE-2018-14715HIGHCVSS 7.5EG 7.52018-08-03
The endCoinFlip function and throwSlammer function of the smart contract implementations for Cryptogs, an Ethereum game, generate random numbers with an old block's hash. Therefore, attackers can predict the random number and always win th…
- CVE-2018-12454HIGHCVSS 7.5EG 7.52018-06-17
The _addguess function of a simplelottery smart contract implementation for 1000 Guess, an Ethereum gambling game, generates a random value with publicly readable variables such as the current block information and a private variable (whic…
- CVE-2017-9230HIGHCVSS 7.5EG 7.52017-05-24
The Bitcoin Proof-of-Work algorithm does not consider a certain attack methodology related to 80-byte block headers with a variety of initial 64-byte chunks followed by the same 16-byte chunk, multiple candidate root values ending with the…
- CVE-2017-5493HIGHCVSS 7.5EG 7.52017-01-15
wp-includes/ms-functions.php in the Multisite WordPress API in WordPress before 4.7.1 does not properly choose random numbers for keys, which makes it easier for remote attackers to bypass intended access restrictions via a crafted (1) sit…
- CVE-2021-34600HIGHCVSS 5.5EG 7.52022-01-20
Telenot CompasX versions prior to 32.0 use a weak seed for random number generation leading to predictable AES keys used in the NFC tags used for local authorization of users. This may lead to total loss of trustworthiness of the installat…
- CVE-2026-7830HIGHCVSS 7.4EG 7.42026-07-01
UltraVNC through 1.8.2.2 uses inadequate cryptography in the MS-Logon II authentication scheme (rfbUltraVNC_MsLogonIIAuth). In rfb/dh.cpp the Diffie-Hellman key exchange is performed with parameters that fit in an unsigned 64-bit integer (…
- CVE-2025-41731HIGHCVSS 7.4EG 7.42025-11-10
A vulnerability was identified in the password generation algorithm when accessing the debug-interface. An unauthenticated local attacker with knowledge of the password generation timeframe might be able to brute force the password in a ti…
- CVE-2022-20817HIGHCVSS 7.4EG 7.42022-06-15
A vulnerability in Cisco Unified IP Phones could allow an unauthenticated, remote attacker to impersonate another user's phone if the Cisco Unified Communications Manager (CUCM) is in secure mode. This vulnerability is due to improper key …
- CVE-2025-40905HIGHCVSS 7.3EG 7.32026-02-13
WWW::OAuth 1.000 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions.
- CVE-2025-40923HIGHCVSS 7.3EG 7.32025-07-16
Plack-Middleware-Session before version 0.35 for Perl generates session ids insecurely. The default session id generator returns a SHA-1 hash seeded with the built-in rand function, the epoch time, and the PID. The PID will come from a sm…
- CVE-2017-17845HIGHCVSS 7.3EG 7.32017-12-27
An issue was discovered in Enigmail before 1.9.9. Improper Random Secret Generation occurs because Math.Random() is used by pretty Easy privacy (pEp), aka TBE-01-001.
- CVE-2025-26379HIGHCVSS 7.2EG 7.22025-12-22
Use of a weak pseudo-random number generator, which may allow an attacker to read or inject encrypted PowerG packets.
- CVE-2021-22948HIGHCVSS 7.1EG 7.12021-09-23
Vulnerability in the generation of session IDs in revive-adserver < 5.3.0, based on the cryptographically insecure uniqid() PHP function. Under some circumstances, an attacker could theoretically be able to brute force session IDs in order…
- CVE-2025-40915HIGHCVSS 7.0EG 7.02025-06-11
Mojolicious::Plugin::CSRF 1.03 for Perl uses a weak random number source for generating CSRF tokens. That version of the module generates tokens as an MD5 of the process id, the current time, and a single call to the built-in rand() funct…
- CVE-2026-16615MEDIUMCVSS 6.8EG 6.82026-07-22
A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number generator. Because the generated "code verifier" lacks sufficient cry…
- CVE-2023-32549MEDIUMCVSS 6.8EG 6.82023-06-06
Landscape cryptographic keys were insecurely generated with a weak pseudo-random generator.
- CVE-2026-34871MEDIUMCVSS 6.7EG 6.72026-04-01
An issue was discovered in Mbed TLS before 3.6.6 and 4.x before 4.1.0 and TF-PSA-Crypto before 1.1.0. There is a Predictable Seed in a Pseudo-Random Number Generator (PRNG).
- CVE-2026-44040MEDIUMCVSS 6.5EG 6.52026-07-01
UltraVNC through 1.8.2.2 uses a cryptographically weak pseudo-random number generator to produce VNC authentication challenge bytes. In rfb/vncauth.c:119-129, the vncRandomBytes() function seeds libc rand() with time(0) + getpid() + rand()…
Map vulnerabilities like CWE-338 to your infrastructure
EchelonGraph correlates every CVE — across CWE-338 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →