CWE-320 · 88 записей
Key Management Errors
CVE этого класса
88 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
62На этой неделе | CVE-2015-0936Готовый эксплойт | Ceragon FibeAir IP-10 have a default SSH public key in the authorized_keys file for the mateidu user, which allows remote attackers to obtaiceragon · fibeair ip-10 firmware · CWE-320 | Критическая9,8 | — | 78,1 % | 1 июн. 2017 г. |
45В плане | CVE-2018-0732Эксплойта нет | Client DoS due to large DH parameteropenssl · openssl · CWE-320 | Высокая7,5 | — | 48,8 % | 12 июн. 2018 г. |
41В плане | CVE-2018-0124Эксплойта нет | A vulnerability in Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to bypass security protectioncisco · unified communications domain manager · CWE-320 | Критическая9,8 | — | 5,1 % | 21 февр. 2018 г. |
39Наблюдать | CVE-2016-10467Эксплойта нет | In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile SD 210/SD 212/SD 205, Squalcomm · sd 210 firmware · CWE-320 | Критическая9,8 | — | 1,2 % | 18 апр. 2018 г. |
39Наблюдать | CVE-2016-10421Эксплойта нет | In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9615, MDqualcomm · mdm9206 firmware · CWE-320 | Критическая9,8 | — | 1,2 % | 18 апр. 2018 г. |
39Наблюдать | CVE-2015-4166Эксплойта нет | Cloudera Key Trustee Server before 5.4.3 does not store keys synchronously, which might allow attackers to have unspecified impact via vectocloudera · key trustee server · CWE-320 | Критическая9,8 | — | 0,7 % | 23 мар. 2017 г. |
36Наблюдать | CVE-2015-8542Эксплойта нет | An issue was discovered in Open-Xchange Guard before 2.2.0-rev8.open-xchange · ox guard · CWE-320 | Высокая8,8 | — | 2,2 % | 15 дек. 2016 г. |
36Наблюдать | CVE-2019-5672Эксплойта нет | NVIDIA Jetson TX1 and TX2 contain a vulnerability in the Linux for Tegra (L4T) operating system (on all versions prior to R28.3) where the Snvidia · jetson tx1 · CWE-320 | Критическая9,1 | — | 1,4 % | 11 апр. 2019 г. |
34Наблюдать | CVE-2015-0839Эксплойта нет | The hp-plugin utility in HP Linux Imaging and Printing (HPLIP) makes it easier for man-in-the-middle attackers to execute arbitrary code by hp · linux imaging and printing · CWE-320 | Высокая8,1 | — | 6,3 % | 2 авг. 2017 г. |
33Наблюдать | CVE-2026-56254Эксплойта нет | capacitor-updater - End-to-End Encryption Bypass via Private Key Distributioncapacitor-updater · capacitor-updater · CWE-320 | Высокая8,3 | — | 0,2 % | 10 июл. 2026 г. |
31Наблюдать | CVE-2019-9894Эксплойта нет | A remotely triggerable memory overwrite in RSA key exchange in PuTTY before 0.71 can occur before host key verification.putty · putty · CWE-320 | Высокая7,5 | — | 2,4 % | 21 мар. 2019 г. |
31Наблюдать | CVE-2018-9234Эксплойта нет | GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in agnupg · gnupg · CWE-320 | Высокая7,5 | — | 2,0 % | 3 апр. 2018 г. |
31Наблюдать | CVE-2015-0153Эксплойта нет | D-Link DIR-815 devices with firmware before 2.07.B01 allow remote attackers to obtain sensitive information by leveraging cleartext storage dlink · dir-815 firmware · CWE-320 | Высокая7,5 | — | 1,9 % | 12 апр. 2018 г. |
31Наблюдать | CVE-2016-6886Эксплойта нет | The pstm_reverse function in MatrixSSL before 3.8.4 allows remote attackers to cause a denial of service (invalid memory read and crash) viamatrixssl · matrixssl · CWE-320 | Высокая7,5 | — | 1,7 % | 13 янв. 2017 г. |
31Наблюдать | CVE-2016-2880Эксплойта нет | IBM QRadar 7.2 stores the encryption key used to encrypt the service account password which can be obtained by a local user.ibm · qradar security information and event manager · CWE-320 | Высокая7,8 | — | 0,2 % | 1 мар. 2017 г. |
30Наблюдать | CVE-2013-2233Эксплойта нет | Ansible before 1.2.1 makes it easier for remote attackers to conduct man-in-the-middle attacks by leveraging failure to cache SSH host keys.redhat · ansible · CWE-320 | Высокая7,4 | — | 1,9 % | 4 мая 2018 г. |
30Наблюдать | CVE-2015-7503Эксплойта нет | Zend Framework before 2.4.9, zend-framework/zend-crypt 2.4.x before 2.4.9, and 2.5.x before 2.5.2 allows remote attackers to recover the RSAzend · zend framework · CWE-320 | Высокая7,5 | — | 1,4 % | 10 окт. 2017 г. |
30Наблюдать | CVE-2015-1316Эксплойта нет | Juju Joyent provider uploads user's private ssh key by defaultcanonical · juju · CWE-320 | Высокая7,5 | — | 1,2 % | 22 апр. 2019 г. |
30Наблюдать | CVE-2021-26322Эксплойта нет | Persistent platform private key may not be protected with a random IV leading to a potential “two time pad attack”.amd · epyc 7601 firmware · CWE-320 | Высокая7,5 | — | 1,0 % | 16 нояб. 2021 г. |
30Наблюдать | CVE-2017-13887Эксплойта нет | In macOS High Sierra before 10.13.2, a logic issue existed in APFS when deleting keys during hibernation.apple · mac os x · CWE-320 | Высокая7,5 | — | 0,8 % | 11 янв. 2019 г. |
30Наблюдать | CVE-2016-6879Эксплойта нет | The X509_Certificate::allowed_usage function in botan 1.11.x before 1.11.31 might allow attackers to have unspecified impact by leveraging abotan project · botan · CWE-320 | Высокая7,5 | — | 0,6 % | 10 апр. 2017 г. |
29Наблюдать | CVE-2019-12621Эксплойта нет | Cisco HyperFlex Static SSL Key Vulnerabilitycisco · hyperflex hx220c m5 firmware · CWE-320 | Высокая7,4 | — | 0,4 % | 21 авг. 2019 г. |
29Наблюдать | CVE-2024-36391Эксплойта нет | MileSight DeviceHub - CWE-320: Key Management Errorsmilesight · devicehub · CWE-320 | Высокая7,4 | — | 0,4 % | 2 июн. 2024 г. |
28Наблюдать | CVE-2014-2361Эксплойта нет | OleumTech WIO Family Key Management Errorsoleumtech · sensor wireless i\/o module · CWE-320 | Высокая7,2 | — | 0,4 % | 24 июл. 2014 г. |
28Наблюдать | CVE-2023-21626Эксплойта нет | Improper Authentication in HLOS.qualcomm · apq8009 firmware · CWE-320 | Высокая7,1 | — | 0,1 % | 8 авг. 2023 г. |
- CVE-2015-093662На этой неделе
Ceragon FibeAir IP-10 have a default SSH public key in the authorized_keys file for the mateidu user, which allows remote attackers to obtai
КритическаяCVSS 9,8Готовый эксплойтEPSS 78 %ceragon · fibeair ip-10 firmware1 июн. 2017 г.
- CVE-2018-073245В плане
Client DoS due to large DH parameter
ВысокаяCVSS 7,5Эксплойта нетEPSS 49 %openssl · openssl12 июн. 2018 г.
- CVE-2018-012441В плане
A vulnerability in Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to bypass security protection
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %cisco · unified communications domain manager21 февр. 2018 г.
- CVE-2016-1046739Наблюдать
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile SD 210/SD 212/SD 205, S
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %qualcomm · sd 210 firmware18 апр. 2018 г.
- CVE-2016-1042139Наблюдать
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9615, MD
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %qualcomm · mdm9206 firmware18 апр. 2018 г.
- CVE-2015-416639Наблюдать
Cloudera Key Trustee Server before 5.4.3 does not store keys synchronously, which might allow attackers to have unspecified impact via vecto
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %cloudera · key trustee server23 мар. 2017 г.
- CVE-2015-854236Наблюдать
An issue was discovered in Open-Xchange Guard before 2.2.0-rev8.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %open-xchange · ox guard15 дек. 2016 г.
- CVE-2019-567236Наблюдать
NVIDIA Jetson TX1 and TX2 contain a vulnerability in the Linux for Tegra (L4T) operating system (on all versions prior to R28.3) where the S
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %nvidia · jetson tx111 апр. 2019 г.
- CVE-2015-083934Наблюдать
The hp-plugin utility in HP Linux Imaging and Printing (HPLIP) makes it easier for man-in-the-middle attackers to execute arbitrary code by
ВысокаяCVSS 8,1Эксплойта нетEPSS 6 %hp · linux imaging and printing2 авг. 2017 г.
- CVE-2026-5625433Наблюдать
capacitor-updater - End-to-End Encryption Bypass via Private Key Distribution
ВысокаяCVSS 8,3Эксплойта нетEPSS 0 %capacitor-updater · capacitor-updater10 июл. 2026 г.
- CVE-2019-989431Наблюдать
A remotely triggerable memory overwrite in RSA key exchange in PuTTY before 0.71 can occur before host key verification.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %putty · putty21 мар. 2019 г.
- CVE-2018-923431Наблюдать
GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in a
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %gnupg · gnupg3 апр. 2018 г.
- CVE-2015-015331Наблюдать
D-Link DIR-815 devices with firmware before 2.07.B01 allow remote attackers to obtain sensitive information by leveraging cleartext storage
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %dlink · dir-815 firmware12 апр. 2018 г.
- CVE-2016-688631Наблюдать
The pstm_reverse function in MatrixSSL before 3.8.4 allows remote attackers to cause a denial of service (invalid memory read and crash) via
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %matrixssl · matrixssl13 янв. 2017 г.
- CVE-2016-288031Наблюдать
IBM QRadar 7.2 stores the encryption key used to encrypt the service account password which can be obtained by a local user.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %ibm · qradar security information and event manager1 мар. 2017 г.
- CVE-2013-223330Наблюдать
Ansible before 1.2.1 makes it easier for remote attackers to conduct man-in-the-middle attacks by leveraging failure to cache SSH host keys.
ВысокаяCVSS 7,4Эксплойта нетEPSS 2 %redhat · ansible4 мая 2018 г.
- CVE-2015-750330Наблюдать
Zend Framework before 2.4.9, zend-framework/zend-crypt 2.4.x before 2.4.9, and 2.5.x before 2.5.2 allows remote attackers to recover the RSA
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %zend · zend framework10 окт. 2017 г.
- CVE-2015-131630Наблюдать
Juju Joyent provider uploads user's private ssh key by default
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %canonical · juju22 апр. 2019 г.
- CVE-2021-2632230Наблюдать
Persistent platform private key may not be protected with a random IV leading to a potential “two time pad attack”.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %amd · epyc 7601 firmware16 нояб. 2021 г.
- CVE-2017-1388730Наблюдать
In macOS High Sierra before 10.13.2, a logic issue existed in APFS when deleting keys during hibernation.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %apple · mac os x11 янв. 2019 г.
- CVE-2016-687930Наблюдать
The X509_Certificate::allowed_usage function in botan 1.11.x before 1.11.31 might allow attackers to have unspecified impact by leveraging a
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %botan project · botan10 апр. 2017 г.
- CVE-2019-1262129Наблюдать
Cisco HyperFlex Static SSL Key Vulnerability
ВысокаяCVSS 7,4Эксплойта нетEPSS 0 %cisco · hyperflex hx220c m5 firmware21 авг. 2019 г.
- CVE-2024-3639129Наблюдать
MileSight DeviceHub - CWE-320: Key Management Errors
ВысокаяCVSS 7,4Эксплойта нетEPSS 0 %milesight · devicehub2 июн. 2024 г.
- CVE-2014-236128Наблюдать
OleumTech WIO Family Key Management Errors
ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %oleumtech · sensor wireless i\/o module24 июл. 2014 г.
- CVE-2023-2162628Наблюдать
Improper Authentication in HLOS.
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %qualcomm · apq8009 firmware8 авг. 2023 г.