Skip to content
Noroxi

CWE-331 · 138 records

Insufficient Entropy

CVEs in this class

138 records

  • The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windows 2000 SP4, XP SP2

    MediumCVSS 6.8WeaponizedEPSS 95%

    microsoft · windows 2000Jul 8, 2008

  • DNN (aka DotNetNuke) 9.2 through 9.2.2 incorrectly converts encryption key source values, resulting in lower than expected entropy.

    HighCVSS 7.5WeaponizedEPSS 54%

    dnnsoftware · dotnetnukeJul 3, 2019

  • DNN (aka DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, resulting in lower than expected entropy.

    HighCVSS 7.5WeaponizedEPSS 47%

    dnnsoftware · dotnetnukeJul 3, 2019

  • The GENERATE_SEED macro in PHP 4.x before 4.4.8 and 5.x before 5.2.5, when running on 64-bit systems, performs a multiplication that generat

    CriticalCVSS 9.8No exploitEPSS 4%

    php · phpMay 7, 2008

  • Cryptocat before 2.0.22: Cryptocat.random() Function Array Key has Entropy Weakness

    CriticalCVSS 9.8No exploitEPSS 2%

    cryptocat project · cryptocatNov 4, 2019

  • totd 1.5.3 uses a fixed UDP source port in upstream queries sent to DNS resolvers.

    CriticalCVSS 9.8No exploitEPSS 2%

    totd project · totdAug 15, 2022

  • Rancher: Non-random authentication token

    CriticalCVSS 9.8No exploitEPSS 2%

    suse · rancherFeb 7, 2023

  • reset.php in DomainMOD 4.13.0 uses insufficient entropy for password reset requests, leading to account takeover.

    CriticalCVSS 9.8No exploitEPSS 2%

    domainmod · domainmodMay 8, 2020

  • Eran Hammer cryptiles version 4.1.1 earlier contains a CWE-331: Insufficient Entropy vulnerability in randomDigits() method that can result

    CriticalCVSS 9.8No exploitEPSS 2%

    cryptiles project · cryptilesJul 9, 2018

  • Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authentication bypass vulnerability.

    CriticalCVSS 9.8No exploitEPSS 2%

    dell · emc unity operating environmentJan 25, 2022

  • A CWE-331: Insufficient Entropy vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking

    CriticalCVSS 9.8No exploitEPSS 1%

    schneider-electric · evlink city evc1s22p4 firmwareJul 21, 2021

  • websda.c in GoAhead WebServer 2.1.8 has insufficient nonce entropy because the nonce calculation relies on the hardcoded onceuponatimeinpara

    CriticalCVSS 9.8No exploitEPSS 1%

    embedthis · goaheadAug 8, 2022

  • Sylabs Singularity Enterprise through 1.6.2 has Insufficient Entropy in a nonce.

    CriticalCVSS 9.8No exploitEPSS 1%

    sylabs · singularityJul 19, 2021

  • Dell Networking X-Series firmware versions prior to 3.0.1.8 contain an authentication bypass vulnerability.

    CriticalCVSS 9.8No exploitEPSS 1%

    dell · x1008p firmwareNov 19, 2021

  • Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Improper Input

    CriticalCVSS 9.8No exploitEPSS 1%

    dell · bsafe crypto-c-micro-editionJul 11, 2022

  • An insufficient entropy vulnerability exists in the salt generation functionality of WWBN AVideo dev master commit 15fed957fb.

    CriticalCVSS 9.8No exploitEPSS 1%

    wwbn · avideoJan 10, 2024

  • Insufficient entropy vulnerability could lead to authentication bypass

    CriticalCVSS 9.8No exploitEPSS 1%

    selinc · sel-451 firmwareNov 30, 2023

  • Hitron CODA-4582 and CODA-4589 devices have default PSKs that are generated from 5-digit hex values concatenated with a "Hitron" substring,

    CriticalCVSS 9.8No exploitEPSS 1%

    hitrontech · coda-4582u firmwareFeb 23, 2024

  • nano-id is unable to generate the correct character set

    CriticalCVSS 9.8No exploitEPSS 1%

    viz · nano idJun 4, 2024

  • CVE-2023-4344
    39Monitor

    Broadcom RAID Controller web interface is vulnerable to insufficient randomness due to improper use of ssl.rnd to setup CIM connection

    CriticalCVSS 9.8No exploitEPSS 1%

    broadcom · raid controller web interfaceAug 15, 2023

  • osTicket 1.18.3 generates API keys using a predictable construction based on MD5 hashing.

    CriticalCVSS 9.8No exploitEPSS 1%

    Aug 3, 2026

  • An insufficient entropy vulnerability in login logic in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009

    CriticalCVSS 9.8No exploitEPSS 1%

    synology · diskstation manager (dsm)Sep 18, 2026

  • Rallly Insufficient Password Login Token Entropy Leads to Account Takeover

    CriticalCVSS 9.8No exploitEPSS 1%

    rallly · ralllyMay 14, 2025

  • WBCE CMS has Weak Random Number Generator in Password Generation Function

    CriticalCVSS 9.8No exploitEPSS 1%

    wbce · wbce cmsDec 9, 2025

  • Auth0 PHP SDK Insufficient Entropy in Cookie Encryption

    CriticalCVSS 9.8No exploitEPSS 0%

    auth0 · auth0-phpApr 1, 2026

All vulnerability classes