CWE-334 · 12 records
Small Space of Random Values
CVEs in this class
12 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2023-39979No exploit | MXsecurity Authentication Bypassmoxa · mxsecurity · CWE-334 | Critical9.8 | — | 1.0% | Sep 2, 2023 |
36Monitor | CVE-2025-3895No exploit | Low token entropy in MegaBIPjan syski · megabip · CWE-334 | Critical9.1 | — | 0.5% | May 23, 2025 |
30Monitor | CVE-2022-22517No exploit | Communication Components in multiple CODESYS products vulnerable to communication channel disruptioncodesys · control for beaglebone sl · CWE-334 | High7.5 | — | 1.3% | Apr 7, 2022 |
30Monitor | CVE-2021-21955No exploit | An authentication bypass vulnerability exists in the get_aes_key_info_by_packetid() function of the home_security binary of Anker Eufy Homebanker · eufy homebase 2 firmware · CWE-334 | High7.5 | — | 1.0% | Dec 9, 2021 |
30Monitor | CVE-2022-24402No exploit | Intentionally weakened effective strength in TETRA TEA1midnightblue · tetra\ · CWE-334 | High7.5 | — | 0.6% | Oct 19, 2023 |
29Monitor | CVE-2020-7566No exploit | A CWE-334: Small Space of Random Values vulnerability exists in Modicon M221 (all references, all versions) that could allow the attacker toschneider-electric · modicon m221 firmware · CWE-334 | High7.3 | — | 0.3% | Nov 19, 2020 |
27Monitor | CVE-2024-54017No exploit | A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V11.0), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 siemens · siprotec 5 6md84 (cp300) · CWE-334 | Medium6.9 | — | 0.3% | May 12, 2026 |
26Monitor | CVE-2023-6951No exploit | A Use of Weak Credentials vulnerability affecting the Wi-Fi network generated by a set of DJI drones could allow a remote attacker to derivedji · mavic 3 pro · CWE-334 | Medium6.6 | — | 0.3% | Apr 2, 2024 |
22Monitor | GHSA-jp37-5qhw-mffwNo exploit | Sharks has a Bias of Polynomial Coefficients in Secret Sharingcrates.io · sharks · CWE-334 | Medium5.5 | — | — | Nov 18, 2024 |
21Monitor | CVE-2022-33707No exploit | Improper identifier creation logic in Find My Mobile prior to version 7.2.24.12 allows attacker to identify the device.samsung · find my mobile · CWE-334 | Medium5.3 | — | 0.8% | Jul 12, 2022 |
21Monitor | CVE-2022-20941No exploit | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, recisco · secure firewall management center · CWE-334 | Medium5.3 | — | 0.7% | Nov 15, 2022 |
21Monitor | CVE-2024-52616No exploit | Avahi: avahi wide-area dns predictable transaction idsred hat · red hat enterprise linux 9 · CWE-334 | Medium5.3 | — | 0.7% | Nov 21, 2024 |
- CVE-2023-3997939Monitor
MXsecurity Authentication Bypass
CriticalCVSS 9.8No exploitEPSS 1%moxa · mxsecuritySep 2, 2023
- CVE-2025-389536Monitor
Low token entropy in MegaBIP
CriticalCVSS 9.1No exploitEPSS 0%jan syski · megabipMay 23, 2025
- CVE-2022-2251730Monitor
Communication Components in multiple CODESYS products vulnerable to communication channel disruption
HighCVSS 7.5No exploitEPSS 1%codesys · control for beaglebone slApr 7, 2022
- CVE-2021-2195530Monitor
An authentication bypass vulnerability exists in the get_aes_key_info_by_packetid() function of the home_security binary of Anker Eufy Homeb
HighCVSS 7.5No exploitEPSS 1%anker · eufy homebase 2 firmwareDec 9, 2021
- CVE-2022-2440230Monitor
Intentionally weakened effective strength in TETRA TEA1
HighCVSS 7.5No exploitEPSS 1%midnightblue · tetra\Oct 19, 2023
- CVE-2020-756629Monitor
A CWE-334: Small Space of Random Values vulnerability exists in Modicon M221 (all references, all versions) that could allow the attacker to
HighCVSS 7.3No exploitEPSS 0%schneider-electric · modicon m221 firmwareNov 19, 2020
- CVE-2024-5401727Monitor
A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V11.0), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5
MediumCVSS 6.9No exploitEPSS 0%siemens · siprotec 5 6md84 (cp300)May 12, 2026
- CVE-2023-695126Monitor
A Use of Weak Credentials vulnerability affecting the Wi-Fi network generated by a set of DJI drones could allow a remote attacker to derive
MediumCVSS 6.6No exploitEPSS 0%dji · mavic 3 proApr 2, 2024
- GHSA-jp37-5qhw-mffw22Monitor
Sharks has a Bias of Polynomial Coefficients in Secret Sharing
MediumCVSS 5.5No exploitcrates.io · sharksNov 18, 2024
- CVE-2022-3370721Monitor
Improper identifier creation logic in Find My Mobile prior to version 7.2.24.12 allows attacker to identify the device.
MediumCVSS 5.3No exploitEPSS 1%samsung · find my mobileJul 12, 2022
- CVE-2022-2094121Monitor
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, re
MediumCVSS 5.3No exploitEPSS 1%cisco · secure firewall management centerNov 15, 2022
- CVE-2024-5261621Monitor
Avahi: avahi wide-area dns predictable transaction ids
MediumCVSS 5.3No exploitEPSS 1%red hat · red hat enterprise linux 9Nov 21, 2024