CWE-327 · 641 записей
Use of a Broken or Risky Cryptographic Algorithm
CVE этого класса
641 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
59В плане | CVE-2023-34039Готовый эксплойт | Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key generation.vmware · aria operations for networks · CWE-327 | Критическая9,8 | — | 67,2 % | 29 авг. 2023 г. |
56В плане | CVE-2016-6602Готовый эксплойт | ZOHO WebNMS Framework 5.2 and 5.2 SP1 use a weak obfuscation algorithm to store passwords, which allows context-dependent attackers to obtaizohocorp · webnms framework · CWE-327 | Критическая9,8 | — | 55,1 % | 23 янв. 2017 г. |
52В плане | CVE-2014-8687Готовый эксплойт | Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root privileges by leveraseagate · business nas firmware · CWE-327 | Критическая9,8 | — | 43,8 % | 8 июн. 2017 г. |
40В плане | CVE-2007-6013Эксплойта нет | Wordpress 1.5 through 2.3.1 uses cookie values based on the MD5 hash of a password MD5 hash, which allows attackers to bypass authenticationwordpress · wordpress · CWE-327 | Критическая9,8 | — | 3,3 % | 19 нояб. 2007 г. |
40В плане | CVE-2019-8237Эксплойта нет | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earadobe · acrobat dc · CWE-327 | Критическая9,8 | — | 2,8 % | 23 окт. 2019 г. |
40В плане | CVE-2019-0187Эксплойта нет | Unauthenticated RCE is possible when JMeter is used in distributed mode (-r or -R command line options).apache · jmeter · CWE-327 | Критическая9,8 | — | 2,7 % | 6 мар. 2019 г. |
40В плане | CVE-2022-3365Готовый эксплойт | Emote Interactive Remote Mouse Server command injection due to weak encodingemote interactive · remote mouse server · CWE-327 | Критическая9,8 | — | 2,1 % | 27 янв. 2025 г. |
39Наблюдать | CVE-2017-17878Эксплойта нет | An issue was discovered in Valve Steam Link build 643.valvesoftware · steam link firmware · CWE-327 | Критическая9,8 | — | 1,6 % | 27 дек. 2017 г. |
39Наблюдать | CVE-2019-13022Эксплойта нет | Bond JetSelect (all versions) has an issue in the Java class (ENCtool.jar) and corresponding password generation algorithm (used to set initjetstream · jetselect · CWE-327 | Критическая9,8 | — | 1,3 % | 14 мая 2020 г. |
39Наблюдать | CVE-2012-4449Эксплойта нет | Apache Hadoop before 0.23.4, 1.x before 1.0.4, and 2.x before 2.0.2 generate token passwords using a 20-bit secret when Kerberos security feapache · hadoop · CWE-327 | Критическая9,8 | — | 1,2 % | 30 окт. 2017 г. |
39Наблюдать | CVE-2017-9859Эксплойта нет | An issue was discovered in SMA Solar Technology products.sma · sunny boy 3600 firmware · CWE-327 | Критическая9,8 | — | 1,1 % | 5 авг. 2017 г. |
39Наблюдать | CVE-2019-5723Эксплойта нет | An issue was discovered in portier vision 4.4.4.2 and 4.4.4.6.portier · portier · CWE-327 | Критическая9,8 | — | 1,1 % | 21 мар. 2019 г. |
39Наблюдать | CVE-2019-16143Эксплойта нет | An issue was discovered in the blake2 crate before 0.8.1 for Rust.blake2 · blake2-rust · CWE-327 | Критическая9,8 | — | 0,9 % | 9 сент. 2019 г. |
39Наблюдать | CVE-2017-4917Эксплойта нет | VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x locally stores vCenter Server credentials using reversible encryption.vmware · vsphere data protection · CWE-327 | Критическая9,8 | — | 0,8 % | 7 июн. 2017 г. |
39Наблюдать | CVE-2021-36298Эксплойта нет | Dell EMC InsightIQ, versions prior to 4.1.4, contain risky cryptographic algorithms in the SSH component.dell · isilon insightiq firmware · CWE-327 | Критическая9,8 | — | 0,8 % | 1 окт. 2021 г. |
39Наблюдать | CVE-2021-45696Эксплойта нет | An issue was discovered in the sha2 crate 0.9.7 before 0.9.8 for Rust.sha2 project · sha2 · CWE-327 | Критическая9,8 | — | 0,8 % | 26 дек. 2021 г. |
39Наблюдать | CVE-2020-3681Эксплойта нет | Authenticated and encrypted payload MMEs can be forged and remotely sent to any HPAV2 system using a jailbreak key recoverable from code.qualcomm · - · CWE-327 | Критическая9,8 | — | 0,7 % | 31 июл. 2020 г. |
39Наблюдать | CVE-2022-26854Эксплойта нет | Dell PowerScale OneFS, versions 8.2.x-9.2.x, contain risky cryptographic algorithms.dell · emc powerscale onefs · CWE-327 | Критическая9,8 | — | 0,7 % | 8 апр. 2022 г. |
39Наблюдать | CVE-2019-9095Эксплойта нет | An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3,moxa · mb3170 firmware · CWE-327 | Критическая9,8 | — | 0,7 % | 11 мар. 2020 г. |
39Наблюдать | CVE-2017-17717Эксплойта нет | Sonatype Nexus Repository Manager through 2.14.5 has weak password encryption with a hardcoded CMMDwoV value in the LDAP integration featuresonatype · nexus repository manager · CWE-327 | Критическая9,8 | — | 0,7 % | 17 дек. 2017 г. |
39Наблюдать | CVE-2020-36363Эксплойта нет | Amazon AWS CloudFront TLSv1.2_2019 allows TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 and TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384, which some entitiamazon · amazon cloudfront · CWE-327 | Критическая9,8 | — | 0,7 % | 12 авг. 2021 г. |
39Наблюдать | CVE-2022-31230Эксплойта нет | Dell PowerScale OneFS, versions 8.2.x-9.2.x, contain broken or risky cryptographic algorithm.dell · powerscale onefs · CWE-327 | Критическая9,8 | — | 0,7 % | 28 июн. 2022 г. |
39Наблюдать | CVE-2021-22738Эксплойта нет | Use of a Broken or Risky Cryptographic Algorithm vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior that could cschneider-electric · spacelynk firmware · CWE-327 | Критическая9,8 | — | 0,6 % | 26 мая 2021 г. |
39Наблюдать | CVE-2024-31510Эксплойта нет | An issue in Open Quantum Safe liboqs v.10.0 allows a remote attacker to escalate privileges via the crypto_sign_signature parameter in the /openquantumsafe · liboqs · CWE-327 | Критическая9,8 | — | 0,6 % | 24 мая 2024 г. |
39Наблюдать | CVE-2020-10377Эксплойта нет | A weak encryption vulnerability in Mitel MiVoice Connect Client before 214.100.1214.0 could allow an unauthenticated attacker to gain accessmitel · mivoice connect client · CWE-327 | Критическая9,8 | — | 0,6 % | 17 апр. 2020 г. |
- CVE-2023-3403959В плане
Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key generation.
КритическаяCVSS 9,8Готовый эксплойтEPSS 67 %vmware · aria operations for networks29 авг. 2023 г.
- CVE-2016-660256В плане
ZOHO WebNMS Framework 5.2 and 5.2 SP1 use a weak obfuscation algorithm to store passwords, which allows context-dependent attackers to obtai
КритическаяCVSS 9,8Готовый эксплойтEPSS 55 %zohocorp · webnms framework23 янв. 2017 г.
- CVE-2014-868752В плане
Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root privileges by levera
КритическаяCVSS 9,8Готовый эксплойтEPSS 44 %seagate · business nas firmware8 июн. 2017 г.
- CVE-2007-601340В плане
Wordpress 1.5 through 2.3.1 uses cookie values based on the MD5 hash of a password MD5 hash, which allows attackers to bypass authentication
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %wordpress · wordpress19 нояб. 2007 г.
- CVE-2019-823740В плане
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and ear
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %adobe · acrobat dc23 окт. 2019 г.
- CVE-2019-018740В плане
Unauthenticated RCE is possible when JMeter is used in distributed mode (-r or -R command line options).
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %apache · jmeter6 мар. 2019 г.
- CVE-2022-336540В плане
Emote Interactive Remote Mouse Server command injection due to weak encoding
КритическаяCVSS 9,8Готовый эксплойтEPSS 2 %emote interactive · remote mouse server27 янв. 2025 г.
- CVE-2017-1787839Наблюдать
An issue was discovered in Valve Steam Link build 643.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %valvesoftware · steam link firmware27 дек. 2017 г.
- CVE-2019-1302239Наблюдать
Bond JetSelect (all versions) has an issue in the Java class (ENCtool.jar) and corresponding password generation algorithm (used to set init
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %jetstream · jetselect14 мая 2020 г.
- CVE-2012-444939Наблюдать
Apache Hadoop before 0.23.4, 1.x before 1.0.4, and 2.x before 2.0.2 generate token passwords using a 20-bit secret when Kerberos security fe
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %apache · hadoop30 окт. 2017 г.
- CVE-2017-985939Наблюдать
An issue was discovered in SMA Solar Technology products.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %sma · sunny boy 3600 firmware5 авг. 2017 г.
- CVE-2019-572339Наблюдать
An issue was discovered in portier vision 4.4.4.2 and 4.4.4.6.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %portier · portier21 мар. 2019 г.
- CVE-2019-1614339Наблюдать
An issue was discovered in the blake2 crate before 0.8.1 for Rust.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %blake2 · blake2-rust9 сент. 2019 г.
- CVE-2017-491739Наблюдать
VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x locally stores vCenter Server credentials using reversible encryption.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %vmware · vsphere data protection7 июн. 2017 г.
- CVE-2021-3629839Наблюдать
Dell EMC InsightIQ, versions prior to 4.1.4, contain risky cryptographic algorithms in the SSH component.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %dell · isilon insightiq firmware1 окт. 2021 г.
- CVE-2021-4569639Наблюдать
An issue was discovered in the sha2 crate 0.9.7 before 0.9.8 for Rust.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %sha2 project · sha226 дек. 2021 г.
- CVE-2020-368139Наблюдать
Authenticated and encrypted payload MMEs can be forged and remotely sent to any HPAV2 system using a jailbreak key recoverable from code.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %qualcomm · -31 июл. 2020 г.
- CVE-2022-2685439Наблюдать
Dell PowerScale OneFS, versions 8.2.x-9.2.x, contain risky cryptographic algorithms.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %dell · emc powerscale onefs8 апр. 2022 г.
- CVE-2019-909539Наблюдать
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3,
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %moxa · mb3170 firmware11 мар. 2020 г.
- CVE-2017-1771739Наблюдать
Sonatype Nexus Repository Manager through 2.14.5 has weak password encryption with a hardcoded CMMDwoV value in the LDAP integration feature
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %sonatype · nexus repository manager17 дек. 2017 г.
- CVE-2020-3636339Наблюдать
Amazon AWS CloudFront TLSv1.2_2019 allows TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 and TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384, which some entiti
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %amazon · amazon cloudfront12 авг. 2021 г.
- CVE-2022-3123039Наблюдать
Dell PowerScale OneFS, versions 8.2.x-9.2.x, contain broken or risky cryptographic algorithm.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %dell · powerscale onefs28 июн. 2022 г.
- CVE-2021-2273839Наблюдать
Use of a Broken or Risky Cryptographic Algorithm vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior that could c
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %schneider-electric · spacelynk firmware26 мая 2021 г.
- CVE-2024-3151039Наблюдать
An issue in Open Quantum Safe liboqs v.10.0 allows a remote attacker to escalate privileges via the crypto_sign_signature parameter in the /
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %openquantumsafe · liboqs24 мая 2024 г.
- CVE-2020-1037739Наблюдать
A weak encryption vulnerability in Mitel MiVoice Connect Client before 214.100.1214.0 could allow an unauthenticated attacker to gain access
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mitel · mivoice connect client17 апр. 2020 г.