CWE-329 · 11 записей
Generation of Predictable IV with CBC Mode
CVE этого класса
11 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
30Наблюдать | CVE-2022-46397Эксплойта нет | FP.io VPP (Vector Packet Processor) 22.10, 22.06, 22.02, 21.10, 21.06, 21.01, 20.09, 20.05, 20.01, 19.08, and 19.04 Generates a Predictable lfprojects · vector packet processor · CWE-329 | Высокая7,5 | — | 0,6 % | 28 мар. 2023 г. |
30Наблюдать | CVE-2025-59322Эксплойта нет | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly handle decryption errors and allows encrypted volumes to be mountedCWE-329 | Высокая7,5 | — | 0,5 % | 12 авг. 2026 г. |
26Наблюдать | CVE-2020-5408Эксплойта нет | Dictionary attack with Spring Security queryable text encryptorpivotal software · spring security · CWE-329 | Средняя6,5 | — | 1,6 % | 14 мая 2020 г. |
26Наблюдать | CVE-2024-49783Эксплойта нет | IBM OpenPages with Watson information disclosureibm · openpages with watson · CWE-329 | Средняя6,5 | — | 0,3 % | 8 июл. 2025 г. |
25Наблюдать | CVE-2017-3226Эксплойта нет | Das U-Boot's AES-CBC encryption feature improperly handles an error condition and may allow attacks against the underlying cryptographic implementation and allodenx · u-boot · CWE-329 | Средняя6,4 | — | 0,3 % | 24 июл. 2018 г. |
23Наблюдать | CVE-2021-27499Эксплойта нет | Ypsomed mylife Cloud, mylife Mobile Application, Ypsomed mylife Cloud: All versions prior to 1.7.2, Ypsomed mylife App: All versions prior typsomed · mylife · CWE-329 | Средняя5,9 | — | 0,5 % | 2 авг. 2021 г. |
20Наблюдать | CVE-2024-56141Эксплойта нет | Minosoft has IV equal to keybixilon · minosoft · CWE-329 | Средняя5,0 | — | 0,2 % | 6 июл. 2026 г. |
18Наблюдать | CVE-2017-3225Эксплойта нет | Das U-Boot's AES-CBC encryption feature uses a zero (0) initialization vector that may allow attacks against the underlying cryptographic implementation and alldenx · u-boot · CWE-329 | Средняя4,6 | — | 0,3 % | 24 июл. 2018 г. |
17Наблюдать | CVE-2026-14969Эксплойта нет | 389-ds-base: 389-ds-base: static initialization vector in aes-cbc/3des-cbc attribute encryptionredhat · directory server · CWE-329 | Средняя4,4 | — | 0,1 % | 7 июл. 2026 г. |
16Наблюдать | CVE-2025-2814Эксплойта нет | Crypt::CBC versions between 1.21 and 3.05 for Perl may use insecure rand() function for cryptographic functionslds · crypt::cbc · CWE-329 | Средняя4,0 | — | 0,2 % | 12 апр. 2025 г. |
13Наблюдать | CVE-2022-29054Эксплойта нет | A missing cryptographic steps vulnerability [CWE-325] in the functions that encrypt the DHCP and DNS keys in Fortinet FortiOS version 7.2.0,fortinet · fortiproxy · CWE-329 | Низкая3,3 | — | 0,2 % | 16 февр. 2023 г. |
- CVE-2022-4639730Наблюдать
FP.io VPP (Vector Packet Processor) 22.10, 22.06, 22.02, 21.10, 21.06, 21.01, 20.09, 20.05, 20.01, 19.08, and 19.04 Generates a Predictable
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %lfprojects · vector packet processor28 мар. 2023 г.
- CVE-2025-5932230Наблюдать
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly handle decryption errors and allows encrypted volumes to be mounted
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %12 авг. 2026 г.
- CVE-2020-540826Наблюдать
Dictionary attack with Spring Security queryable text encryptor
СредняяCVSS 6,5Эксплойта нетEPSS 2 %pivotal software · spring security14 мая 2020 г.
- CVE-2024-4978326Наблюдать
IBM OpenPages with Watson information disclosure
СредняяCVSS 6,5Эксплойта нетEPSS 0 %ibm · openpages with watson8 июл. 2025 г.
- CVE-2017-322625Наблюдать
Das U-Boot's AES-CBC encryption feature improperly handles an error condition and may allow attacks against the underlying cryptographic implementation and allo
СредняяCVSS 6,4Эксплойта нетEPSS 0 %denx · u-boot24 июл. 2018 г.
- CVE-2021-2749923Наблюдать
Ypsomed mylife Cloud, mylife Mobile Application, Ypsomed mylife Cloud: All versions prior to 1.7.2, Ypsomed mylife App: All versions prior t
СредняяCVSS 5,9Эксплойта нетEPSS 0 %ypsomed · mylife2 авг. 2021 г.
- CVE-2024-5614120Наблюдать
Minosoft has IV equal to key
СредняяCVSS 5,0Эксплойта нетEPSS 0 %bixilon · minosoft6 июл. 2026 г.
- CVE-2017-322518Наблюдать
Das U-Boot's AES-CBC encryption feature uses a zero (0) initialization vector that may allow attacks against the underlying cryptographic implementation and all
СредняяCVSS 4,6Эксплойта нетEPSS 0 %denx · u-boot24 июл. 2018 г.
- CVE-2026-1496917Наблюдать
389-ds-base: 389-ds-base: static initialization vector in aes-cbc/3des-cbc attribute encryption
СредняяCVSS 4,4Эксплойта нетEPSS 0 %redhat · directory server7 июл. 2026 г.
- CVE-2025-281416Наблюдать
Crypt::CBC versions between 1.21 and 3.05 for Perl may use insecure rand() function for cryptographic functions
СредняяCVSS 4,0Эксплойта нетEPSS 0 %lds · crypt::cbc12 апр. 2025 г.
- CVE-2022-2905413Наблюдать
A missing cryptographic steps vulnerability [CWE-325] in the functions that encrypt the DHCP and DNS keys in Fortinet FortiOS version 7.2.0,
НизкаяCVSS 3,3Эксплойта нетEPSS 0 %fortinet · fortiproxy16 февр. 2023 г.