CWE-331 · 138 записей
Insufficient Entropy
CVE этого класса
138 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
56В плане | CVE-2008-1447Готовый эксплойт | The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windows 2000 SP4, XP SP2 microsoft · windows 2000 · CWE-331 | Средняя6,8 | — | 95,2 % | 8 июл. 2008 г. |
46В плане | CVE-2018-18326Готовый эксплойт | DNN (aka DotNetNuke) 9.2 through 9.2.2 incorrectly converts encryption key source values, resulting in lower than expected entropy.dnnsoftware · dotnetnuke · CWE-331 | Высокая7,5 | — | 54,3 % | 3 июл. 2019 г. |
44В плане | CVE-2018-15812Готовый эксплойт | DNN (aka DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, resulting in lower than expected entropy.dnnsoftware · dotnetnuke · CWE-331 | Высокая7,5 | — | 47,2 % | 3 июл. 2019 г. |
40В плане | CVE-2008-2108Эксплойта нет | The GENERATE_SEED macro in PHP 4.x before 4.4.8 and 5.x before 5.2.5, when running on 64-bit systems, performs a multiplication that generatphp · php · CWE-331 | Критическая9,8 | — | 4,3 % | 7 мая 2008 г. |
40В плане | CVE-2013-2260Эксплойта нет | Cryptocat before 2.0.22: Cryptocat.random() Function Array Key has Entropy Weaknesscryptocat project · cryptocat · CWE-331 | Критическая9,8 | — | 2,2 % | 4 нояб. 2019 г. |
40В плане | CVE-2022-34294Эксплойта нет | totd 1.5.3 uses a fixed UDP source port in upstream queries sent to DNS resolvers.totd project · totd · CWE-331 | Критическая9,8 | — | 1,8 % | 15 авг. 2022 г. |
40В плане | CVE-2022-43755Эксплойта нет | Rancher: Non-random authentication tokensuse · rancher · CWE-331 | Критическая9,8 | — | 1,7 % | 7 февр. 2023 г. |
40В плане | CVE-2020-12735Эксплойта нет | reset.php in DomainMOD 4.13.0 uses insufficient entropy for password reset requests, leading to account takeover.domainmod · domainmod · CWE-331 | Критическая9,8 | — | 1,7 % | 8 мая 2020 г. |
40В плане | CVE-2018-1000620Эксплойта нет | Eran Hammer cryptiles version 4.1.1 earlier contains a CWE-331: Insufficient Entropy vulnerability in randomDigits() method that can result cryptiles project · cryptiles · CWE-331 | Критическая9,8 | — | 1,7 % | 9 июл. 2018 г. |
39Наблюдать | CVE-2021-36294Эксплойта нет | Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authentication bypass vulnerability.dell · emc unity operating environment · CWE-331 | Критическая9,8 | — | 1,6 % | 25 янв. 2022 г. |
39Наблюдать | CVE-2021-22727Эксплойта нет | A CWE-331: Insufficient Entropy vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parkingschneider-electric · evlink city evc1s22p4 firmware · CWE-331 | Критическая9,8 | — | 1,4 % | 21 июл. 2021 г. |
39Наблюдать | CVE-2021-41615Эксплойта нет | websda.c in GoAhead WebServer 2.1.8 has insufficient nonce entropy because the nonce calculation relies on the hardcoded onceuponatimeinparaembedthis · goahead · CWE-331 | Критическая9,8 | — | 1,4 % | 8 авг. 2022 г. |
39Наблюдать | CVE-2021-33027Эксплойта нет | Sylabs Singularity Enterprise through 1.6.2 has Insufficient Entropy in a nonce.sylabs · singularity · CWE-331 | Критическая9,8 | — | 1,3 % | 19 июл. 2021 г. |
39Наблюдать | CVE-2021-36320Эксплойта нет | Dell Networking X-Series firmware versions prior to 3.0.1.8 contain an authentication bypass vulnerability.dell · x1008p firmware · CWE-331 | Критическая9,8 | — | 1,2 % | 19 нояб. 2021 г. |
39Наблюдать | CVE-2020-29508Эксплойта нет | Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Improper Inputdell · bsafe crypto-c-micro-edition · CWE-331 | Критическая9,8 | — | 1,2 % | 11 июл. 2022 г. |
39Наблюдать | CVE-2023-49599Эксплойта нет | An insufficient entropy vulnerability exists in the salt generation functionality of WWBN AVideo dev master commit 15fed957fb.wwbn · avideo · CWE-331 | Критическая9,8 | — | 1,0 % | 10 янв. 2024 г. |
39Наблюдать | CVE-2023-31176Эксплойта нет | Insufficient entropy vulnerability could lead to authentication bypassselinc · sel-451 firmware · CWE-331 | Критическая9,8 | — | 0,9 % | 30 нояб. 2023 г. |
39Наблюдать | CVE-2024-25730Эксплойта нет | Hitron CODA-4582 and CODA-4589 devices have default PSKs that are generated from 5-digit hex values concatenated with a "Hitron" substring, hitrontech · coda-4582u firmware · CWE-331 | Критическая9,8 | — | 0,9 % | 23 февр. 2024 г. |
39Наблюдать | CVE-2024-36400Эксплойта нет | nano-id is unable to generate the correct character setviz · nano id · CWE-331 | Критическая9,8 | — | 0,8 % | 4 июн. 2024 г. |
39Наблюдать | CVE-2023-4344Эксплойта нет | Broadcom RAID Controller web interface is vulnerable to insufficient randomness due to improper use of ssl.rnd to setup CIM connectionbroadcom · raid controller web interface · CWE-331 | Критическая9,8 | — | 0,7 % | 15 авг. 2023 г. |
39Наблюдать | CVE-2026-38447Эксплойта нет | osTicket 1.18.3 generates API keys using a predictable construction based on MD5 hashing.CWE-331 | Критическая9,8 | — | 0,7 % | 3 авг. 2026 г. |
39Наблюдать | CVE-2026-13639Эксплойта нет | An insufficient entropy vulnerability in login logic in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009synology · diskstation manager (dsm) · CWE-331 | Критическая9,8 | — | 0,7 % | 18 сент. 2026 г. |
39Наблюдать | CVE-2025-47781Эксплойта нет | Rallly Insufficient Password Login Token Entropy Leads to Account Takeoverrallly · rallly · CWE-331 | Критическая9,8 | — | 0,6 % | 14 мая 2025 г. |
39Наблюдать | CVE-2025-67504Эксплойта нет | WBCE CMS has Weak Random Number Generator in Password Generation Functionwbce · wbce cms · CWE-331 | Критическая9,8 | — | 0,5 % | 9 дек. 2025 г. |
39Наблюдать | CVE-2026-34236Эксплойта нет | Auth0 PHP SDK Insufficient Entropy in Cookie Encryptionauth0 · auth0-php · CWE-331 | Критическая9,8 | — | 0,3 % | 1 апр. 2026 г. |
- CVE-2008-144756В плане
The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windows 2000 SP4, XP SP2
СредняяCVSS 6,8Готовый эксплойтEPSS 95 %microsoft · windows 20008 июл. 2008 г.
- CVE-2018-1832646В плане
DNN (aka DotNetNuke) 9.2 through 9.2.2 incorrectly converts encryption key source values, resulting in lower than expected entropy.
ВысокаяCVSS 7,5Готовый эксплойтEPSS 54 %dnnsoftware · dotnetnuke3 июл. 2019 г.
- CVE-2018-1581244В плане
DNN (aka DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, resulting in lower than expected entropy.
ВысокаяCVSS 7,5Готовый эксплойтEPSS 47 %dnnsoftware · dotnetnuke3 июл. 2019 г.
- CVE-2008-210840В плане
The GENERATE_SEED macro in PHP 4.x before 4.4.8 and 5.x before 5.2.5, when running on 64-bit systems, performs a multiplication that generat
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %php · php7 мая 2008 г.
- CVE-2013-226040В плане
Cryptocat before 2.0.22: Cryptocat.random() Function Array Key has Entropy Weakness
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %cryptocat project · cryptocat4 нояб. 2019 г.
- CVE-2022-3429440В плане
totd 1.5.3 uses a fixed UDP source port in upstream queries sent to DNS resolvers.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %totd project · totd15 авг. 2022 г.
- CVE-2022-4375540В плане
Rancher: Non-random authentication token
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %suse · rancher7 февр. 2023 г.
- CVE-2020-1273540В плане
reset.php in DomainMOD 4.13.0 uses insufficient entropy for password reset requests, leading to account takeover.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %domainmod · domainmod8 мая 2020 г.
- CVE-2018-100062040В плане
Eran Hammer cryptiles version 4.1.1 earlier contains a CWE-331: Insufficient Entropy vulnerability in randomDigits() method that can result
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %cryptiles project · cryptiles9 июл. 2018 г.
- CVE-2021-3629439Наблюдать
Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authentication bypass vulnerability.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %dell · emc unity operating environment25 янв. 2022 г.
- CVE-2021-2272739Наблюдать
A CWE-331: Insufficient Entropy vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %schneider-electric · evlink city evc1s22p4 firmware21 июл. 2021 г.
- CVE-2021-4161539Наблюдать
websda.c in GoAhead WebServer 2.1.8 has insufficient nonce entropy because the nonce calculation relies on the hardcoded onceuponatimeinpara
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %embedthis · goahead8 авг. 2022 г.
- CVE-2021-3302739Наблюдать
Sylabs Singularity Enterprise through 1.6.2 has Insufficient Entropy in a nonce.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %sylabs · singularity19 июл. 2021 г.
- CVE-2021-3632039Наблюдать
Dell Networking X-Series firmware versions prior to 3.0.1.8 contain an authentication bypass vulnerability.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %dell · x1008p firmware19 нояб. 2021 г.
- CVE-2020-2950839Наблюдать
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Improper Input
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %dell · bsafe crypto-c-micro-edition11 июл. 2022 г.
- CVE-2023-4959939Наблюдать
An insufficient entropy vulnerability exists in the salt generation functionality of WWBN AVideo dev master commit 15fed957fb.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %wwbn · avideo10 янв. 2024 г.
- CVE-2023-3117639Наблюдать
Insufficient entropy vulnerability could lead to authentication bypass
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %selinc · sel-451 firmware30 нояб. 2023 г.
- CVE-2024-2573039Наблюдать
Hitron CODA-4582 and CODA-4589 devices have default PSKs that are generated from 5-digit hex values concatenated with a "Hitron" substring,
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %hitrontech · coda-4582u firmware23 февр. 2024 г.
- CVE-2024-3640039Наблюдать
nano-id is unable to generate the correct character set
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %viz · nano id4 июн. 2024 г.
- CVE-2023-434439Наблюдать
Broadcom RAID Controller web interface is vulnerable to insufficient randomness due to improper use of ssl.rnd to setup CIM connection
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %broadcom · raid controller web interface15 авг. 2023 г.
- CVE-2026-3844739Наблюдать
osTicket 1.18.3 generates API keys using a predictable construction based on MD5 hashing.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %3 авг. 2026 г.
- CVE-2026-1363939Наблюдать
An insufficient entropy vulnerability in login logic in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %synology · diskstation manager (dsm)18 сент. 2026 г.
- CVE-2025-4778139Наблюдать
Rallly Insufficient Password Login Token Entropy Leads to Account Takeover
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %rallly · rallly14 мая 2025 г.
- CVE-2025-6750439Наблюдать
WBCE CMS has Weak Random Number Generator in Password Generation Function
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %wbce · wbce cms9 дек. 2025 г.
- CVE-2026-3423639Наблюдать
Auth0 PHP SDK Insufficient Entropy in Cookie Encryption
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %auth0 · auth0-php1 апр. 2026 г.