CWE-332 · 10 записей
Insufficient Entropy in PRNG
CVE этого класса
10 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2018-9057Эксплойта нет | aws/resource_aws_iam_user_login_profile.go in the HashiCorp Terraform Amazon Web Services (AWS) provider through v1.12.0 has an inappropriathashicorp · terraform · CWE-332 | Критическая9,8 | — | 1,9 % | 27 мар. 2018 г. |
31Наблюдать | CVE-2016-10743Эксплойта нет | hostapd before 2.6 does not prevent use of the low-quality PRNG that is reached by an os_random() function call.w1.fi · hostapd · CWE-332 | Высокая7,5 | — | 2,4 % | 23 мар. 2019 г. |
31Наблюдать | CVE-2019-1715Эксплойта нет | Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Low-Entropy Keys Vulnerabilitycisco · adaptive security appliance device manager · CWE-332 | Высокая7,5 | — | 1,7 % | 3 мая 2019 г. |
30Наблюдать | CVE-2016-9154Эксплойта нет | Siemens Desigo PX Web modules PXA40-W0, PXA40-W1, PXA40-W2 for Desigo PX automation controllers PXC00-E.D, PXC50-E.D, PXC100-E.D, PXC200-E.Dsiemens · desigo web module pxa30-w0 firmware · CWE-332 | Высокая7,5 | — | 1,5 % | 23 дек. 2016 г. |
30Наблюдать | CVE-2014-9690Эксплойта нет | Huawei home gateways WS318 with software V100R001C01B022 and earlier versions are affected by the PIN offline brute force cracking vulnerabihuawei · ws318 firmware · CWE-332 | Высокая7,5 | — | 0,8 % | 2 апр. 2017 г. |
30Наблюдать | CVE-2023-20107Эксплойта нет | Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Low-Entropy Keys Vulnerabilitycisco · adaptive security appliance · CWE-332 | Высокая7,5 | — | 0,7 % | 23 мар. 2023 г. |
29Наблюдать | CVE-2017-18486Proof of concept | Jitbit Helpdesk before 9.0.3 allows remote attackers to escalate privileges because of mishandling of the User/AutoLogin userHash parameter.jitbit · helpdesk · CWE-332 | Высокая7,2 | — | 4,8 % | 9 авг. 2019 г. |
29Наблюдать | CVE-2026-3290Эксплойта нет | Timing limitations of the HRNG in RS9116 when power save mode is enabled results in predictable valuessilicon labs · rs9116 sdk · CWE-332 | Высокая7,4 | — | 0,3 % | 14 мая 2026 г. |
18Наблюдать | CVE-2014-0016Эксплойта нет | stunnel before 5.00, when using fork threading, does not properly update the state of the OpenSSL pseudo-random number generator (PRNG), whistunnel · stunnel · CWE-332 | Средняя4,3 | — | 2,2 % | 24 мар. 2014 г. |
10Наблюдать | CVE-2017-9371Эксплойта нет | In BlackBerry QNX Software Development Platform (SDP) 6.6.0 and 6.5.0 SP1 and earlier, a loss of integrity vulnerability in the default confblackberry · qnx software development platform · CWE-332 | Низкая2,6 | — | 0,8 % | 14 нояб. 2017 г. |
- CVE-2018-905740В плане
aws/resource_aws_iam_user_login_profile.go in the HashiCorp Terraform Amazon Web Services (AWS) provider through v1.12.0 has an inappropriat
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %hashicorp · terraform27 мар. 2018 г.
- CVE-2016-1074331Наблюдать
hostapd before 2.6 does not prevent use of the low-quality PRNG that is reached by an os_random() function call.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %w1.fi · hostapd23 мар. 2019 г.
- CVE-2019-171531Наблюдать
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Low-Entropy Keys Vulnerability
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %cisco · adaptive security appliance device manager3 мая 2019 г.
- CVE-2016-915430Наблюдать
Siemens Desigo PX Web modules PXA40-W0, PXA40-W1, PXA40-W2 for Desigo PX automation controllers PXC00-E.D, PXC50-E.D, PXC100-E.D, PXC200-E.D
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %siemens · desigo web module pxa30-w0 firmware23 дек. 2016 г.
- CVE-2014-969030Наблюдать
Huawei home gateways WS318 with software V100R001C01B022 and earlier versions are affected by the PIN offline brute force cracking vulnerabi
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %huawei · ws318 firmware2 апр. 2017 г.
- CVE-2023-2010730Наблюдать
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Low-Entropy Keys Vulnerability
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %cisco · adaptive security appliance23 мар. 2023 г.
- CVE-2017-1848629Наблюдать
Jitbit Helpdesk before 9.0.3 allows remote attackers to escalate privileges because of mishandling of the User/AutoLogin userHash parameter.
ВысокаяCVSS 7,2Proof of conceptEPSS 5 %jitbit · helpdesk9 авг. 2019 г.
- CVE-2026-329029Наблюдать
Timing limitations of the HRNG in RS9116 when power save mode is enabled results in predictable values
ВысокаяCVSS 7,4Эксплойта нетEPSS 0 %silicon labs · rs9116 sdk14 мая 2026 г.
- CVE-2014-001618Наблюдать
stunnel before 5.00, when using fork threading, does not properly update the state of the OpenSSL pseudo-random number generator (PRNG), whi
СредняяCVSS 4,3Эксплойта нетEPSS 2 %stunnel · stunnel24 мар. 2014 г.
- CVE-2017-937110Наблюдать
In BlackBerry QNX Software Development Platform (SDP) 6.6.0 and 6.5.0 SP1 and earlier, a loss of integrity vulnerability in the default conf
НизкаяCVSS 2,6Эксплойта нетEPSS 1 %blackberry · qnx software development platform14 нояб. 2017 г.