CWE-334 · 12 записей
Small Space of Random Values
CVE этого класса
12 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2023-39979Эксплойта нет | MXsecurity Authentication Bypassmoxa · mxsecurity · CWE-334 | Критическая9,8 | — | 1,0 % | 2 сент. 2023 г. |
36Наблюдать | CVE-2025-3895Эксплойта нет | Low token entropy in MegaBIPjan syski · megabip · CWE-334 | Критическая9,1 | — | 0,5 % | 23 мая 2025 г. |
30Наблюдать | CVE-2022-22517Эксплойта нет | Communication Components in multiple CODESYS products vulnerable to communication channel disruptioncodesys · control for beaglebone sl · CWE-334 | Высокая7,5 | — | 1,3 % | 7 апр. 2022 г. |
30Наблюдать | CVE-2021-21955Эксплойта нет | An authentication bypass vulnerability exists in the get_aes_key_info_by_packetid() function of the home_security binary of Anker Eufy Homebanker · eufy homebase 2 firmware · CWE-334 | Высокая7,5 | — | 1,0 % | 9 дек. 2021 г. |
30Наблюдать | CVE-2022-24402Эксплойта нет | Intentionally weakened effective strength in TETRA TEA1midnightblue · tetra\ · CWE-334 | Высокая7,5 | — | 0,6 % | 19 окт. 2023 г. |
29Наблюдать | CVE-2020-7566Эксплойта нет | A CWE-334: Small Space of Random Values vulnerability exists in Modicon M221 (all references, all versions) that could allow the attacker toschneider-electric · modicon m221 firmware · CWE-334 | Высокая7,3 | — | 0,3 % | 19 нояб. 2020 г. |
27Наблюдать | CVE-2024-54017Эксплойта нет | A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V11.0), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 siemens · siprotec 5 6md84 (cp300) · CWE-334 | Средняя6,9 | — | 0,3 % | 12 мая 2026 г. |
26Наблюдать | CVE-2023-6951Эксплойта нет | A Use of Weak Credentials vulnerability affecting the Wi-Fi network generated by a set of DJI drones could allow a remote attacker to derivedji · mavic 3 pro · CWE-334 | Средняя6,6 | — | 0,3 % | 2 апр. 2024 г. |
22Наблюдать | GHSA-jp37-5qhw-mffwЭксплойта нет | Sharks has a Bias of Polynomial Coefficients in Secret Sharingcrates.io · sharks · CWE-334 | Средняя5,5 | — | — | 18 нояб. 2024 г. |
21Наблюдать | CVE-2022-33707Эксплойта нет | Improper identifier creation logic in Find My Mobile prior to version 7.2.24.12 allows attacker to identify the device.samsung · find my mobile · CWE-334 | Средняя5,3 | — | 0,8 % | 12 июл. 2022 г. |
21Наблюдать | CVE-2022-20941Эксплойта нет | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, recisco · secure firewall management center · CWE-334 | Средняя5,3 | — | 0,7 % | 15 нояб. 2022 г. |
21Наблюдать | CVE-2024-52616Эксплойта нет | Avahi: avahi wide-area dns predictable transaction idsred hat · red hat enterprise linux 9 · CWE-334 | Средняя5,3 | — | 0,7 % | 21 нояб. 2024 г. |
- CVE-2023-3997939Наблюдать
MXsecurity Authentication Bypass
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %moxa · mxsecurity2 сент. 2023 г.
- CVE-2025-389536Наблюдать
Low token entropy in MegaBIP
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %jan syski · megabip23 мая 2025 г.
- CVE-2022-2251730Наблюдать
Communication Components in multiple CODESYS products vulnerable to communication channel disruption
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %codesys · control for beaglebone sl7 апр. 2022 г.
- CVE-2021-2195530Наблюдать
An authentication bypass vulnerability exists in the get_aes_key_info_by_packetid() function of the home_security binary of Anker Eufy Homeb
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %anker · eufy homebase 2 firmware9 дек. 2021 г.
- CVE-2022-2440230Наблюдать
Intentionally weakened effective strength in TETRA TEA1
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %midnightblue · tetra\19 окт. 2023 г.
- CVE-2020-756629Наблюдать
A CWE-334: Small Space of Random Values vulnerability exists in Modicon M221 (all references, all versions) that could allow the attacker to
ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %schneider-electric · modicon m221 firmware19 нояб. 2020 г.
- CVE-2024-5401727Наблюдать
A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V11.0), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5
СредняяCVSS 6,9Эксплойта нетEPSS 0 %siemens · siprotec 5 6md84 (cp300)12 мая 2026 г.
- CVE-2023-695126Наблюдать
A Use of Weak Credentials vulnerability affecting the Wi-Fi network generated by a set of DJI drones could allow a remote attacker to derive
СредняяCVSS 6,6Эксплойта нетEPSS 0 %dji · mavic 3 pro2 апр. 2024 г.
- GHSA-jp37-5qhw-mffw22Наблюдать
Sharks has a Bias of Polynomial Coefficients in Secret Sharing
СредняяCVSS 5,5Эксплойта нетcrates.io · sharks18 нояб. 2024 г.
- CVE-2022-3370721Наблюдать
Improper identifier creation logic in Find My Mobile prior to version 7.2.24.12 allows attacker to identify the device.
СредняяCVSS 5,3Эксплойта нетEPSS 1 %samsung · find my mobile12 июл. 2022 г.
- CVE-2022-2094121Наблюдать
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, re
СредняяCVSS 5,3Эксплойта нетEPSS 1 %cisco · secure firewall management center15 нояб. 2022 г.
- CVE-2024-5261621Наблюдать
Avahi: avahi wide-area dns predictable transaction ids
СредняяCVSS 5,3Эксплойта нетEPSS 1 %red hat · red hat enterprise linux 921 нояб. 2024 г.