Перейти к содержимому
Noroxi

CWE-757 · 30 записей

Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')

CVE этого класса

30 записей

  • CVE-2017-9269
    40В плане

    lack of keypinning in libzypp could lead to repository switching

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    opensuse · libzypp1 мар. 2018 г.

  • CVE-2026-72887
    39Наблюдать

    Net::OAuth::Client versions before 0.32 for Perl allow the service provider to silently downgrade OAuth 1.0a to OAuth 1.0 in get_request_token

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    16 авг. 2026 г.

  • CVE-2019-14887
    36Наблюдать

    A flaw was found when an OpenSSL security provider is used with Wildfly, the 'enabled-protocols' value in the Wildfly configuration isn't ho

    КритическаяCVSS 9,1Эксплойта нетEPSS 1 %

    redhat · jboss data grid16 мар. 2020 г.

  • CVE-2024-4995
    36Наблюдать

    Protocol Downgrade in Wapro ERP Desktop

    КритическаяCVSS 9,1Эксплойта нетEPSS 1 %

    asseco business solutions s.a. · wapro erp desktop18 дек. 2024 г.

  • CVE-2026-55953
    36Наблюдать

    TLS 1.2 and DTLS client accepts unoffered anonymous cipher suite, bypassing server authentication

    КритическаяCVSS 9,1Эксплойта нетEPSS 0 %

    erlang · erlang\/otp27 июл. 2026 г.

  • CVE-2026-18691
    36Наблюдать

    Improper Authentication in MongoDB Intra-Cluster Connections Allows Credential Exposure

    КритическаяCVSS 9,0Эксплойта нетEPSS 0 %

    mongodb · mongodb11 авг. 2026 г.

  • CVE-2024-38883
    36Наблюдать

    An issue in Horizon Business Services Inc.

    КритическаяCVSS 9,1Эксплойта нетEPSS 0 %

    horizoncloud · caterease2 авг. 2024 г.

  • CVE-2026-89177
    34Наблюдать

    Howyar|WeenyGenius - Use of Insecure Protocol

    ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %

    howyar · weenygenius11 сент. 2026 г.

  • CVE-2024-8773
    33Наблюдать

    Protocol Downgrade in SIMPLE.ERP

    ВысокаяCVSS 8,3Эксплойта нетEPSS 0 %

    simple sa · simple.erp24 мар. 2025 г.

  • CVE-2023-2974
    32Наблюдать

    Quarkus-core: tls protocol configured with quarkus.http.ssl.protocols is not enforced, client can enforce weaker supported tls protocol

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    redhat · build of quarkus4 июл. 2023 г.

  • CVE-2018-25029
    32Наблюдать

    The Z-Wave specification requires that S2 security can be downgraded to S0 or other less secure protocols, allowing an attacker within radio

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    silabs · zgm130s037hgn firmware4 февр. 2022 г.

  • CVE-2022-23000
    31Наблюдать

    Weak Default SSL use in Port Forwarding Service

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    westerndigital · my cloud pr2100 firmware25 июл. 2022 г.

  • CVE-2017-9267
    30Наблюдать

    eDirectory LDAP peer certificate validation issue

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    novell · edirectory2 мар. 2018 г.

  • CVE-2026-4942
    30Наблюдать

    IBM i is Affected by Algorithm Downgrade in Transport Layer Security []

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    ibm · i17 июл. 2026 г.

  • CVE-2026-32650
    30Наблюдать

    Anviz CrossChex Standard Algorithm Downgrade

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    anviz · crosschex standard17 апр. 2026 г.

  • CVE-2025-10693
    30Наблюдать

    Silicon Labs Z-Wave PIR Sensor Joins Network as Non-Secure

    ВысокаяCVSS 7,6Эксплойта нетEPSS 0 %

    silabs.com · silicon labs z-wave sdk31 окт. 2025 г.

  • CVE-2022-33160
    30Наблюдать

    IBM Security Directory Suite information disclosure

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    ibm · security directory suite va6 окт. 2023 г.

  • CVE-2023-7005
    30Наблюдать

    A specially crafted message can be sent to the TTLock App that downgrades the encryption protocol used for communication, and can be utilize

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    sciener · ttlock app19 дек. 2024 г.

  • CVE-2025-36582
    30Наблюдать

    Dell NetWorker, versions 19.12.0.1 and prior, contains a Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade') vulne

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    dell · networker1 июл. 2025 г.

  • CVE-2021-36326
    26Наблюдать

    Dell EMC Streaming Data Platform, versions prior to 1.3 contain an SSL Strip Vulnerability in the User Interface (UI).

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    dell · emc streaming data platform30 нояб. 2021 г.

  • CVE-2020-16200
    26Наблюдать

    Philips Clinical Collaboration Platform Algorithm Downgrade

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    philips · clinical collaboration platform18 сент. 2020 г.

  • CVE-2024-20069
    26Наблюдать

    In modem, there is a possible selection of less-secure algorithm during the VoWiFi IKE due to a missing DH downgrade check.

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    mediatek · nr152 июн. 2024 г.

  • CVE-2026-2673
    26Наблюдать

    OpenSSL TLS 1.3 server may choose unexpected key agreement group

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    openssl · openssl13 мар. 2026 г.

  • CVE-2026-59293
    26Наблюдать

    SMB minimum protocol dialect defaults to SMB1

    СредняяCVSS 6,6Эксплойта нетEPSS 0 %

    vmware · spring integration27 авг. 2026 г.

  • CVE-2019-16791
    23Наблюдать

    downgrade of effective Strict Transport Security (STS) policy in postfix-mta-sts-resolver

    СредняяCVSS 5,9Эксплойта нетEPSS 1 %

    postfix-mta-sts-resolver project · postfix-mta-sts-resolver21 янв. 2020 г.

Все классы уязвимостей