CWE-757 · 30 записей
Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')
CVE этого класса
30 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2017-9269Эксплойта нет | lack of keypinning in libzypp could lead to repository switchingopensuse · libzypp · CWE-757 | Критическая9,8 | — | 2,2 % | 1 мар. 2018 г. |
39Наблюдать | CVE-2026-72887Эксплойта нет | Net::OAuth::Client versions before 0.32 for Perl allow the service provider to silently downgrade OAuth 1.0a to OAuth 1.0 in get_request_tokenCWE-757 | Критическая9,8 | — | 0,7 % | 16 авг. 2026 г. |
36Наблюдать | CVE-2019-14887Эксплойта нет | A flaw was found when an OpenSSL security provider is used with Wildfly, the 'enabled-protocols' value in the Wildfly configuration isn't horedhat · jboss data grid · CWE-757 | Критическая9,1 | — | 1,1 % | 16 мар. 2020 г. |
36Наблюдать | CVE-2024-4995Эксплойта нет | Protocol Downgrade in Wapro ERP Desktopasseco business solutions s.a. · wapro erp desktop · CWE-757 | Критическая9,1 | — | 0,9 % | 18 дек. 2024 г. |
36Наблюдать | CVE-2026-55953Эксплойта нет | TLS 1.2 and DTLS client accepts unoffered anonymous cipher suite, bypassing server authenticationerlang · erlang\/otp · CWE-757 | Критическая9,1 | — | 0,4 % | 27 июл. 2026 г. |
36Наблюдать | CVE-2026-18691Эксплойта нет | Improper Authentication in MongoDB Intra-Cluster Connections Allows Credential Exposuremongodb · mongodb · CWE-757 | Критическая9,0 | — | 0,4 % | 11 авг. 2026 г. |
36Наблюдать | CVE-2024-38883Эксплойта нет | An issue in Horizon Business Services Inc.horizoncloud · caterease · CWE-757 | Критическая9,1 | — | 0,4 % | 2 авг. 2024 г. |
34Наблюдать | CVE-2026-89177Эксплойта нет | Howyar|WeenyGenius - Use of Insecure Protocolhowyar · weenygenius · CWE-757 | Высокая8,7 | — | 0,4 % | 11 сент. 2026 г. |
33Наблюдать | CVE-2024-8773Эксплойта нет | Protocol Downgrade in SIMPLE.ERPsimple sa · simple.erp · CWE-757 | Высокая8,3 | — | 0,4 % | 24 мар. 2025 г. |
32Наблюдать | CVE-2023-2974Эксплойта нет | Quarkus-core: tls protocol configured with quarkus.http.ssl.protocols is not enforced, client can enforce weaker supported tls protocolredhat · build of quarkus · CWE-757 | Высокая8,1 | — | 0,9 % | 4 июл. 2023 г. |
32Наблюдать | CVE-2018-25029Эксплойта нет | The Z-Wave specification requires that S2 security can be downgraded to S0 or other less secure protocols, allowing an attacker within radiosilabs · zgm130s037hgn firmware · CWE-757 | Высокая8,1 | — | 0,6 % | 4 февр. 2022 г. |
31Наблюдать | CVE-2022-23000Эксплойта нет | Weak Default SSL use in Port Forwarding Servicewesterndigital · my cloud pr2100 firmware · CWE-757 | Высокая7,8 | — | 0,2 % | 25 июл. 2022 г. |
30Наблюдать | CVE-2017-9267Эксплойта нет | eDirectory LDAP peer certificate validation issuenovell · edirectory · CWE-757 | Высокая7,5 | — | 1,0 % | 2 мар. 2018 г. |
30Наблюдать | CVE-2026-4942Эксплойта нет | IBM i is Affected by Algorithm Downgrade in Transport Layer Security []ibm · i · CWE-757 | Высокая7,5 | — | 0,4 % | 17 июл. 2026 г. |
30Наблюдать | CVE-2026-32650Эксплойта нет | Anviz CrossChex Standard Algorithm Downgradeanviz · crosschex standard · CWE-757 | Высокая7,5 | — | 0,3 % | 17 апр. 2026 г. |
30Наблюдать | CVE-2025-10693Эксплойта нет | Silicon Labs Z-Wave PIR Sensor Joins Network as Non-Securesilabs.com · silicon labs z-wave sdk · CWE-757 | Высокая7,6 | — | 0,3 % | 31 окт. 2025 г. |
30Наблюдать | CVE-2022-33160Эксплойта нет | IBM Security Directory Suite information disclosureibm · security directory suite va · CWE-757 | Высокая7,5 | — | 0,3 % | 6 окт. 2023 г. |
30Наблюдать | CVE-2023-7005Эксплойта нет | A specially crafted message can be sent to the TTLock App that downgrades the encryption protocol used for communication, and can be utilizesciener · ttlock app · CWE-757 | Высокая7,5 | — | 0,3 % | 19 дек. 2024 г. |
30Наблюдать | CVE-2025-36582Эксплойта нет | Dell NetWorker, versions 19.12.0.1 and prior, contains a Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade') vulnedell · networker · CWE-757 | Высокая7,5 | — | 0,2 % | 1 июл. 2025 г. |
26Наблюдать | CVE-2021-36326Эксплойта нет | Dell EMC Streaming Data Platform, versions prior to 1.3 contain an SSL Strip Vulnerability in the User Interface (UI).dell · emc streaming data platform · CWE-757 | Средняя6,5 | — | 1,2 % | 30 нояб. 2021 г. |
26Наблюдать | CVE-2020-16200Эксплойта нет | Philips Clinical Collaboration Platform Algorithm Downgradephilips · clinical collaboration platform · CWE-757 | Средняя6,5 | — | 0,6 % | 18 сент. 2020 г. |
26Наблюдать | CVE-2024-20069Эксплойта нет | In modem, there is a possible selection of less-secure algorithm during the VoWiFi IKE due to a missing DH downgrade check.mediatek · nr15 · CWE-757 | Средняя6,5 | — | 0,6 % | 2 июн. 2024 г. |
26Наблюдать | CVE-2026-2673Эксплойта нет | OpenSSL TLS 1.3 server may choose unexpected key agreement groupopenssl · openssl · CWE-757 | Средняя6,5 | — | 0,5 % | 13 мар. 2026 г. |
26Наблюдать | CVE-2026-59293Эксплойта нет | SMB minimum protocol dialect defaults to SMB1vmware · spring integration · CWE-757 | Средняя6,6 | — | 0,2 % | 27 авг. 2026 г. |
23Наблюдать | CVE-2019-16791Эксплойта нет | downgrade of effective Strict Transport Security (STS) policy in postfix-mta-sts-resolverpostfix-mta-sts-resolver project · postfix-mta-sts-resolver · CWE-757 | Средняя5,9 | — | 0,8 % | 21 янв. 2020 г. |
- CVE-2017-926940В плане
lack of keypinning in libzypp could lead to repository switching
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %opensuse · libzypp1 мар. 2018 г.
- CVE-2026-7288739Наблюдать
Net::OAuth::Client versions before 0.32 for Perl allow the service provider to silently downgrade OAuth 1.0a to OAuth 1.0 in get_request_token
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %16 авг. 2026 г.
- CVE-2019-1488736Наблюдать
A flaw was found when an OpenSSL security provider is used with Wildfly, the 'enabled-protocols' value in the Wildfly configuration isn't ho
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %redhat · jboss data grid16 мар. 2020 г.
- CVE-2024-499536Наблюдать
Protocol Downgrade in Wapro ERP Desktop
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %asseco business solutions s.a. · wapro erp desktop18 дек. 2024 г.
- CVE-2026-5595336Наблюдать
TLS 1.2 and DTLS client accepts unoffered anonymous cipher suite, bypassing server authentication
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %erlang · erlang\/otp27 июл. 2026 г.
- CVE-2026-1869136Наблюдать
Improper Authentication in MongoDB Intra-Cluster Connections Allows Credential Exposure
КритическаяCVSS 9,0Эксплойта нетEPSS 0 %mongodb · mongodb11 авг. 2026 г.
- CVE-2024-3888336Наблюдать
An issue in Horizon Business Services Inc.
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %horizoncloud · caterease2 авг. 2024 г.
- CVE-2026-8917734Наблюдать
Howyar|WeenyGenius - Use of Insecure Protocol
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %howyar · weenygenius11 сент. 2026 г.
- CVE-2024-877333Наблюдать
Protocol Downgrade in SIMPLE.ERP
ВысокаяCVSS 8,3Эксплойта нетEPSS 0 %simple sa · simple.erp24 мар. 2025 г.
- CVE-2023-297432Наблюдать
Quarkus-core: tls protocol configured with quarkus.http.ssl.protocols is not enforced, client can enforce weaker supported tls protocol
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %redhat · build of quarkus4 июл. 2023 г.
- CVE-2018-2502932Наблюдать
The Z-Wave specification requires that S2 security can be downgraded to S0 or other less secure protocols, allowing an attacker within radio
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %silabs · zgm130s037hgn firmware4 февр. 2022 г.
- CVE-2022-2300031Наблюдать
Weak Default SSL use in Port Forwarding Service
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %westerndigital · my cloud pr2100 firmware25 июл. 2022 г.
- CVE-2017-926730Наблюдать
eDirectory LDAP peer certificate validation issue
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %novell · edirectory2 мар. 2018 г.
- CVE-2026-494230Наблюдать
IBM i is Affected by Algorithm Downgrade in Transport Layer Security []
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %ibm · i17 июл. 2026 г.
- CVE-2026-3265030Наблюдать
Anviz CrossChex Standard Algorithm Downgrade
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %anviz · crosschex standard17 апр. 2026 г.
- CVE-2025-1069330Наблюдать
Silicon Labs Z-Wave PIR Sensor Joins Network as Non-Secure
ВысокаяCVSS 7,6Эксплойта нетEPSS 0 %silabs.com · silicon labs z-wave sdk31 окт. 2025 г.
- CVE-2022-3316030Наблюдать
IBM Security Directory Suite information disclosure
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %ibm · security directory suite va6 окт. 2023 г.
- CVE-2023-700530Наблюдать
A specially crafted message can be sent to the TTLock App that downgrades the encryption protocol used for communication, and can be utilize
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %sciener · ttlock app19 дек. 2024 г.
- CVE-2025-3658230Наблюдать
Dell NetWorker, versions 19.12.0.1 and prior, contains a Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade') vulne
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %dell · networker1 июл. 2025 г.
- CVE-2021-3632626Наблюдать
Dell EMC Streaming Data Platform, versions prior to 1.3 contain an SSL Strip Vulnerability in the User Interface (UI).
СредняяCVSS 6,5Эксплойта нетEPSS 1 %dell · emc streaming data platform30 нояб. 2021 г.
- CVE-2020-1620026Наблюдать
Philips Clinical Collaboration Platform Algorithm Downgrade
СредняяCVSS 6,5Эксплойта нетEPSS 1 %philips · clinical collaboration platform18 сент. 2020 г.
- CVE-2024-2006926Наблюдать
In modem, there is a possible selection of less-secure algorithm during the VoWiFi IKE due to a missing DH downgrade check.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %mediatek · nr152 июн. 2024 г.
- CVE-2026-267326Наблюдать
OpenSSL TLS 1.3 server may choose unexpected key agreement group
СредняяCVSS 6,5Эксплойта нетEPSS 0 %openssl · openssl13 мар. 2026 г.
- CVE-2026-5929326Наблюдать
SMB minimum protocol dialect defaults to SMB1
СредняяCVSS 6,6Эксплойта нетEPSS 0 %vmware · spring integration27 авг. 2026 г.
- CVE-2019-1679123Наблюдать
downgrade of effective Strict Transport Security (STS) policy in postfix-mta-sts-resolver
СредняяCVSS 5,9Эксплойта нетEPSS 1 %postfix-mta-sts-resolver project · postfix-mta-sts-resolver21 янв. 2020 г.