CWE-327 · 641 kayıt
Use of a Broken or Risky Cryptographic Algorithm
Bu sınıftaki CVE’ler
641 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
59Planlayın | CVE-2023-34039Silahlaştırılmış | Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key generation.vmware · aria operations for networks · CWE-327 | Kritik9,8 | — | %67,2 | 29 Ağu 2023 |
56Planlayın | CVE-2016-6602Silahlaştırılmış | ZOHO WebNMS Framework 5.2 and 5.2 SP1 use a weak obfuscation algorithm to store passwords, which allows context-dependent attackers to obtaizohocorp · webnms framework · CWE-327 | Kritik9,8 | — | %55,1 | 23 Oca 2017 |
52Planlayın | CVE-2014-8687Silahlaştırılmış | Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root privileges by leveraseagate · business nas firmware · CWE-327 | Kritik9,8 | — | %43,8 | 8 Haz 2017 |
40Planlayın | CVE-2007-6013İstismar yok | Wordpress 1.5 through 2.3.1 uses cookie values based on the MD5 hash of a password MD5 hash, which allows attackers to bypass authenticationwordpress · wordpress · CWE-327 | Kritik9,8 | — | %3,3 | 19 Kas 2007 |
40Planlayın | CVE-2019-8237İstismar yok | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earadobe · acrobat dc · CWE-327 | Kritik9,8 | — | %2,8 | 23 Eki 2019 |
40Planlayın | CVE-2019-0187İstismar yok | Unauthenticated RCE is possible when JMeter is used in distributed mode (-r or -R command line options).apache · jmeter · CWE-327 | Kritik9,8 | — | %2,7 | 6 Mar 2019 |
40Planlayın | CVE-2022-3365Silahlaştırılmış | Emote Interactive Remote Mouse Server command injection due to weak encodingemote interactive · remote mouse server · CWE-327 | Kritik9,8 | — | %2,1 | 27 Oca 2025 |
39İzleyin | CVE-2017-17878İstismar yok | An issue was discovered in Valve Steam Link build 643.valvesoftware · steam link firmware · CWE-327 | Kritik9,8 | — | %1,6 | 27 Ara 2017 |
39İzleyin | CVE-2019-13022İstismar yok | Bond JetSelect (all versions) has an issue in the Java class (ENCtool.jar) and corresponding password generation algorithm (used to set initjetstream · jetselect · CWE-327 | Kritik9,8 | — | %1,3 | 14 May 2020 |
39İzleyin | CVE-2012-4449İstismar yok | Apache Hadoop before 0.23.4, 1.x before 1.0.4, and 2.x before 2.0.2 generate token passwords using a 20-bit secret when Kerberos security feapache · hadoop · CWE-327 | Kritik9,8 | — | %1,2 | 30 Eki 2017 |
39İzleyin | CVE-2017-9859İstismar yok | An issue was discovered in SMA Solar Technology products.sma · sunny boy 3600 firmware · CWE-327 | Kritik9,8 | — | %1,1 | 5 Ağu 2017 |
39İzleyin | CVE-2019-5723İstismar yok | An issue was discovered in portier vision 4.4.4.2 and 4.4.4.6.portier · portier · CWE-327 | Kritik9,8 | — | %1,1 | 21 Mar 2019 |
39İzleyin | CVE-2019-16143İstismar yok | An issue was discovered in the blake2 crate before 0.8.1 for Rust.blake2 · blake2-rust · CWE-327 | Kritik9,8 | — | %0,9 | 9 Eyl 2019 |
39İzleyin | CVE-2017-4917İstismar yok | VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x locally stores vCenter Server credentials using reversible encryption.vmware · vsphere data protection · CWE-327 | Kritik9,8 | — | %0,8 | 7 Haz 2017 |
39İzleyin | CVE-2021-36298İstismar yok | Dell EMC InsightIQ, versions prior to 4.1.4, contain risky cryptographic algorithms in the SSH component.dell · isilon insightiq firmware · CWE-327 | Kritik9,8 | — | %0,8 | 1 Eki 2021 |
39İzleyin | CVE-2021-45696İstismar yok | An issue was discovered in the sha2 crate 0.9.7 before 0.9.8 for Rust.sha2 project · sha2 · CWE-327 | Kritik9,8 | — | %0,8 | 26 Ara 2021 |
39İzleyin | CVE-2020-3681İstismar yok | Authenticated and encrypted payload MMEs can be forged and remotely sent to any HPAV2 system using a jailbreak key recoverable from code.qualcomm · - · CWE-327 | Kritik9,8 | — | %0,7 | 31 Tem 2020 |
39İzleyin | CVE-2022-26854İstismar yok | Dell PowerScale OneFS, versions 8.2.x-9.2.x, contain risky cryptographic algorithms.dell · emc powerscale onefs · CWE-327 | Kritik9,8 | — | %0,7 | 8 Nis 2022 |
39İzleyin | CVE-2019-9095İstismar yok | An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3,moxa · mb3170 firmware · CWE-327 | Kritik9,8 | — | %0,7 | 11 Mar 2020 |
39İzleyin | CVE-2017-17717İstismar yok | Sonatype Nexus Repository Manager through 2.14.5 has weak password encryption with a hardcoded CMMDwoV value in the LDAP integration featuresonatype · nexus repository manager · CWE-327 | Kritik9,8 | — | %0,7 | 17 Ara 2017 |
39İzleyin | CVE-2020-36363İstismar yok | Amazon AWS CloudFront TLSv1.2_2019 allows TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 and TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384, which some entitiamazon · amazon cloudfront · CWE-327 | Kritik9,8 | — | %0,7 | 12 Ağu 2021 |
39İzleyin | CVE-2022-31230İstismar yok | Dell PowerScale OneFS, versions 8.2.x-9.2.x, contain broken or risky cryptographic algorithm.dell · powerscale onefs · CWE-327 | Kritik9,8 | — | %0,7 | 28 Haz 2022 |
39İzleyin | CVE-2021-22738İstismar yok | Use of a Broken or Risky Cryptographic Algorithm vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior that could cschneider-electric · spacelynk firmware · CWE-327 | Kritik9,8 | — | %0,6 | 26 May 2021 |
39İzleyin | CVE-2024-31510İstismar yok | An issue in Open Quantum Safe liboqs v.10.0 allows a remote attacker to escalate privileges via the crypto_sign_signature parameter in the /openquantumsafe · liboqs · CWE-327 | Kritik9,8 | — | %0,6 | 24 May 2024 |
39İzleyin | CVE-2020-10377İstismar yok | A weak encryption vulnerability in Mitel MiVoice Connect Client before 214.100.1214.0 could allow an unauthenticated attacker to gain accessmitel · mivoice connect client · CWE-327 | Kritik9,8 | — | %0,6 | 17 Nis 2020 |
- CVE-2023-3403959Planlayın
Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key generation.
KritikCVSS 9,8SilahlaştırılmışEPSS %67vmware · aria operations for networks29 Ağu 2023
- CVE-2016-660256Planlayın
ZOHO WebNMS Framework 5.2 and 5.2 SP1 use a weak obfuscation algorithm to store passwords, which allows context-dependent attackers to obtai
KritikCVSS 9,8SilahlaştırılmışEPSS %55zohocorp · webnms framework23 Oca 2017
- CVE-2014-868752Planlayın
Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root privileges by levera
KritikCVSS 9,8SilahlaştırılmışEPSS %44seagate · business nas firmware8 Haz 2017
- CVE-2007-601340Planlayın
Wordpress 1.5 through 2.3.1 uses cookie values based on the MD5 hash of a password MD5 hash, which allows attackers to bypass authentication
KritikCVSS 9,8İstismar yokEPSS %3wordpress · wordpress19 Kas 2007
- CVE-2019-823740Planlayın
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and ear
KritikCVSS 9,8İstismar yokEPSS %3adobe · acrobat dc23 Eki 2019
- CVE-2019-018740Planlayın
Unauthenticated RCE is possible when JMeter is used in distributed mode (-r or -R command line options).
KritikCVSS 9,8İstismar yokEPSS %3apache · jmeter6 Mar 2019
- CVE-2022-336540Planlayın
Emote Interactive Remote Mouse Server command injection due to weak encoding
KritikCVSS 9,8SilahlaştırılmışEPSS %2emote interactive · remote mouse server27 Oca 2025
- CVE-2017-1787839İzleyin
An issue was discovered in Valve Steam Link build 643.
KritikCVSS 9,8İstismar yokEPSS %2valvesoftware · steam link firmware27 Ara 2017
- CVE-2019-1302239İzleyin
Bond JetSelect (all versions) has an issue in the Java class (ENCtool.jar) and corresponding password generation algorithm (used to set init
KritikCVSS 9,8İstismar yokEPSS %1jetstream · jetselect14 May 2020
- CVE-2012-444939İzleyin
Apache Hadoop before 0.23.4, 1.x before 1.0.4, and 2.x before 2.0.2 generate token passwords using a 20-bit secret when Kerberos security fe
KritikCVSS 9,8İstismar yokEPSS %1apache · hadoop30 Eki 2017
- CVE-2017-985939İzleyin
An issue was discovered in SMA Solar Technology products.
KritikCVSS 9,8İstismar yokEPSS %1sma · sunny boy 3600 firmware5 Ağu 2017
- CVE-2019-572339İzleyin
An issue was discovered in portier vision 4.4.4.2 and 4.4.4.6.
KritikCVSS 9,8İstismar yokEPSS %1portier · portier21 Mar 2019
- CVE-2019-1614339İzleyin
An issue was discovered in the blake2 crate before 0.8.1 for Rust.
KritikCVSS 9,8İstismar yokEPSS %1blake2 · blake2-rust9 Eyl 2019
- CVE-2017-491739İzleyin
VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x locally stores vCenter Server credentials using reversible encryption.
KritikCVSS 9,8İstismar yokEPSS %1vmware · vsphere data protection7 Haz 2017
- CVE-2021-3629839İzleyin
Dell EMC InsightIQ, versions prior to 4.1.4, contain risky cryptographic algorithms in the SSH component.
KritikCVSS 9,8İstismar yokEPSS %1dell · isilon insightiq firmware1 Eki 2021
- CVE-2021-4569639İzleyin
An issue was discovered in the sha2 crate 0.9.7 before 0.9.8 for Rust.
KritikCVSS 9,8İstismar yokEPSS %1sha2 project · sha226 Ara 2021
- CVE-2020-368139İzleyin
Authenticated and encrypted payload MMEs can be forged and remotely sent to any HPAV2 system using a jailbreak key recoverable from code.
KritikCVSS 9,8İstismar yokEPSS %1qualcomm · -31 Tem 2020
- CVE-2022-2685439İzleyin
Dell PowerScale OneFS, versions 8.2.x-9.2.x, contain risky cryptographic algorithms.
KritikCVSS 9,8İstismar yokEPSS %1dell · emc powerscale onefs8 Nis 2022
- CVE-2019-909539İzleyin
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3,
KritikCVSS 9,8İstismar yokEPSS %1moxa · mb3170 firmware11 Mar 2020
- CVE-2017-1771739İzleyin
Sonatype Nexus Repository Manager through 2.14.5 has weak password encryption with a hardcoded CMMDwoV value in the LDAP integration feature
KritikCVSS 9,8İstismar yokEPSS %1sonatype · nexus repository manager17 Ara 2017
- CVE-2020-3636339İzleyin
Amazon AWS CloudFront TLSv1.2_2019 allows TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 and TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384, which some entiti
KritikCVSS 9,8İstismar yokEPSS %1amazon · amazon cloudfront12 Ağu 2021
- CVE-2022-3123039İzleyin
Dell PowerScale OneFS, versions 8.2.x-9.2.x, contain broken or risky cryptographic algorithm.
KritikCVSS 9,8İstismar yokEPSS %1dell · powerscale onefs28 Haz 2022
- CVE-2021-2273839İzleyin
Use of a Broken or Risky Cryptographic Algorithm vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior that could c
KritikCVSS 9,8İstismar yokEPSS %1schneider-electric · spacelynk firmware26 May 2021
- CVE-2024-3151039İzleyin
An issue in Open Quantum Safe liboqs v.10.0 allows a remote attacker to escalate privileges via the crypto_sign_signature parameter in the /
KritikCVSS 9,8İstismar yokEPSS %1openquantumsafe · liboqs24 May 2024
- CVE-2020-1037739İzleyin
A weak encryption vulnerability in Mitel MiVoice Connect Client before 214.100.1214.0 could allow an unauthenticated attacker to gain access
KritikCVSS 9,8İstismar yokEPSS %1mitel · mivoice connect client17 Nis 2020