CWE-329 · 11 kayıt
Generation of Predictable IV with CBC Mode
Bu sınıftaki CVE’ler
11 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
30İzleyin | CVE-2022-46397İstismar yok | FP.io VPP (Vector Packet Processor) 22.10, 22.06, 22.02, 21.10, 21.06, 21.01, 20.09, 20.05, 20.01, 19.08, and 19.04 Generates a Predictable lfprojects · vector packet processor · CWE-329 | Yüksek7,5 | — | %0,6 | 28 Mar 2023 |
30İzleyin | CVE-2025-59322İstismar yok | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly handle decryption errors and allows encrypted volumes to be mountedCWE-329 | Yüksek7,5 | — | %0,5 | 12 Ağu 2026 |
26İzleyin | CVE-2020-5408İstismar yok | Dictionary attack with Spring Security queryable text encryptorpivotal software · spring security · CWE-329 | Orta6,5 | — | %1,6 | 14 May 2020 |
26İzleyin | CVE-2024-49783İstismar yok | IBM OpenPages with Watson information disclosureibm · openpages with watson · CWE-329 | Orta6,5 | — | %0,3 | 8 Tem 2025 |
25İzleyin | CVE-2017-3226İstismar yok | Das U-Boot's AES-CBC encryption feature improperly handles an error condition and may allow attacks against the underlying cryptographic implementation and allodenx · u-boot · CWE-329 | Orta6,4 | — | %0,3 | 24 Tem 2018 |
23İzleyin | CVE-2021-27499İstismar yok | Ypsomed mylife Cloud, mylife Mobile Application, Ypsomed mylife Cloud: All versions prior to 1.7.2, Ypsomed mylife App: All versions prior typsomed · mylife · CWE-329 | Orta5,9 | — | %0,5 | 2 Ağu 2021 |
20İzleyin | CVE-2024-56141İstismar yok | Minosoft has IV equal to keybixilon · minosoft · CWE-329 | Orta5,0 | — | %0,2 | 6 Tem 2026 |
18İzleyin | CVE-2017-3225İstismar yok | Das U-Boot's AES-CBC encryption feature uses a zero (0) initialization vector that may allow attacks against the underlying cryptographic implementation and alldenx · u-boot · CWE-329 | Orta4,6 | — | %0,3 | 24 Tem 2018 |
17İzleyin | CVE-2026-14969İstismar yok | 389-ds-base: 389-ds-base: static initialization vector in aes-cbc/3des-cbc attribute encryptionredhat · directory server · CWE-329 | Orta4,4 | — | %0,1 | 7 Tem 2026 |
16İzleyin | CVE-2025-2814İstismar yok | Crypt::CBC versions between 1.21 and 3.05 for Perl may use insecure rand() function for cryptographic functionslds · crypt::cbc · CWE-329 | Orta4,0 | — | %0,2 | 12 Nis 2025 |
13İzleyin | CVE-2022-29054İstismar yok | A missing cryptographic steps vulnerability [CWE-325] in the functions that encrypt the DHCP and DNS keys in Fortinet FortiOS version 7.2.0,fortinet · fortiproxy · CWE-329 | Düşük3,3 | — | %0,2 | 16 Şub 2023 |
- CVE-2022-4639730İzleyin
FP.io VPP (Vector Packet Processor) 22.10, 22.06, 22.02, 21.10, 21.06, 21.01, 20.09, 20.05, 20.01, 19.08, and 19.04 Generates a Predictable
YüksekCVSS 7,5İstismar yokEPSS %1lfprojects · vector packet processor28 Mar 2023
- CVE-2025-5932230İzleyin
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly handle decryption errors and allows encrypted volumes to be mounted
YüksekCVSS 7,5İstismar yokEPSS %012 Ağu 2026
- CVE-2020-540826İzleyin
Dictionary attack with Spring Security queryable text encryptor
OrtaCVSS 6,5İstismar yokEPSS %2pivotal software · spring security14 May 2020
- CVE-2024-4978326İzleyin
IBM OpenPages with Watson information disclosure
OrtaCVSS 6,5İstismar yokEPSS %0ibm · openpages with watson8 Tem 2025
- CVE-2017-322625İzleyin
Das U-Boot's AES-CBC encryption feature improperly handles an error condition and may allow attacks against the underlying cryptographic implementation and allo
OrtaCVSS 6,4İstismar yokEPSS %0denx · u-boot24 Tem 2018
- CVE-2021-2749923İzleyin
Ypsomed mylife Cloud, mylife Mobile Application, Ypsomed mylife Cloud: All versions prior to 1.7.2, Ypsomed mylife App: All versions prior t
OrtaCVSS 5,9İstismar yokEPSS %0ypsomed · mylife2 Ağu 2021
- CVE-2024-5614120İzleyin
Minosoft has IV equal to key
OrtaCVSS 5,0İstismar yokEPSS %0bixilon · minosoft6 Tem 2026
- CVE-2017-322518İzleyin
Das U-Boot's AES-CBC encryption feature uses a zero (0) initialization vector that may allow attacks against the underlying cryptographic implementation and all
OrtaCVSS 4,6İstismar yokEPSS %0denx · u-boot24 Tem 2018
- CVE-2026-1496917İzleyin
389-ds-base: 389-ds-base: static initialization vector in aes-cbc/3des-cbc attribute encryption
OrtaCVSS 4,4İstismar yokEPSS %0redhat · directory server7 Tem 2026
- CVE-2025-281416İzleyin
Crypt::CBC versions between 1.21 and 3.05 for Perl may use insecure rand() function for cryptographic functions
OrtaCVSS 4,0İstismar yokEPSS %0lds · crypt::cbc12 Nis 2025
- CVE-2022-2905413İzleyin
A missing cryptographic steps vulnerability [CWE-325] in the functions that encrypt the DHCP and DNS keys in Fortinet FortiOS version 7.2.0,
DüşükCVSS 3,3İstismar yokEPSS %0fortinet · fortiproxy16 Şub 2023