CWE-332 · 10 kayıt
Insufficient Entropy in PRNG
Bu sınıftaki CVE’ler
10 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2018-9057İstismar yok | aws/resource_aws_iam_user_login_profile.go in the HashiCorp Terraform Amazon Web Services (AWS) provider through v1.12.0 has an inappropriathashicorp · terraform · CWE-332 | Kritik9,8 | — | %1,9 | 27 Mar 2018 |
31İzleyin | CVE-2016-10743İstismar yok | hostapd before 2.6 does not prevent use of the low-quality PRNG that is reached by an os_random() function call.w1.fi · hostapd · CWE-332 | Yüksek7,5 | — | %2,4 | 23 Mar 2019 |
31İzleyin | CVE-2019-1715İstismar yok | Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Low-Entropy Keys Vulnerabilitycisco · adaptive security appliance device manager · CWE-332 | Yüksek7,5 | — | %1,7 | 3 May 2019 |
30İzleyin | CVE-2016-9154İstismar yok | Siemens Desigo PX Web modules PXA40-W0, PXA40-W1, PXA40-W2 for Desigo PX automation controllers PXC00-E.D, PXC50-E.D, PXC100-E.D, PXC200-E.Dsiemens · desigo web module pxa30-w0 firmware · CWE-332 | Yüksek7,5 | — | %1,5 | 23 Ara 2016 |
30İzleyin | CVE-2014-9690İstismar yok | Huawei home gateways WS318 with software V100R001C01B022 and earlier versions are affected by the PIN offline brute force cracking vulnerabihuawei · ws318 firmware · CWE-332 | Yüksek7,5 | — | %0,8 | 2 Nis 2017 |
30İzleyin | CVE-2023-20107İstismar yok | Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Low-Entropy Keys Vulnerabilitycisco · adaptive security appliance · CWE-332 | Yüksek7,5 | — | %0,7 | 23 Mar 2023 |
29İzleyin | CVE-2017-18486Kavram kanıtı | Jitbit Helpdesk before 9.0.3 allows remote attackers to escalate privileges because of mishandling of the User/AutoLogin userHash parameter.jitbit · helpdesk · CWE-332 | Yüksek7,2 | — | %4,8 | 9 Ağu 2019 |
29İzleyin | CVE-2026-3290İstismar yok | Timing limitations of the HRNG in RS9116 when power save mode is enabled results in predictable valuessilicon labs · rs9116 sdk · CWE-332 | Yüksek7,4 | — | %0,3 | 14 May 2026 |
18İzleyin | CVE-2014-0016İstismar yok | stunnel before 5.00, when using fork threading, does not properly update the state of the OpenSSL pseudo-random number generator (PRNG), whistunnel · stunnel · CWE-332 | Orta4,3 | — | %2,2 | 24 Mar 2014 |
10İzleyin | CVE-2017-9371İstismar yok | In BlackBerry QNX Software Development Platform (SDP) 6.6.0 and 6.5.0 SP1 and earlier, a loss of integrity vulnerability in the default confblackberry · qnx software development platform · CWE-332 | Düşük2,6 | — | %0,8 | 14 Kas 2017 |
- CVE-2018-905740Planlayın
aws/resource_aws_iam_user_login_profile.go in the HashiCorp Terraform Amazon Web Services (AWS) provider through v1.12.0 has an inappropriat
KritikCVSS 9,8İstismar yokEPSS %2hashicorp · terraform27 Mar 2018
- CVE-2016-1074331İzleyin
hostapd before 2.6 does not prevent use of the low-quality PRNG that is reached by an os_random() function call.
YüksekCVSS 7,5İstismar yokEPSS %2w1.fi · hostapd23 Mar 2019
- CVE-2019-171531İzleyin
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Low-Entropy Keys Vulnerability
YüksekCVSS 7,5İstismar yokEPSS %2cisco · adaptive security appliance device manager3 May 2019
- CVE-2016-915430İzleyin
Siemens Desigo PX Web modules PXA40-W0, PXA40-W1, PXA40-W2 for Desigo PX automation controllers PXC00-E.D, PXC50-E.D, PXC100-E.D, PXC200-E.D
YüksekCVSS 7,5İstismar yokEPSS %1siemens · desigo web module pxa30-w0 firmware23 Ara 2016
- CVE-2014-969030İzleyin
Huawei home gateways WS318 with software V100R001C01B022 and earlier versions are affected by the PIN offline brute force cracking vulnerabi
YüksekCVSS 7,5İstismar yokEPSS %1huawei · ws318 firmware2 Nis 2017
- CVE-2023-2010730İzleyin
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Low-Entropy Keys Vulnerability
YüksekCVSS 7,5İstismar yokEPSS %1cisco · adaptive security appliance23 Mar 2023
- CVE-2017-1848629İzleyin
Jitbit Helpdesk before 9.0.3 allows remote attackers to escalate privileges because of mishandling of the User/AutoLogin userHash parameter.
YüksekCVSS 7,2Kavram kanıtıEPSS %5jitbit · helpdesk9 Ağu 2019
- CVE-2026-329029İzleyin
Timing limitations of the HRNG in RS9116 when power save mode is enabled results in predictable values
YüksekCVSS 7,4İstismar yokEPSS %0silicon labs · rs9116 sdk14 May 2026
- CVE-2014-001618İzleyin
stunnel before 5.00, when using fork threading, does not properly update the state of the OpenSSL pseudo-random number generator (PRNG), whi
OrtaCVSS 4,3İstismar yokEPSS %2stunnel · stunnel24 Mar 2014
- CVE-2017-937110İzleyin
In BlackBerry QNX Software Development Platform (SDP) 6.6.0 and 6.5.0 SP1 and earlier, a loss of integrity vulnerability in the default conf
DüşükCVSS 2,6İstismar yokEPSS %1blackberry · qnx software development platform14 Kas 2017