CWE-757 · 30 kayıt
Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')
Bu sınıftaki CVE’ler
30 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2017-9269İstismar yok | lack of keypinning in libzypp could lead to repository switchingopensuse · libzypp · CWE-757 | Kritik9,8 | — | %2,2 | 1 Mar 2018 |
39İzleyin | CVE-2026-72887İstismar yok | Net::OAuth::Client versions before 0.32 for Perl allow the service provider to silently downgrade OAuth 1.0a to OAuth 1.0 in get_request_tokenCWE-757 | Kritik9,8 | — | %0,7 | 16 Ağu 2026 |
36İzleyin | CVE-2019-14887İstismar yok | A flaw was found when an OpenSSL security provider is used with Wildfly, the 'enabled-protocols' value in the Wildfly configuration isn't horedhat · jboss data grid · CWE-757 | Kritik9,1 | — | %1,1 | 16 Mar 2020 |
36İzleyin | CVE-2024-4995İstismar yok | Protocol Downgrade in Wapro ERP Desktopasseco business solutions s.a. · wapro erp desktop · CWE-757 | Kritik9,1 | — | %0,9 | 18 Ara 2024 |
36İzleyin | CVE-2026-55953İstismar yok | TLS 1.2 and DTLS client accepts unoffered anonymous cipher suite, bypassing server authenticationerlang · erlang\/otp · CWE-757 | Kritik9,1 | — | %0,4 | 27 Tem 2026 |
36İzleyin | CVE-2026-18691İstismar yok | Improper Authentication in MongoDB Intra-Cluster Connections Allows Credential Exposuremongodb · mongodb · CWE-757 | Kritik9,0 | — | %0,4 | 11 Ağu 2026 |
36İzleyin | CVE-2024-38883İstismar yok | An issue in Horizon Business Services Inc.horizoncloud · caterease · CWE-757 | Kritik9,1 | — | %0,4 | 2 Ağu 2024 |
34İzleyin | CVE-2026-89177İstismar yok | Howyar|WeenyGenius - Use of Insecure Protocolhowyar · weenygenius · CWE-757 | Yüksek8,7 | — | %0,4 | 11 Eyl 2026 |
33İzleyin | CVE-2024-8773İstismar yok | Protocol Downgrade in SIMPLE.ERPsimple sa · simple.erp · CWE-757 | Yüksek8,3 | — | %0,4 | 24 Mar 2025 |
32İzleyin | CVE-2023-2974İstismar yok | Quarkus-core: tls protocol configured with quarkus.http.ssl.protocols is not enforced, client can enforce weaker supported tls protocolredhat · build of quarkus · CWE-757 | Yüksek8,1 | — | %0,9 | 4 Tem 2023 |
32İzleyin | CVE-2018-25029İstismar yok | The Z-Wave specification requires that S2 security can be downgraded to S0 or other less secure protocols, allowing an attacker within radiosilabs · zgm130s037hgn firmware · CWE-757 | Yüksek8,1 | — | %0,6 | 4 Şub 2022 |
31İzleyin | CVE-2022-23000İstismar yok | Weak Default SSL use in Port Forwarding Servicewesterndigital · my cloud pr2100 firmware · CWE-757 | Yüksek7,8 | — | %0,2 | 25 Tem 2022 |
30İzleyin | CVE-2017-9267İstismar yok | eDirectory LDAP peer certificate validation issuenovell · edirectory · CWE-757 | Yüksek7,5 | — | %1,0 | 2 Mar 2018 |
30İzleyin | CVE-2026-4942İstismar yok | IBM i is Affected by Algorithm Downgrade in Transport Layer Security []ibm · i · CWE-757 | Yüksek7,5 | — | %0,4 | 17 Tem 2026 |
30İzleyin | CVE-2026-32650İstismar yok | Anviz CrossChex Standard Algorithm Downgradeanviz · crosschex standard · CWE-757 | Yüksek7,5 | — | %0,3 | 17 Nis 2026 |
30İzleyin | CVE-2025-10693İstismar yok | Silicon Labs Z-Wave PIR Sensor Joins Network as Non-Securesilabs.com · silicon labs z-wave sdk · CWE-757 | Yüksek7,6 | — | %0,3 | 31 Eki 2025 |
30İzleyin | CVE-2022-33160İstismar yok | IBM Security Directory Suite information disclosureibm · security directory suite va · CWE-757 | Yüksek7,5 | — | %0,3 | 6 Eki 2023 |
30İzleyin | CVE-2023-7005İstismar yok | A specially crafted message can be sent to the TTLock App that downgrades the encryption protocol used for communication, and can be utilizesciener · ttlock app · CWE-757 | Yüksek7,5 | — | %0,3 | 19 Ara 2024 |
30İzleyin | CVE-2025-36582İstismar yok | Dell NetWorker, versions 19.12.0.1 and prior, contains a Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade') vulnedell · networker · CWE-757 | Yüksek7,5 | — | %0,2 | 1 Tem 2025 |
26İzleyin | CVE-2021-36326İstismar yok | Dell EMC Streaming Data Platform, versions prior to 1.3 contain an SSL Strip Vulnerability in the User Interface (UI).dell · emc streaming data platform · CWE-757 | Orta6,5 | — | %1,2 | 30 Kas 2021 |
26İzleyin | CVE-2020-16200İstismar yok | Philips Clinical Collaboration Platform Algorithm Downgradephilips · clinical collaboration platform · CWE-757 | Orta6,5 | — | %0,6 | 18 Eyl 2020 |
26İzleyin | CVE-2024-20069İstismar yok | In modem, there is a possible selection of less-secure algorithm during the VoWiFi IKE due to a missing DH downgrade check.mediatek · nr15 · CWE-757 | Orta6,5 | — | %0,6 | 2 Haz 2024 |
26İzleyin | CVE-2026-2673İstismar yok | OpenSSL TLS 1.3 server may choose unexpected key agreement groupopenssl · openssl · CWE-757 | Orta6,5 | — | %0,5 | 13 Mar 2026 |
26İzleyin | CVE-2026-59293İstismar yok | SMB minimum protocol dialect defaults to SMB1vmware · spring integration · CWE-757 | Orta6,6 | — | %0,2 | 27 Ağu 2026 |
23İzleyin | CVE-2019-16791İstismar yok | downgrade of effective Strict Transport Security (STS) policy in postfix-mta-sts-resolverpostfix-mta-sts-resolver project · postfix-mta-sts-resolver · CWE-757 | Orta5,9 | — | %0,8 | 21 Oca 2020 |
- CVE-2017-926940Planlayın
lack of keypinning in libzypp could lead to repository switching
KritikCVSS 9,8İstismar yokEPSS %2opensuse · libzypp1 Mar 2018
- CVE-2026-7288739İzleyin
Net::OAuth::Client versions before 0.32 for Perl allow the service provider to silently downgrade OAuth 1.0a to OAuth 1.0 in get_request_token
KritikCVSS 9,8İstismar yokEPSS %116 Ağu 2026
- CVE-2019-1488736İzleyin
A flaw was found when an OpenSSL security provider is used with Wildfly, the 'enabled-protocols' value in the Wildfly configuration isn't ho
KritikCVSS 9,1İstismar yokEPSS %1redhat · jboss data grid16 Mar 2020
- CVE-2024-499536İzleyin
Protocol Downgrade in Wapro ERP Desktop
KritikCVSS 9,1İstismar yokEPSS %1asseco business solutions s.a. · wapro erp desktop18 Ara 2024
- CVE-2026-5595336İzleyin
TLS 1.2 and DTLS client accepts unoffered anonymous cipher suite, bypassing server authentication
KritikCVSS 9,1İstismar yokEPSS %0erlang · erlang\/otp27 Tem 2026
- CVE-2026-1869136İzleyin
Improper Authentication in MongoDB Intra-Cluster Connections Allows Credential Exposure
KritikCVSS 9,0İstismar yokEPSS %0mongodb · mongodb11 Ağu 2026
- CVE-2024-3888336İzleyin
An issue in Horizon Business Services Inc.
KritikCVSS 9,1İstismar yokEPSS %0horizoncloud · caterease2 Ağu 2024
- CVE-2026-8917734İzleyin
Howyar|WeenyGenius - Use of Insecure Protocol
YüksekCVSS 8,7İstismar yokEPSS %0howyar · weenygenius11 Eyl 2026
- CVE-2024-877333İzleyin
Protocol Downgrade in SIMPLE.ERP
YüksekCVSS 8,3İstismar yokEPSS %0simple sa · simple.erp24 Mar 2025
- CVE-2023-297432İzleyin
Quarkus-core: tls protocol configured with quarkus.http.ssl.protocols is not enforced, client can enforce weaker supported tls protocol
YüksekCVSS 8,1İstismar yokEPSS %1redhat · build of quarkus4 Tem 2023
- CVE-2018-2502932İzleyin
The Z-Wave specification requires that S2 security can be downgraded to S0 or other less secure protocols, allowing an attacker within radio
YüksekCVSS 8,1İstismar yokEPSS %1silabs · zgm130s037hgn firmware4 Şub 2022
- CVE-2022-2300031İzleyin
Weak Default SSL use in Port Forwarding Service
YüksekCVSS 7,8İstismar yokEPSS %0westerndigital · my cloud pr2100 firmware25 Tem 2022
- CVE-2017-926730İzleyin
eDirectory LDAP peer certificate validation issue
YüksekCVSS 7,5İstismar yokEPSS %1novell · edirectory2 Mar 2018
- CVE-2026-494230İzleyin
IBM i is Affected by Algorithm Downgrade in Transport Layer Security []
YüksekCVSS 7,5İstismar yokEPSS %0ibm · i17 Tem 2026
- CVE-2026-3265030İzleyin
Anviz CrossChex Standard Algorithm Downgrade
YüksekCVSS 7,5İstismar yokEPSS %0anviz · crosschex standard17 Nis 2026
- CVE-2025-1069330İzleyin
Silicon Labs Z-Wave PIR Sensor Joins Network as Non-Secure
YüksekCVSS 7,6İstismar yokEPSS %0silabs.com · silicon labs z-wave sdk31 Eki 2025
- CVE-2022-3316030İzleyin
IBM Security Directory Suite information disclosure
YüksekCVSS 7,5İstismar yokEPSS %0ibm · security directory suite va6 Eki 2023
- CVE-2023-700530İzleyin
A specially crafted message can be sent to the TTLock App that downgrades the encryption protocol used for communication, and can be utilize
YüksekCVSS 7,5İstismar yokEPSS %0sciener · ttlock app19 Ara 2024
- CVE-2025-3658230İzleyin
Dell NetWorker, versions 19.12.0.1 and prior, contains a Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade') vulne
YüksekCVSS 7,5İstismar yokEPSS %0dell · networker1 Tem 2025
- CVE-2021-3632626İzleyin
Dell EMC Streaming Data Platform, versions prior to 1.3 contain an SSL Strip Vulnerability in the User Interface (UI).
OrtaCVSS 6,5İstismar yokEPSS %1dell · emc streaming data platform30 Kas 2021
- CVE-2020-1620026İzleyin
Philips Clinical Collaboration Platform Algorithm Downgrade
OrtaCVSS 6,5İstismar yokEPSS %1philips · clinical collaboration platform18 Eyl 2020
- CVE-2024-2006926İzleyin
In modem, there is a possible selection of less-secure algorithm during the VoWiFi IKE due to a missing DH downgrade check.
OrtaCVSS 6,5İstismar yokEPSS %1mediatek · nr152 Haz 2024
- CVE-2026-267326İzleyin
OpenSSL TLS 1.3 server may choose unexpected key agreement group
OrtaCVSS 6,5İstismar yokEPSS %0openssl · openssl13 Mar 2026
- CVE-2026-5929326İzleyin
SMB minimum protocol dialect defaults to SMB1
OrtaCVSS 6,6İstismar yokEPSS %0vmware · spring integration27 Ağu 2026
- CVE-2019-1679123İzleyin
downgrade of effective Strict Transport Security (STS) policy in postfix-mta-sts-resolver
OrtaCVSS 5,9İstismar yokEPSS %1postfix-mta-sts-resolver project · postfix-mta-sts-resolver21 Oca 2020