İçeriğe atla
Noroxi

CWE-757 · 30 kayıt

Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')

Bu sınıftaki CVE’ler

30 kayıt

  • CVE-2017-9269
    40Planlayın

    lack of keypinning in libzypp could lead to repository switching

    KritikCVSS 9,8İstismar yokEPSS %2

    opensuse · libzypp1 Mar 2018

  • CVE-2026-72887
    39İzleyin

    Net::OAuth::Client versions before 0.32 for Perl allow the service provider to silently downgrade OAuth 1.0a to OAuth 1.0 in get_request_token

    KritikCVSS 9,8İstismar yokEPSS %1

    16 Ağu 2026

  • CVE-2019-14887
    36İzleyin

    A flaw was found when an OpenSSL security provider is used with Wildfly, the 'enabled-protocols' value in the Wildfly configuration isn't ho

    KritikCVSS 9,1İstismar yokEPSS %1

    redhat · jboss data grid16 Mar 2020

  • CVE-2024-4995
    36İzleyin

    Protocol Downgrade in Wapro ERP Desktop

    KritikCVSS 9,1İstismar yokEPSS %1

    asseco business solutions s.a. · wapro erp desktop18 Ara 2024

  • CVE-2026-55953
    36İzleyin

    TLS 1.2 and DTLS client accepts unoffered anonymous cipher suite, bypassing server authentication

    KritikCVSS 9,1İstismar yokEPSS %0

    erlang · erlang\/otp27 Tem 2026

  • CVE-2026-18691
    36İzleyin

    Improper Authentication in MongoDB Intra-Cluster Connections Allows Credential Exposure

    KritikCVSS 9,0İstismar yokEPSS %0

    mongodb · mongodb11 Ağu 2026

  • CVE-2024-38883
    36İzleyin

    An issue in Horizon Business Services Inc.

    KritikCVSS 9,1İstismar yokEPSS %0

    horizoncloud · caterease2 Ağu 2024

  • CVE-2026-89177
    34İzleyin

    Howyar|WeenyGenius - Use of Insecure Protocol

    YüksekCVSS 8,7İstismar yokEPSS %0

    howyar · weenygenius11 Eyl 2026

  • CVE-2024-8773
    33İzleyin

    Protocol Downgrade in SIMPLE.ERP

    YüksekCVSS 8,3İstismar yokEPSS %0

    simple sa · simple.erp24 Mar 2025

  • CVE-2023-2974
    32İzleyin

    Quarkus-core: tls protocol configured with quarkus.http.ssl.protocols is not enforced, client can enforce weaker supported tls protocol

    YüksekCVSS 8,1İstismar yokEPSS %1

    redhat · build of quarkus4 Tem 2023

  • CVE-2018-25029
    32İzleyin

    The Z-Wave specification requires that S2 security can be downgraded to S0 or other less secure protocols, allowing an attacker within radio

    YüksekCVSS 8,1İstismar yokEPSS %1

    silabs · zgm130s037hgn firmware4 Şub 2022

  • CVE-2022-23000
    31İzleyin

    Weak Default SSL use in Port Forwarding Service

    YüksekCVSS 7,8İstismar yokEPSS %0

    westerndigital · my cloud pr2100 firmware25 Tem 2022

  • CVE-2017-9267
    30İzleyin

    eDirectory LDAP peer certificate validation issue

    YüksekCVSS 7,5İstismar yokEPSS %1

    novell · edirectory2 Mar 2018

  • CVE-2026-4942
    30İzleyin

    IBM i is Affected by Algorithm Downgrade in Transport Layer Security []

    YüksekCVSS 7,5İstismar yokEPSS %0

    ibm · i17 Tem 2026

  • CVE-2026-32650
    30İzleyin

    Anviz CrossChex Standard Algorithm Downgrade

    YüksekCVSS 7,5İstismar yokEPSS %0

    anviz · crosschex standard17 Nis 2026

  • CVE-2025-10693
    30İzleyin

    Silicon Labs Z-Wave PIR Sensor Joins Network as Non-Secure

    YüksekCVSS 7,6İstismar yokEPSS %0

    silabs.com · silicon labs z-wave sdk31 Eki 2025

  • CVE-2022-33160
    30İzleyin

    IBM Security Directory Suite information disclosure

    YüksekCVSS 7,5İstismar yokEPSS %0

    ibm · security directory suite va6 Eki 2023

  • CVE-2023-7005
    30İzleyin

    A specially crafted message can be sent to the TTLock App that downgrades the encryption protocol used for communication, and can be utilize

    YüksekCVSS 7,5İstismar yokEPSS %0

    sciener · ttlock app19 Ara 2024

  • CVE-2025-36582
    30İzleyin

    Dell NetWorker, versions 19.12.0.1 and prior, contains a Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade') vulne

    YüksekCVSS 7,5İstismar yokEPSS %0

    dell · networker1 Tem 2025

  • CVE-2021-36326
    26İzleyin

    Dell EMC Streaming Data Platform, versions prior to 1.3 contain an SSL Strip Vulnerability in the User Interface (UI).

    OrtaCVSS 6,5İstismar yokEPSS %1

    dell · emc streaming data platform30 Kas 2021

  • CVE-2020-16200
    26İzleyin

    Philips Clinical Collaboration Platform Algorithm Downgrade

    OrtaCVSS 6,5İstismar yokEPSS %1

    philips · clinical collaboration platform18 Eyl 2020

  • CVE-2024-20069
    26İzleyin

    In modem, there is a possible selection of less-secure algorithm during the VoWiFi IKE due to a missing DH downgrade check.

    OrtaCVSS 6,5İstismar yokEPSS %1

    mediatek · nr152 Haz 2024

  • CVE-2026-2673
    26İzleyin

    OpenSSL TLS 1.3 server may choose unexpected key agreement group

    OrtaCVSS 6,5İstismar yokEPSS %0

    openssl · openssl13 Mar 2026

  • CVE-2026-59293
    26İzleyin

    SMB minimum protocol dialect defaults to SMB1

    OrtaCVSS 6,6İstismar yokEPSS %0

    vmware · spring integration27 Ağu 2026

  • CVE-2019-16791
    23İzleyin

    downgrade of effective Strict Transport Security (STS) policy in postfix-mta-sts-resolver

    OrtaCVSS 5,9İstismar yokEPSS %1

    postfix-mta-sts-resolver project · postfix-mta-sts-resolver21 Oca 2020

Tüm zafiyet sınıfları