CWE-326

Inadequate Encryption Strength

Parent: CWE-693 - Protection Mechanism Failure

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

448 vulnerabilities with CWE-326
CVE-2020-7565 HIGH
Modicon M221 Firmware - Inadequate Encryption Strength
CVSS 7.3
CVE-2020-17494 MEDIUM
Untangle Firewall NG <16.0 - Info Disclosure
CVSS 5.3
CVE-2020-8761 MEDIUM
Intel(R) CSME <13.0.40,13.30.10 - Info Disclosure
CVSS 4.6
CVE-2020-9128 MEDIUM
FusionCompute 8.0.0 - Inadequate Encryption Strength
CVSS 4.4
CVE-2020-5938 MEDIUM
BIG-IP <13.1.3.4, <12.1.5.2, <11.6.5.2 - Info Disclosure
CVSS 6.5
CVE-2020-3549 HIGH
Cisco Firepower Management Center and Firepower Threat Defense < 6.6.1 - Unauthenticated MitM via sftunnel
CVSS 8.1
CVE-2020-7069 MEDIUM
PHP 7.2.0-7.2.33, 7.3.0-7.3.22, 7.4.0-7.4.10 - Inadequate Encryption Strength in AES-CCM Mode
CVSS 5.4
CVE-2020-14517 CRITICAL
CodeMeter < 6.90 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 9.8
CVE-2020-5917 MEDIUM
F5 BIG-IP 11.6.1-15.1.0.4 & BIG-IQ 5.2.0-7.0.0 - Weak OpenSSH Host Key Encryption
CVSS 5.9
CVE-2020-10125 HIGH
NCR APTRA XFS 04.02.01 and 05.01.00 - Inadequate Encryption Strength in BNA Software Update Validation
CVSS 7.6
CVE-2020-5763 HIGH
Grandstream HT800 Series Firmware < 1.0.17.5 - Authenticated Backdoor Root Shell via SSH Challenge
CVSS 8.8
CVE-2020-10919 MEDIUM
C-MORE HMI EA9 Firmware <6.52 - Info Disclosure
CVSS 5.9
CVE-2020-1982 MEDIUM
PAN-OS 8.0-8.0.19 - Inadequate Encryption Strength via TLS 1.0
CVSS 4.8
CVE-2020-10275 CRITICAL
Default Credentials - Info Disclosure
CVSS 9.8
CVE-2020-0533 MEDIUM
Intel CSME Firmware < 11.8.77 - Inadequate Encryption Strength via Reversible One-Way Hash
CVSS 6.7
CVE-2020-3929 MEDIUM
GeoVision Door Access Control - Info Disclosure
CVSS 5.9
CVE-2020-12714 MEDIUM
CipherMail <4.7.1-0 - Man-in-the-Middle
CVSS 5.9
CVE-2020-13785 HIGH
D-Link DIR-865L Ax 1.20B01 Beta - Inadequate Encryption Strength
CVSS 7.5
CVE-2020-12872 MEDIUM
Yaws <2.0.2-2.0.7 - Buffer Overflow
CVSS 5.5
CVE-2020-5886 CRITICAL
F5 BIG-IP 12.1.0-15.1.0.1 Cleartext Transmission of Sensitive Cryptographic Objects via Connection Mirroring
CVSS 9.1
CVE-2020-5885 CRITICAL
F5 BIG-IP 12.1.0-15.1.0.1 Cleartext Transmission of Sensitive Cryptographic Objects
CVSS 9.1
CVE-2020-10601 HIGH
VISAM VBASE Editor <11.5.0.2 - Privilege Escalation
CVSS 7.8
CVE-2020-10866 HIGH
Avast Antivirus <20 - Info Disclosure
CVSS 7.5
CVE-2020-10244 HIGH
jpaseto < 0.3.0 - Inadequate Encryption Strength in v2.local Token Hashing
CVSS 7.5
CVE-2020-9476 HIGH
ARRIS TG1692A Firmware - Inadequate Encryption Strength via Base64 Decoding
CVSS 7.5
Details
Vulnerabilities 448