CWE-326

Inadequate Encryption Strength

Parent: CWE-693 - Protection Mechanism Failure

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

457 vulnerabilities with CWE-326
CVE-2020-27208 MEDIUM
SoloKeys Solo 4.0.0 & Somu/Nitrokey FIDO2 - Info Disclosure
CVSS 6.8
CVE-2020-18220 HIGH
DoraCMS < 2.1.1 - Inadequate Encryption Strength for User Passwords
CVSS 7.5
CVE-2020-27020 HIGH
Kaspersky Password Manager - Info Disclosure
CVSS 7.5
CVE-2020-26197 HIGH
Dell PowerScale OneFS 8.1.0-9.1.0 - Cleartext Transmission of Sensitive Information via LDAP Provider
CVSS 7.5
CVE-2020-35221 HIGH
NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 - Inadequate Encryption Strength in NSDP Password Authentication
CVSS 8.8
CVE-2020-10554 HIGH
Psyprax < 3.2.2 - Insufficiently Protected Credentials via Obfuscated Password Storage
CVSS 7.5
CVE-2020-10375 MEDIUM
New Media Smarty < 9.10 - Inadequate Encryption Strength in Password Storage
CVSS 5.5
CVE-2020-25685 LOW
dnsmasq < 2.83 - DNS Cache Poisoning via Weak Query Name Hash
CVSS 3.7
CVE-2020-26263 HIGH
tlslite-ng <0.7.6, 0.8.0-alpha39 - Info Disclosure
CVSS 7.5
CVE-2020-7565 HIGH
Modicon M221 Firmware - Inadequate Encryption Strength
CVSS 7.3
CVE-2020-17494 MEDIUM
Untangle Firewall NG <16.0 - Info Disclosure
CVSS 5.3
CVE-2020-8761 MEDIUM
Intel(R) CSME <13.0.40,13.30.10 - Info Disclosure
CVSS 4.6
CVE-2020-9128 MEDIUM
FusionCompute 8.0.0 - Inadequate Encryption Strength
CVSS 4.4
CVE-2020-5938 MEDIUM
BIG-IP <13.1.3.4, <12.1.5.2, <11.6.5.2 - Info Disclosure
CVSS 6.5
CVE-2020-3549 HIGH
Cisco Firepower Management Center and Firepower Threat Defense < 6.6.1 - Unauthenticated MitM via sftunnel
CVSS 8.1
CVE-2020-7069 MEDIUM
PHP 7.2.0-7.2.33, 7.3.0-7.3.22, 7.4.0-7.4.10 - Inadequate Encryption Strength in AES-CCM Mode
CVSS 5.4
CVE-2020-14517 CRITICAL
CodeMeter < 6.90 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 9.8
CVE-2020-5917 MEDIUM
F5 BIG-IP 11.6.1-15.1.0.4 & BIG-IQ 5.2.0-7.0.0 - Weak OpenSSH Host Key Encryption
CVSS 5.9
CVE-2020-10125 HIGH
NCR APTRA XFS 04.02.01 and 05.01.00 - Inadequate Encryption Strength in BNA Software Update Validation
CVSS 7.6
CVE-2020-5763 HIGH
Grandstream HT800 Series Firmware < 1.0.17.5 - Authenticated Backdoor Root Shell via SSH Challenge
CVSS 8.8
CVE-2020-10919 MEDIUM
C-MORE HMI EA9 Firmware <6.52 - Info Disclosure
CVSS 5.9
CVE-2020-1982 MEDIUM
PAN-OS 8.0-8.0.19 - Inadequate Encryption Strength via TLS 1.0
CVSS 4.8
CVE-2020-10275 CRITICAL
Default Credentials - Info Disclosure
CVSS 9.8
CVE-2020-0533 MEDIUM
Intel CSME Firmware < 11.8.77 - Inadequate Encryption Strength via Reversible One-Way Hash
CVSS 6.7
CVE-2020-3929 MEDIUM
GeoVision Door Access Control - Info Disclosure
CVSS 5.9
Details
Vulnerabilities 457