The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
457 vulnerabilities with CWE-326
CVE-2020-27208
MEDIUM
SoloKeys Solo 4.0.0 & Somu/Nitrokey FIDO2 - Info Disclosure
CVSS 6.8
CVE-2020-18220
HIGH
DoraCMS < 2.1.1 - Inadequate Encryption Strength for User Passwords
CVSS 7.5
CVE-2020-27020
HIGH
Kaspersky Password Manager - Info Disclosure
CVSS 7.5
CVE-2020-26197
HIGH
Dell PowerScale OneFS 8.1.0-9.1.0 - Cleartext Transmission of Sensitive Information via LDAP Provider
CVSS 7.5
CVE-2020-35221
HIGH
NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 - Inadequate Encryption Strength in NSDP Password Authentication
CVSS 8.8
CVE-2020-10554
HIGH
Psyprax < 3.2.2 - Insufficiently Protected Credentials via Obfuscated Password Storage
CVSS 7.5
CVE-2020-10375
MEDIUM
New Media Smarty < 9.10 - Inadequate Encryption Strength in Password Storage
CVSS 5.5
CVE-2020-25685
LOW
dnsmasq < 2.83 - DNS Cache Poisoning via Weak Query Name Hash
CVSS 3.7
CVE-2020-26263
HIGH
tlslite-ng <0.7.6, 0.8.0-alpha39 - Info Disclosure
CVSS 7.5
CVE-2020-7565
HIGH
Modicon M221 Firmware - Inadequate Encryption Strength
CVSS 7.3
CVE-2020-17494
MEDIUM
Untangle Firewall NG <16.0 - Info Disclosure
CVSS 5.3
CVE-2020-8761
MEDIUM
Intel(R) CSME <13.0.40,13.30.10 - Info Disclosure
CVSS 4.6
CVE-2020-9128
MEDIUM
FusionCompute 8.0.0 - Inadequate Encryption Strength
CVSS 4.4
CVE-2020-5938
MEDIUM
BIG-IP <13.1.3.4, <12.1.5.2, <11.6.5.2 - Info Disclosure
CVSS 6.5
CVE-2020-3549
HIGH
Cisco Firepower Management Center and Firepower Threat Defense < 6.6.1 - Unauthenticated MitM via sftunnel
CVSS 8.1
CVE-2020-7069
MEDIUM
PHP 7.2.0-7.2.33, 7.3.0-7.3.22, 7.4.0-7.4.10 - Inadequate Encryption Strength in AES-CCM Mode
CVSS 5.4
CVE-2020-14517
CRITICAL
CodeMeter < 6.90 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 9.8
CVE-2020-5917
MEDIUM
F5 BIG-IP 11.6.1-15.1.0.4 & BIG-IQ 5.2.0-7.0.0 - Weak OpenSSH Host Key Encryption
CVSS 5.9
CVE-2020-10125
HIGH
NCR APTRA XFS 04.02.01 and 05.01.00 - Inadequate Encryption Strength in BNA Software Update Validation
CVSS 7.6
CVE-2020-5763
HIGH
Grandstream HT800 Series Firmware < 1.0.17.5 - Authenticated Backdoor Root Shell via SSH Challenge
CVSS 8.8
CVE-2020-10919
MEDIUM
C-MORE HMI EA9 Firmware <6.52 - Info Disclosure
CVSS 5.9
CVE-2020-1982
MEDIUM
PAN-OS 8.0-8.0.19 - Inadequate Encryption Strength via TLS 1.0
CVSS 4.8
CVE-2020-10275
CRITICAL
Default Credentials - Info Disclosure
CVSS 9.8
CVE-2020-0533
MEDIUM
Intel CSME Firmware < 11.8.77 - Inadequate Encryption Strength via Reversible One-Way Hash
CVSS 6.7
CVE-2020-3929
MEDIUM
GeoVision Door Access Control - Info Disclosure
CVSS 5.9
Details
Vulnerabilities
457