The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
448 vulnerabilities with CWE-326
CVE-2020-7565
HIGH
Modicon M221 Firmware - Inadequate Encryption Strength
CVSS 7.3
CVE-2020-17494
MEDIUM
Untangle Firewall NG <16.0 - Info Disclosure
CVSS 5.3
CVE-2020-8761
MEDIUM
Intel(R) CSME <13.0.40,13.30.10 - Info Disclosure
CVSS 4.6
CVE-2020-9128
MEDIUM
FusionCompute 8.0.0 - Inadequate Encryption Strength
CVSS 4.4
CVE-2020-5938
MEDIUM
BIG-IP <13.1.3.4, <12.1.5.2, <11.6.5.2 - Info Disclosure
CVSS 6.5
CVE-2020-3549
HIGH
Cisco Firepower Management Center and Firepower Threat Defense < 6.6.1 - Unauthenticated MitM via sftunnel
CVSS 8.1
CVE-2020-7069
MEDIUM
PHP 7.2.0-7.2.33, 7.3.0-7.3.22, 7.4.0-7.4.10 - Inadequate Encryption Strength in AES-CCM Mode
CVSS 5.4
CVE-2020-14517
CRITICAL
CodeMeter < 6.90 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 9.8
CVE-2020-5917
MEDIUM
F5 BIG-IP 11.6.1-15.1.0.4 & BIG-IQ 5.2.0-7.0.0 - Weak OpenSSH Host Key Encryption
CVSS 5.9
CVE-2020-10125
HIGH
NCR APTRA XFS 04.02.01 and 05.01.00 - Inadequate Encryption Strength in BNA Software Update Validation
CVSS 7.6
CVE-2020-5763
HIGH
Grandstream HT800 Series Firmware < 1.0.17.5 - Authenticated Backdoor Root Shell via SSH Challenge
CVSS 8.8
CVE-2020-10919
MEDIUM
C-MORE HMI EA9 Firmware <6.52 - Info Disclosure
CVSS 5.9
CVE-2020-1982
MEDIUM
PAN-OS 8.0-8.0.19 - Inadequate Encryption Strength via TLS 1.0
CVSS 4.8
CVE-2020-10275
CRITICAL
Default Credentials - Info Disclosure
CVSS 9.8
CVE-2020-0533
MEDIUM
Intel CSME Firmware < 11.8.77 - Inadequate Encryption Strength via Reversible One-Way Hash
CVSS 6.7
CVE-2020-3929
MEDIUM
GeoVision Door Access Control - Info Disclosure
CVSS 5.9
CVE-2020-12714
MEDIUM
CipherMail <4.7.1-0 - Man-in-the-Middle
CVSS 5.9
CVE-2020-13785
HIGH
D-Link DIR-865L Ax 1.20B01 Beta - Inadequate Encryption Strength
CVSS 7.5
CVE-2020-12872
MEDIUM
Yaws <2.0.2-2.0.7 - Buffer Overflow
CVSS 5.5
CVE-2020-5886
CRITICAL
F5 BIG-IP 12.1.0-15.1.0.1 Cleartext Transmission of Sensitive Cryptographic Objects via Connection Mirroring
CVSS 9.1
CVE-2020-5885
CRITICAL
F5 BIG-IP 12.1.0-15.1.0.1 Cleartext Transmission of Sensitive Cryptographic Objects
CVSS 9.1
CVE-2020-10601
HIGH
VISAM VBASE Editor <11.5.0.2 - Privilege Escalation
CVSS 7.8
CVE-2020-10866
HIGH
Avast Antivirus <20 - Info Disclosure
CVSS 7.5
CVE-2020-10244
HIGH
jpaseto < 0.3.0 - Inadequate Encryption Strength in v2.local Token Hashing
CVSS 7.5
CVE-2020-9476
HIGH
ARRIS TG1692A Firmware - Inadequate Encryption Strength via Base64 Decoding
CVSS 7.5
Details
Vulnerabilities
448