CWE-326

Inadequate Encryption Strength

Parent: CWE-693 - Protection Mechanism Failure

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

457 vulnerabilities with CWE-326
CVE-2020-12714 MEDIUM
CipherMail <4.7.1-0 - Man-in-the-Middle
CVSS 5.9
CVE-2020-13785 HIGH
D-Link DIR-865L Ax 1.20B01 Beta - Inadequate Encryption Strength
CVSS 7.5
CVE-2020-12872 MEDIUM
Yaws <2.0.2-2.0.7 - Buffer Overflow
CVSS 5.5
CVE-2020-5886 CRITICAL
F5 BIG-IP 12.1.0-15.1.0.1 Cleartext Transmission of Sensitive Cryptographic Objects via Connection Mirroring
CVSS 9.1
CVE-2020-5885 CRITICAL
F5 BIG-IP 12.1.0-15.1.0.1 Cleartext Transmission of Sensitive Cryptographic Objects
CVSS 9.1
CVE-2020-10601 HIGH
VISAM VBASE Editor <11.5.0.2 - Privilege Escalation
CVSS 7.8
CVE-2020-10866 HIGH
Avast Antivirus <20 - Info Disclosure
CVSS 7.5
CVE-2020-10244 HIGH
jpaseto < 0.3.0 - Inadequate Encryption Strength in v2.local Token Hashing
CVSS 7.5
CVE-2020-9476 HIGH
ARRIS TG1692A Firmware - Inadequate Encryption Strength via Base64 Decoding
CVSS 7.5
CVE-2020-9337 MEDIUM
GolfBuddy Course Manager 1.1 - Inadequate Encryption Strength via Base64-Encoded Password Transmission
CVSS 6.5
CVE-2020-5224 MEDIUM
django-user-sessions < 1.7.1 - Session Takeover via Exposed Session Key
CVSS 6.5
CVE-2020-6966 CRITICAL
GE Healthcare ApexPro Telemetry Server < 4.2 - Inadequate Encryption Strength
CVSS 10.0
CVE-2019-4291 MEDIUM
IBM Maximo Anywhere <7.6.4.0 - Code Injection
CVSS 6.5
CVE-2019-4160 HIGH
IBM Security Guardium Data Encryption 3.0.0.2 - Inadequate Encryption Strength
CVSS 7.5
CVE-2019-19101 MEDIUM
B&R Automation Studio <4.3.11SP-4.7.2 - SSRF
CVSS 6.5
CVE-2019-19097 MEDIUM
Hitachi Energy eSOMS 4.0-6.0.3 - Weak Cipher Suite Acceptance
CVSS 5.9
CVE-2019-14855 HIGH
GnuPG < 2.2.18 - Certificate Signature Forgery via SHA-1 Collision
CVSS 7.5
CVE-2019-12121 HIGH
ONAP Portal < 4.0.0 - Inadequate Encryption Strength via UserId Padding Oracle Attack
CVSS 7.5
CVE-2019-19299 HIGH
SiNVR/SiVMS Video Server <5.0.2 - Info Disclosure
CVSS 7.5
CVE-2019-18863 MEDIUM
Mitel 6800/6900 SIP <5.1.0.2051 SP2 - Man-In-The-Middle
CVSS 5.9
CVE-2019-4557 HIGH
IBM Qradar Advisor <2.5 - Info Disclosure
CVSS 7.5
CVE-2019-13163 MEDIUM
Fujitsu TLS Library - Inadequate Encryption Strength
CVSS 5.9
CVE-2019-18263 MEDIUM
Philips Veradius Unity, Pulsera, and Endura Firmware - Inadequate Encryption Strength
CVSS 6.5
CVE-2019-18241 MEDIUM
Philips IntelliBridge EC40 and EC80 Firmware - Inadequate Encryption Strength in SSH Server
CVSS 6.5
CVE-2019-13539 HIGH
Medtronic Valleylab Exchange Client <3.4 - Info Disclosure
CVSS 7.0
Details
Vulnerabilities 457