The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
457 vulnerabilities with CWE-326
CVE-2020-12714
MEDIUM
CipherMail <4.7.1-0 - Man-in-the-Middle
CVSS 5.9
CVE-2020-13785
HIGH
D-Link DIR-865L Ax 1.20B01 Beta - Inadequate Encryption Strength
CVSS 7.5
CVE-2020-12872
MEDIUM
Yaws <2.0.2-2.0.7 - Buffer Overflow
CVSS 5.5
CVE-2020-5886
CRITICAL
F5 BIG-IP 12.1.0-15.1.0.1 Cleartext Transmission of Sensitive Cryptographic Objects via Connection Mirroring
CVSS 9.1
CVE-2020-5885
CRITICAL
F5 BIG-IP 12.1.0-15.1.0.1 Cleartext Transmission of Sensitive Cryptographic Objects
CVSS 9.1
CVE-2020-10601
HIGH
VISAM VBASE Editor <11.5.0.2 - Privilege Escalation
CVSS 7.8
CVE-2020-10866
HIGH
Avast Antivirus <20 - Info Disclosure
CVSS 7.5
CVE-2020-10244
HIGH
jpaseto < 0.3.0 - Inadequate Encryption Strength in v2.local Token Hashing
CVSS 7.5
CVE-2020-9476
HIGH
ARRIS TG1692A Firmware - Inadequate Encryption Strength via Base64 Decoding
CVSS 7.5
CVE-2020-9337
MEDIUM
GolfBuddy Course Manager 1.1 - Inadequate Encryption Strength via Base64-Encoded Password Transmission
CVSS 6.5
CVE-2020-5224
MEDIUM
django-user-sessions < 1.7.1 - Session Takeover via Exposed Session Key
CVSS 6.5
CVE-2020-6966
CRITICAL
GE Healthcare ApexPro Telemetry Server < 4.2 - Inadequate Encryption Strength
CVSS 10.0
CVE-2019-4291
MEDIUM
IBM Maximo Anywhere <7.6.4.0 - Code Injection
CVSS 6.5
CVE-2019-4160
HIGH
IBM Security Guardium Data Encryption 3.0.0.2 - Inadequate Encryption Strength
CVSS 7.5
CVE-2019-19101
MEDIUM
B&R Automation Studio <4.3.11SP-4.7.2 - SSRF
CVSS 6.5
CVE-2019-19097
MEDIUM
Hitachi Energy eSOMS 4.0-6.0.3 - Weak Cipher Suite Acceptance
CVSS 5.9
CVE-2019-14855
HIGH
GnuPG < 2.2.18 - Certificate Signature Forgery via SHA-1 Collision
CVSS 7.5
CVE-2019-12121
HIGH
ONAP Portal < 4.0.0 - Inadequate Encryption Strength via UserId Padding Oracle Attack
CVSS 7.5
CVE-2019-19299
HIGH
SiNVR/SiVMS Video Server <5.0.2 - Info Disclosure
CVSS 7.5
CVE-2019-18863
MEDIUM
Mitel 6800/6900 SIP <5.1.0.2051 SP2 - Man-In-The-Middle
CVSS 5.9
CVE-2019-4557
HIGH
IBM Qradar Advisor <2.5 - Info Disclosure
CVSS 7.5
CVE-2019-13163
MEDIUM
Fujitsu TLS Library - Inadequate Encryption Strength
CVSS 5.9
CVE-2019-18263
MEDIUM
Philips Veradius Unity, Pulsera, and Endura Firmware - Inadequate Encryption Strength
CVSS 6.5
CVE-2019-18241
MEDIUM
Philips IntelliBridge EC40 and EC80 Firmware - Inadequate Encryption Strength in SSH Server
CVSS 6.5
CVE-2019-13539
HIGH
Medtronic Valleylab Exchange Client <3.4 - Info Disclosure
CVSS 7.0
Details
Vulnerabilities
457