CWE-326

Inadequate Encryption Strength

Parent: CWE-693 - Protection Mechanism Failure

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

457 vulnerabilities with CWE-326
CVE-2019-17598 HIGH
Lightbend Play Framework 2.5.0-2.5.18 and 2.6.0-2.6.23 - Proxy Credential Exposure via HTTPS Connection
CVSS 7.5
CVE-2019-4339 HIGH
IBM Security Guardium Big Data Intelligence - Info Disclosure
CVSS 7.5
CVE-2019-16649 CRITICAL
Supermicro X11DAI-N & X11/H11/H12/M11/X9/X10 Firmware - Virtual Media Service Credential Exposure
CVSS 10.0
CVE-2019-4175 HIGH
IBM Cognos Controller 10.3.0, 10.3.1, 10.4.0, 10.4.1 - Inadequate Encryption Strength
CVSS 7.5
CVE-2019-15806 CRITICAL
CommScope ARRIS TR4400 - Auth Bypass
CVSS 9.8
CVE-2019-15805 CRITICAL
CommScope ARRIS TR4400 - Auth Bypass
CVSS 9.8
CVE-2019-14332 HIGH
D-Link 6600-AP & DWL-3600AP Ax - Info Disclosure
CVSS 7.8
CVE-2019-10639 HIGH
Linux kernel 4.1-4.20.9 - Information Exposure via IP ID Hash Collision
CVSS 7.5
CVE-2019-10638 MEDIUM
Linux Kernel < 5.1.7 - Information Exposure via IP ID Hash Collision
CVSS 6.5
CVE-2019-4102 MEDIUM
IBM DB2 9.7, 10.1, 10.5, 11.0 - Inadequate Encryption Strength
CVSS 5.9
CVE-2019-4151 MEDIUM
IBM Security Access Manager 9.0.1-9.0.6 - Inadequate Encryption Strength
CVSS 5.9
CVE-2019-6972 HIGH
TP-Link TL-WR1043ND V2 - Info Disclosure
CVSS 7.5
CVE-2019-4256 HIGH
IBM API Connect 5.0.0.0-5.0.8.6 - Inadequate Encryption Strength
CVSS 7.5
CVE-2019-10855 HIGH
Computrols CBAS < 19.0.0 - Inadequate Encryption Strength via MD5 Password Hashing
CVSS 7.5
CVE-2019-10112 HIGH
GitLab <11.7.8-11.9.2 - Info Disclosure
CVSS 7.5
CVE-2019-10907 CRITICAL
Airsonic 10.2.1 - Inadequate Encryption Strength in Remember-Me Mechanism
CVSS 9.8
CVE-2019-7648 HIGH
Hotels_Server <2018-11-05 - Info Disclosure
CVSS 7.5
CVE-2018-25272 CRITICAL
ELBA5 5.8.0 Remote Code Execution via Database Access
CVSS 9.8
CVE-2018-16499 MEDIUM
Versa Operating System - Inadequate Encryption Strength
CVSS 5.9
CVE-2018-21080 MEDIUM
Android - Lockscreen Bypass via NFC Magnet Activation
CVSS 4.6
CVE-2018-18325 HIGH KEV
Dnnsoftware Dotnetnuke < 9.2.2 - Weak Encryption
CVSS 7.5
CVE-2018-15811 HIGH KEV
Dnnsoftware Dotnetnuke < 9.2.1 - Weak Encryption
CVSS 7.5
CVE-2018-20810 CRITICAL
Pulse Secure Pulse Connect Secure <8.3R2 & Pulse Policy Secure <5.4R2 - Weak Cluster Sync Encryption
CVSS 9.8
CVE-2018-1608 MEDIUM
IBM Rational Engineering Lifecycle Manager <6.0.6 - Info Disclosure
CVSS 5.9
CVE-2018-2007 MEDIUM
IBM API Connect 2018.1-2018.4.1.2 - Inadequate Encryption Strength
CVSS 5.9
Details
Vulnerabilities 457