CWE-326

Inadequate Encryption Strength

Parent: CWE-693 - Protection Mechanism Failure

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

448 vulnerabilities with CWE-326
CVE-2019-4102 MEDIUM
IBM DB2 9.7, 10.1, 10.5, 11.0 - Inadequate Encryption Strength
CVSS 5.9
CVE-2019-4151 MEDIUM
IBM Security Access Manager 9.0.1-9.0.6 - Inadequate Encryption Strength
CVSS 5.9
CVE-2019-6972 HIGH
TP-Link TL-WR1043ND V2 - Info Disclosure
CVSS 7.5
CVE-2019-4256 HIGH
IBM API Connect 5.0.0.0-5.0.8.6 - Inadequate Encryption Strength
CVSS 7.5
CVE-2019-10855 HIGH
Computrols CBAS < 19.0.0 - Inadequate Encryption Strength via MD5 Password Hashing
CVSS 7.5
CVE-2019-10112 HIGH
GitLab <11.7.8-11.9.2 - Info Disclosure
CVSS 7.5
CVE-2019-10907 CRITICAL
Airsonic 10.2.1 - Inadequate Encryption Strength in Remember-Me Mechanism
CVSS 9.8
CVE-2019-7648 HIGH
Hotels_Server <2018-11-05 - Info Disclosure
CVSS 7.5
CVE-2018-25272 CRITICAL
ELBA5 5.8.0 Remote Code Execution via Database Access
CVSS 9.8
CVE-2018-16499 MEDIUM
Versa Operating System - Inadequate Encryption Strength
CVSS 5.9
CVE-2018-21080 MEDIUM
Android - Lockscreen Bypass via NFC Magnet Activation
CVSS 4.6
CVE-2018-18325 HIGH KEV
Dnnsoftware Dotnetnuke < 9.2.2 - Weak Encryption
CVSS 7.5
CVE-2018-15811 HIGH KEV
Dnnsoftware Dotnetnuke < 9.2.1 - Weak Encryption
CVSS 7.5
CVE-2018-20810 CRITICAL
Pulse Secure Pulse Connect Secure <8.3R2 & Pulse Policy Secure <5.4R2 - Weak Cluster Sync Encryption
CVSS 9.8
CVE-2018-1608 MEDIUM
IBM Rational Engineering Lifecycle Manager <6.0.6 - Info Disclosure
CVSS 5.9
CVE-2018-2007 MEDIUM
IBM API Connect 2018.1-2018.4.1.2 - Inadequate Encryption Strength
CVSS 5.9
CVE-2018-1925 MEDIUM
IBM WebSphere MQ <9.1.1 - Info Disclosure
CVSS 5.9
CVE-2018-1946 MEDIUM
IBM Security Identity Governance and Intelligence 5.2-5.2.4.1 - Inadequate Encryption Strength
CVSS 5.9
CVE-2018-1751 MEDIUM
IBM Security Key Lifecycle Manager 3.0-3.0.0.2 - Inadequate Encryption Strength
CVSS 5.9
CVE-2018-18767 HIGH
D-Link myDlink Baby Camera Monitor - Inadequate Encryption Strength in Credential Transmission
CVSS 7.0
CVE-2018-1814 MEDIUM
IBM Security Access Manager 9.0.1.0-9.0.5.0 - Inadequate Encryption Strength
CVSS 5.9
CVE-2018-1665 MEDIUM
IBM DataPower Gateway - Info Disclosure
CVSS 5.9
CVE-2018-19001 MEDIUM
Philips HealthSuite Health Android App - Inadequate Encryption Strength
CVSS 4.3
CVE-2018-1648 HIGH
IBM QRadar SIEM <7.4 - Info Disclosure
CVSS 7.5
CVE-2018-19784 HIGH
php-proxy 5.1.0 - Inadequate Encryption Strength in str_rot_pass Function
CVSS 7.5
Details
Vulnerabilities 448