CWE-326

Inadequate Encryption Strength

Parent: CWE-693 - Protection Mechanism Failure

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

448 vulnerabilities with CWE-326
CVE-2018-15796 HIGH
Cloud Foundry Bits Service < 2.14.0 - Insecure URL Signing Key Exposure
CVSS 8.1
CVE-2018-1518 MEDIUM
IBM InfoSphere Information Server 11.7 - Weak Password Encryption
CVSS 6.2
CVE-2018-0448 CRITICAL
Cisco DNA Center < 1.1.4 - Authentication Bypass via Identity Management
CVSS 9.8
CVE-2018-1593 LOW
IBM Multi-Cloud Data Encryption 2.1 - Data Manipulation via Missing File Checksums
CVSS 3.7
CVE-2018-1785 HIGH
IBM Spectrum Protect Client/VE 7.1.0.0-7.1.8.3 Weak Encryption
CVSS 7.5
CVE-2018-1545 HIGH
IBM Spectrum Protect Client/VE 7.1.0.0-7.1.8.2 Weak Encryption
CVSS 7.5
CVE-2018-17177 LOW
Neato Botvac Connected <2.2.0, Botvac 85 <1.2.1 - RCE
CVSS 2.4
CVE-2018-0131 MEDIUM
Cisco IOS and IOS XE - Inadequate Encryption Strength in IKEv1 RSA-Encrypted Nonces
CVSS 5.9
CVE-2018-15124 CRITICAL
Zipato Zipabox <BOARD REV - 1 - Info Disclosure
CVSS 9.8
CVE-2018-9028 HIGH
Broadcom Privileged Access Manager 2.x < 3.0.0 - Inadequate Encryption Strength for Passwords
CVSS 7.5
CVE-2018-5184 HIGH
Thunderbird <52.8 - Info Disclosure
CVSS 7.5
CVE-2018-1466 MEDIUM
IBM SAN Volume Controller et al <8.1.1 - Info Disclosure
CVSS 5.3
CVE-2018-7242 CRITICAL
Schneider Electric Modicon and BMXNOR0200 - Inadequate Encryption Strength
CVSS 9.8
CVE-2018-4839 MEDIUM
Siemens SIPROTEC and DIGSI - Inadequate Encryption Strength
CVSS 5.3
CVE-2018-5461 MEDIUM
Belden Hirschmann - Info Disclosure
CVSS 6.5
CVE-2018-6653 MEDIUM
comforte SWAP 1049-1069, 20.0.0-21.5.3 - Inadequate Encryption Strength via TLS Cipher Suite Downgrade
CVSS 5.3
CVE-2018-1425 MEDIUM
IBM Security Guardium Big Data Intelligence - Info Disclosure
CVSS 5.9
CVE-2018-6635 HIGH
Avaya Aura < 7.1.1 - Inadequate Encryption Strength in System Manager
CVSS 7.5
CVE-2018-6594 HIGH
PyCrypto < 2.6.1 - Inadequate Encryption Strength in ElGamal Key Generation
CVSS 7.5
CVE-2018-5298 HIGH
Oral-B App <5.0.0 - Info Disclosure
CVSS 7.5
CVE-2017-16632 HIGH
SapphireIMS 4097_1 - Info Disclosure
CVSS 7.5
CVE-2017-20001 HIGH
AES encryption project 7.x-8.x - Info Disclosure
CVSS 7.5
CVE-2017-1712 MEDIUM
HCL Domino < 9.0.1 - Inadequate Encryption Strength via TLS Protocol Implementation
CVSS 5.9
CVE-2017-1713 MEDIUM
IBM InfoSphere Streams 4.2.1 - Inadequate Encryption Strength
CVSS 5.9
CVE-2017-1695 MEDIUM
IBM QRadar SIEM <7.4 - Info Disclosure
CVSS 5.9
Details
Vulnerabilities 448