The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
448 vulnerabilities with CWE-326
CVE-2017-1366
MEDIUM
IBM Security Identity Governance Virtual Appliance 5.2-5.2.3.2 - Inadequate Encryption Strength
CVSS 5.9
CVE-2017-16726
CRITICAL
Beckhoff TwinCAT - Inadequate Encryption Strength in ADS Protocol
CVSS 9.1
CVE-2017-2598
MEDIUM
Jenkins < 2.44 and < 2.32.2 - Inadequate Encryption Strength for Secrets
CVSS 4.3
CVE-2017-9635
LOW
Schneider Electric Ampla MES <6.5 - Password Reversal
CVSS 3.9
CVE-2017-1255
HIGH
IBM Security Guardium 10.0, 10.0.1, 10.1-10.1.4 - Inadequate Encryption Strength
CVSS 7.5
CVE-2017-5535
MEDIUM
TIBCO DataSynapse GridServer Manager <= 5.1.3, 6.0.0-6.0.2, 6.1.0-6.1.1, 6.2.0 - Inadequate Encryption Strength
CVSS 6.8
CVE-2017-17543
HIGH
FortiClient < 5.6.0 and FortiClient SSLVPN Client < 4.4.2335 - Inadequate Encryption Strength
CVSS 7.5
CVE-2017-1701
HIGH
IBM Rational Collaborative Lifecycle Management 5.0-6.0.4 & Rational Team Concert 5.0-5.0.1 Weak Encryption
CVSS 8.8
CVE-2017-1473
HIGH
IBM Security Access Manager Appliance 8.0.0-8.0.1.6 and 9.0.0-9.0.3.1 - Inadequate Encryption Strength
CVSS 7.5
CVE-2017-3971
HIGH
McAfee NSM <8.2.7.42.2 - Info Disclosure
CVSS 8.2
CVE-2017-6284
MEDIUM
Google Android < 6.2 - Information Disclosure
CVSS 5.5
CVE-2017-1665
MEDIUM
IBM Tivoli Key Lifecycle Manager <2.8 - Info Disclosure
CVSS 5.9
CVE-2017-1664
MEDIUM
IBM Tivoli Key Lifecycle Manager <2.8 - Info Disclosure
CVSS 5.9
CVE-2017-1000486
CRITICAL
KEV
Primefaces Remote Code Execution Exploit
CVSS 9.8
CVE-2017-14090
CRITICAL
Trend Micro ScanMail for Exchange 12.0 - Info Disclosure
CVSS 9.1
CVE-2017-1271
HIGH
IBM Security Guardium 9.0 9.1 9.5 - Inadequate Encryption Strength
CVSS 7.5
CVE-2017-17436
HIGH
Vaultek VT20i Firmware - Inadequate Encryption Strength in Bluetooth Communication
CVSS 8.8
CVE-2017-13699
HIGH
MOXA EDS-G512E 5.1 build 16072215 - Inadequate Encryption Strength via Cleartext Challenge Parameter
CVSS 7.5
CVE-2017-8174
HIGH
Huawei Secospace USG6300 and USG6600 - Inadequate Encryption Strength
CVSS 7.5
CVE-2017-1375
HIGH
IBM System Storage Storwize V7000 Unified - Info Disclosure
CVSS 7.5
CVE-2017-14797
HIGH
Philips Hue Bridge - Info Disclosure
CVSS 7.5
CVE-2017-9645
MEDIUM
Mirion Technologies - Info Disclosure
CVSS 6.5
CVE-2017-14262
HIGH
Samsung SRN-1670D, SRN-1000, SRN-472S, SRN-470D Firmware - Unauthenticated Admin Password Hash Exposure
CVSS 8.1
CVE-2017-12871
MEDIUM
SimpleSAMLphp 1.14.0-1.14.11 - Inadequate Encryption Strength via IV Reuse
CVSS 5.9
CVE-2017-11317
CRITICAL
KEV
Telerik UI for ASP.NET AJAX < 2017.1.118 - Remote Code Execution via Weak RadAsyncUpload Encryption
CVSS 9.8
Details
Vulnerabilities
448