CWE-326

Inadequate Encryption Strength

Parent: CWE-693 - Protection Mechanism Failure

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

457 vulnerabilities with CWE-326
CVE-2018-1425 MEDIUM
IBM Security Guardium Big Data Intelligence - Info Disclosure
CVSS 5.9
CVE-2018-6635 HIGH
Avaya Aura < 7.1.1 - Inadequate Encryption Strength in System Manager
CVSS 7.5
CVE-2018-6594 HIGH
PyCrypto < 2.6.1 - Inadequate Encryption Strength in ElGamal Key Generation
CVSS 7.5
CVE-2018-5298 HIGH
Oral-B App <5.0.0 - Info Disclosure
CVSS 7.5
CVE-2017-16632 HIGH
SapphireIMS 4097_1 - Info Disclosure
CVSS 7.5
CVE-2017-20001 HIGH
AES encryption project 7.x-8.x - Info Disclosure
CVSS 7.5
CVE-2017-1712 MEDIUM
HCL Domino < 9.0.1 - Inadequate Encryption Strength via TLS Protocol Implementation
CVSS 5.9
CVE-2017-1713 MEDIUM
IBM InfoSphere Streams 4.2.1 - Inadequate Encryption Strength
CVSS 5.9
CVE-2017-1695 MEDIUM
IBM QRadar SIEM <7.4 - Info Disclosure
CVSS 5.9
CVE-2017-1366 MEDIUM
IBM Security Identity Governance Virtual Appliance 5.2-5.2.3.2 - Inadequate Encryption Strength
CVSS 5.9
CVE-2017-16726 CRITICAL
Beckhoff TwinCAT - Inadequate Encryption Strength in ADS Protocol
CVSS 9.1
CVE-2017-2598 MEDIUM
Jenkins < 2.44 and < 2.32.2 - Inadequate Encryption Strength for Secrets
CVSS 4.3
CVE-2017-9635 LOW
Schneider Electric Ampla MES <6.5 - Password Reversal
CVSS 3.9
CVE-2017-1255 HIGH
IBM Security Guardium 10.0, 10.0.1, 10.1-10.1.4 - Inadequate Encryption Strength
CVSS 7.5
CVE-2017-5535 MEDIUM
TIBCO DataSynapse GridServer Manager <= 5.1.3, 6.0.0-6.0.2, 6.1.0-6.1.1, 6.2.0 - Inadequate Encryption Strength
CVSS 6.8
CVE-2017-17543 HIGH
FortiClient < 5.6.0 and FortiClient SSLVPN Client < 4.4.2335 - Inadequate Encryption Strength
CVSS 7.5
CVE-2017-1701 HIGH
IBM Rational Collaborative Lifecycle Management 5.0-6.0.4 & Rational Team Concert 5.0-5.0.1 Weak Encryption
CVSS 8.8
CVE-2017-1473 HIGH
IBM Security Access Manager Appliance 8.0.0-8.0.1.6 and 9.0.0-9.0.3.1 - Inadequate Encryption Strength
CVSS 7.5
CVE-2017-3971 HIGH
McAfee NSM <8.2.7.42.2 - Info Disclosure
CVSS 8.2
CVE-2017-6284 MEDIUM
Google Android < 6.2 - Information Disclosure
CVSS 5.5
CVE-2017-1665 MEDIUM
IBM Tivoli Key Lifecycle Manager <2.8 - Info Disclosure
CVSS 5.9
CVE-2017-1664 MEDIUM
IBM Tivoli Key Lifecycle Manager <2.8 - Info Disclosure
CVSS 5.9
CVE-2017-1000486 CRITICAL KEV
Primefaces Remote Code Execution Exploit
CVSS 9.8
CVE-2017-14090 CRITICAL
Trend Micro ScanMail for Exchange 12.0 - Info Disclosure
CVSS 9.1
CVE-2017-1271 HIGH
IBM Security Guardium 9.0 9.1 9.5 - Inadequate Encryption Strength
CVSS 7.5
Details
Vulnerabilities 457