CWE-326

Inadequate Encryption Strength

Parent: CWE-693 - Protection Mechanism Failure

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

448 vulnerabilities with CWE-326
CVE-2017-1366 MEDIUM
IBM Security Identity Governance Virtual Appliance 5.2-5.2.3.2 - Inadequate Encryption Strength
CVSS 5.9
CVE-2017-16726 CRITICAL
Beckhoff TwinCAT - Inadequate Encryption Strength in ADS Protocol
CVSS 9.1
CVE-2017-2598 MEDIUM
Jenkins < 2.44 and < 2.32.2 - Inadequate Encryption Strength for Secrets
CVSS 4.3
CVE-2017-9635 LOW
Schneider Electric Ampla MES <6.5 - Password Reversal
CVSS 3.9
CVE-2017-1255 HIGH
IBM Security Guardium 10.0, 10.0.1, 10.1-10.1.4 - Inadequate Encryption Strength
CVSS 7.5
CVE-2017-5535 MEDIUM
TIBCO DataSynapse GridServer Manager <= 5.1.3, 6.0.0-6.0.2, 6.1.0-6.1.1, 6.2.0 - Inadequate Encryption Strength
CVSS 6.8
CVE-2017-17543 HIGH
FortiClient < 5.6.0 and FortiClient SSLVPN Client < 4.4.2335 - Inadequate Encryption Strength
CVSS 7.5
CVE-2017-1701 HIGH
IBM Rational Collaborative Lifecycle Management 5.0-6.0.4 & Rational Team Concert 5.0-5.0.1 Weak Encryption
CVSS 8.8
CVE-2017-1473 HIGH
IBM Security Access Manager Appliance 8.0.0-8.0.1.6 and 9.0.0-9.0.3.1 - Inadequate Encryption Strength
CVSS 7.5
CVE-2017-3971 HIGH
McAfee NSM <8.2.7.42.2 - Info Disclosure
CVSS 8.2
CVE-2017-6284 MEDIUM
Google Android < 6.2 - Information Disclosure
CVSS 5.5
CVE-2017-1665 MEDIUM
IBM Tivoli Key Lifecycle Manager <2.8 - Info Disclosure
CVSS 5.9
CVE-2017-1664 MEDIUM
IBM Tivoli Key Lifecycle Manager <2.8 - Info Disclosure
CVSS 5.9
CVE-2017-1000486 CRITICAL KEV
Primefaces Remote Code Execution Exploit
CVSS 9.8
CVE-2017-14090 CRITICAL
Trend Micro ScanMail for Exchange 12.0 - Info Disclosure
CVSS 9.1
CVE-2017-1271 HIGH
IBM Security Guardium 9.0 9.1 9.5 - Inadequate Encryption Strength
CVSS 7.5
CVE-2017-17436 HIGH
Vaultek VT20i Firmware - Inadequate Encryption Strength in Bluetooth Communication
CVSS 8.8
CVE-2017-13699 HIGH
MOXA EDS-G512E 5.1 build 16072215 - Inadequate Encryption Strength via Cleartext Challenge Parameter
CVSS 7.5
CVE-2017-8174 HIGH
Huawei Secospace USG6300 and USG6600 - Inadequate Encryption Strength
CVSS 7.5
CVE-2017-1375 HIGH
IBM System Storage Storwize V7000 Unified - Info Disclosure
CVSS 7.5
CVE-2017-14797 HIGH
Philips Hue Bridge - Info Disclosure
CVSS 7.5
CVE-2017-9645 MEDIUM
Mirion Technologies - Info Disclosure
CVSS 6.5
CVE-2017-14262 HIGH
Samsung SRN-1670D, SRN-1000, SRN-472S, SRN-470D Firmware - Unauthenticated Admin Password Hash Exposure
CVSS 8.1
CVE-2017-12871 MEDIUM
SimpleSAMLphp 1.14.0-1.14.11 - Inadequate Encryption Strength via IV Reuse
CVSS 5.9
CVE-2017-11317 CRITICAL KEV
Telerik UI for ASP.NET AJAX < 2017.1.118 - Remote Code Execution via Weak RadAsyncUpload Encryption
CVSS 9.8
Details
Vulnerabilities 448