CWE-326

Inadequate Encryption Strength

Parent: CWE-693 - Protection Mechanism Failure

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

457 vulnerabilities with CWE-326
CVE-2017-17436 HIGH
Vaultek VT20i Firmware - Inadequate Encryption Strength in Bluetooth Communication
CVSS 8.8
CVE-2017-13699 HIGH
MOXA EDS-G512E 5.1 build 16072215 - Inadequate Encryption Strength via Cleartext Challenge Parameter
CVSS 7.5
CVE-2017-8174 HIGH
Huawei Secospace USG6300 and USG6600 - Inadequate Encryption Strength
CVSS 7.5
CVE-2017-1375 HIGH
IBM System Storage Storwize V7000 Unified - Info Disclosure
CVSS 7.5
CVE-2017-14797 HIGH
Philips Hue Bridge - Info Disclosure
CVSS 7.5
CVE-2017-9645 MEDIUM
Mirion Technologies - Info Disclosure
CVSS 6.5
CVE-2017-14262 HIGH
Samsung SRN-1670D, SRN-1000, SRN-472S, SRN-470D Firmware - Unauthenticated Admin Password Hash Exposure
CVSS 8.1
CVE-2017-12871 MEDIUM
SimpleSAMLphp 1.14.0-1.14.11 - Inadequate Encryption Strength via IV Reuse
CVSS 5.9
CVE-2017-11317 CRITICAL KEV
Telerik UI for ASP.NET AJAX < 2017.1.118 - Remote Code Execution via Weak RadAsyncUpload Encryption
CVSS 9.8
CVE-2017-1224 HIGH
IBM BigFix Platform - Inadequate Encryption Strength
CVSS 7.5
CVE-2017-7673 CRITICAL
Apache OpenMeetings 1.0.0 - Info Disclosure
CVSS 9.8
CVE-2017-7905 CRITICAL
GE Multilin SR, UR, and URplus Protective Relays - Weak Password Encoding via Non-Random Initialization Vector
CVSS 9.8
CVE-2017-7903 CRITICAL
Rockwellautomation 1763-l16awa Series A < 16.000 - Weak Encryption
CVSS 9.8
CVE-2017-1319 HIGH
IBM Tivoli Federated Identity Manager 6.2 - Info Disclosure
CVSS 7.5
CVE-2017-1179 MEDIUM
IBM BigFix Compliance Analytics <1.9.79 - Info Disclosure
CVSS 5.9
CVE-2017-7888 CRITICAL
Dolibarr ERP/CRM 4.0.4 - Inadequate Encryption Strength via MD5 Password Storage
CVSS 9.8
CVE-2017-7229 CRITICAL
Vaultive Office 365 Security < 4.5.21 - DoS & Info Disclosure via PGP/MIME Mismanagement
CVSS 9.1
CVE-2017-8076 CRITICAL
TP-Link TL-SG108E Firmware 1.1.2 Build 20141017 Rel.50749 - Inadequate Encryption Strength
CVSS 9.8
CVE-2017-5160 MEDIUM
Schneider Electric Wonderware InTouch Access Anywhere < 11.5.2 - Inadequate Encryption Strength
CVSS 5.3
CVE-2017-2399 MEDIUM
iPhone OS < 10.3 - Inadequate Encryption Strength in Pasteboard
CVSS 4.6
CVE-2017-2391 MEDIUM
Pages, Numbers, Keynote < 6.1/4.1/7.1 (macOS) & < 3.1 (iOS) - Weak Export Encryption
CVSS 5.3
CVE-2017-2380 HIGH
iPhone OS < 10.2.1 - Inadequate Encryption Strength in SCEP Implementation
CVSS 7.5
CVE-2017-5239 HIGH
Eview EV-07S GPS Tracker - Info Disclosure
CVSS 7.5
CVE-2017-5999 HIGH
syspass 2.x - Inadequate Encryption Strength via MCRYPT_RIJNDAEL_256
CVSS 7.5
CVE-2016-11043 HIGH
Android - Inadequate Encryption Strength in S/MIME Implementation
CVSS 7.5
Details
Vulnerabilities 457