CWE-326

Inadequate Encryption Strength

Parent: CWE-693 - Protection Mechanism Failure

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

448 vulnerabilities with CWE-326
CVE-2017-1224 HIGH
IBM BigFix Platform - Inadequate Encryption Strength
CVSS 7.5
CVE-2017-7673 CRITICAL
Apache OpenMeetings 1.0.0 - Info Disclosure
CVSS 9.8
CVE-2017-7905 CRITICAL
GE Multilin SR, UR, and URplus Protective Relays - Weak Password Encoding via Non-Random Initialization Vector
CVSS 9.8
CVE-2017-7903 CRITICAL
Rockwellautomation 1763-l16awa Series A < 16.000 - Weak Encryption
CVSS 9.8
CVE-2017-1319 HIGH
IBM Tivoli Federated Identity Manager 6.2 - Info Disclosure
CVSS 7.5
CVE-2017-1179 MEDIUM
IBM BigFix Compliance Analytics <1.9.79 - Info Disclosure
CVSS 5.9
CVE-2017-7888 CRITICAL
Dolibarr ERP/CRM 4.0.4 - Inadequate Encryption Strength via MD5 Password Storage
CVSS 9.8
CVE-2017-7229 CRITICAL
Vaultive Office 365 Security < 4.5.21 - DoS & Info Disclosure via PGP/MIME Mismanagement
CVSS 9.1
CVE-2017-8076 CRITICAL
TP-Link TL-SG108E Firmware 1.1.2 Build 20141017 Rel.50749 - Inadequate Encryption Strength
CVSS 9.8
CVE-2017-5160 MEDIUM
Schneider Electric Wonderware InTouch Access Anywhere < 11.5.2 - Inadequate Encryption Strength
CVSS 5.3
CVE-2017-2399 MEDIUM
iPhone OS < 10.3 - Inadequate Encryption Strength in Pasteboard
CVSS 4.6
CVE-2017-2391 MEDIUM
Pages, Numbers, Keynote < 6.1/4.1/7.1 (macOS) & < 3.1 (iOS) - Weak Export Encryption
CVSS 5.3
CVE-2017-2380 HIGH
iPhone OS < 10.2.1 - Inadequate Encryption Strength in SCEP Implementation
CVSS 7.5
CVE-2017-5239 HIGH
Eview EV-07S GPS Tracker - Info Disclosure
CVSS 7.5
CVE-2017-5999 HIGH
syspass 2.x - Inadequate Encryption Strength via MCRYPT_RIJNDAEL_256
CVSS 7.5
CVE-2016-11043 HIGH
Android - Inadequate Encryption Strength in S/MIME Implementation
CVSS 7.5
CVE-2016-3019 MEDIUM
IBM Security Access Manager 9.0.0 - Inadequate Encryption Strength
CVSS 6.5
CVE-2016-5056 HIGH
OSRAM SYLVANIA Osram Lightify Pro before 2016-07-26 - Inadequate Encryption Strength
CVSS 7.5
CVE-2016-2379 HIGH
Pidgin Mxit - Inadequate Encryption Strength in Password Handling
CVSS 8.8
CVE-2016-9121 CRITICAL
go-jose < 1.0.4 - Inadequate Encryption Strength via ECDH-ES Invalid Curve Attack
CVSS 9.1
CVE-2016-6225 MEDIUM
Percona XtraBackup <2.3.6, 2.4.x <2.4.5 - Info Disclosure
CVSS 5.9
CVE-2016-2879 HIGH
IBM QRadar SIEM - Inadequate Encryption Strength for Password Hashing
CVSS 7.8
CVE-2016-4693 HIGH
iPhone OS < 10.2, macOS < 10.12.2, watchOS < 3.1.3 - Inadequate Encryption Strength via 3DES Cipher
CVSS 7.5
CVE-2016-4685 MEDIUM
iPhone OS < 10.1 - Inadequate Encryption Strength in iTunes Backup
CVSS 5.9
CVE-2016-5919 HIGH
IBM Security Access Manager for Web <9.0.0 - Info Disclosure
CVSS 7.5
Details
Vulnerabilities 448