The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
457 vulnerabilities with CWE-326
CVE-2016-3019
MEDIUM
IBM Security Access Manager 9.0.0 - Inadequate Encryption Strength
CVSS 6.5
CVE-2016-5056
HIGH
OSRAM SYLVANIA Osram Lightify Pro before 2016-07-26 - Inadequate Encryption Strength
CVSS 7.5
CVE-2016-2379
HIGH
Pidgin Mxit - Inadequate Encryption Strength in Password Handling
CVSS 8.8
CVE-2016-9121
CRITICAL
go-jose < 1.0.4 - Inadequate Encryption Strength via ECDH-ES Invalid Curve Attack
CVSS 9.1
CVE-2016-6225
MEDIUM
Percona XtraBackup <2.3.6, 2.4.x <2.4.5 - Info Disclosure
CVSS 5.9
CVE-2016-2879
HIGH
IBM QRadar SIEM - Inadequate Encryption Strength for Password Hashing
CVSS 7.8
CVE-2016-4693
HIGH
iPhone OS < 10.2, macOS < 10.12.2, watchOS < 3.1.3 - Inadequate Encryption Strength via 3DES Cipher
CVSS 7.5
CVE-2016-4685
MEDIUM
iPhone OS < 10.1 - Inadequate Encryption Strength in iTunes Backup
CVSS 5.9
CVE-2016-5919
HIGH
IBM Security Access Manager for Web <9.0.0 - Info Disclosure
CVSS 7.5
CVE-2016-3034
MEDIUM
IBM AppScan Source - Inadequate Encryption Strength via Unsalted One-Way Hash
CVSS 4.4
CVE-2016-7798
HIGH
openssl < 2.0.0 - Inadequate Encryption Strength in GCM Mode
CVSS 7.5
CVE-2016-10104
MEDIUM
Hitek Software Automize - Info Disclosure
CVSS 5.9
CVE-2016-10103
HIGH
Hitek Software Automize <11.14 - Info Disclosure
CVSS 8.1
CVE-2016-10102
HIGH
Hitek Software Automize <11.14 - Info Disclosure
CVSS 8.1
CVE-2016-10101
HIGH
Hitek Software Automize <11.x - Info Disclosure
CVSS 8.1
CVE-2016-5804
CRITICAL
Moxa MGate MB3180 < 1.8, MB3280 < 2.7, MB3480 < 2.6, MB3170 < 2.5, MB3270 < 2.7 - Weak Encryption Authentication Bypass
CVSS 9.8
CVE-2015-5361
MEDIUM
Juniper Junos - Inadequate Encryption Strength in FTP ALG FTPS Extensions
CVSS 6.5
CVE-2015-4953
MEDIUM
IBM BigFix Remote Control - Inadequate Encryption Strength
CVSS 4.8
CVE-2015-7449
LOW
IBM Rational <4.0.7-6.0.2 - Privilege Escalation
CVSS 3.3
CVE-2015-0575
CRITICAL
Qualcomm Android Products - Inadequate Encryption Strength via Default Ciphersuite Configuration
CVSS 9.8
CVE-2015-8086
MEDIUM
Huawei AR <V200R007C00SPC100, Quidway S9300 <V200R009C00, S12700 <V...
CVSS 4.9
CVE-2015-8085
MEDIUM
Huawei AR <V200R007C00SPC100, Quidway S9300 <V200R009C00, S12700 <V...
CVSS 4.9
CVE-2014-0841
MEDIUM
IBM Rational Focal Point 6.4.0, 6.4.1, 6.5.1, 6.5.2, 6.6.0 - Weak Password Hashing
CVSS 5.3
CVE-2014-9975
CRITICAL
Qualcomm Android - Inadequate Encryption Strength in Full Disk Encryption
CVSS 9.8
CVE-2014-9199
Clorius Controls Java web client <01.00.0009g - Info Disclosure
Details
Vulnerabilities
457