CWE-326

Inadequate Encryption Strength

Parent: CWE-693 - Protection Mechanism Failure

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

448 vulnerabilities with CWE-326
CVE-2016-3034 MEDIUM
IBM AppScan Source - Inadequate Encryption Strength via Unsalted One-Way Hash
CVSS 4.4
CVE-2016-7798 HIGH
openssl < 2.0.0 - Inadequate Encryption Strength in GCM Mode
CVSS 7.5
CVE-2016-10104 MEDIUM
Hitek Software Automize - Info Disclosure
CVSS 5.9
CVE-2016-10103 HIGH
Hitek Software Automize <11.14 - Info Disclosure
CVSS 8.1
CVE-2016-10102 HIGH
Hitek Software Automize <11.14 - Info Disclosure
CVSS 8.1
CVE-2016-10101 HIGH
Hitek Software Automize <11.x - Info Disclosure
CVSS 8.1
CVE-2016-5804 CRITICAL
Moxa MGate MB3180 < 1.8, MB3280 < 2.7, MB3480 < 2.6, MB3170 < 2.5, MB3270 < 2.7 - Weak Encryption Authentication Bypass
CVSS 9.8
CVE-2015-5361 MEDIUM
Juniper Junos - Inadequate Encryption Strength in FTP ALG FTPS Extensions
CVSS 6.5
CVE-2015-4953 MEDIUM
IBM BigFix Remote Control - Inadequate Encryption Strength
CVSS 4.8
CVE-2015-7449 LOW
IBM Rational <4.0.7-6.0.2 - Privilege Escalation
CVSS 3.3
CVE-2015-0575 CRITICAL
Qualcomm Android Products - Inadequate Encryption Strength via Default Ciphersuite Configuration
CVSS 9.8
CVE-2015-8086 MEDIUM
Huawei AR <V200R007C00SPC100, Quidway S9300 <V200R009C00, S12700 <V...
CVSS 4.9
CVE-2015-8085 MEDIUM
Huawei AR <V200R007C00SPC100, Quidway S9300 <V200R009C00, S12700 <V...
CVSS 4.9
CVE-2014-0841 MEDIUM
IBM Rational Focal Point 6.4.0, 6.4.1, 6.5.1, 6.5.2, 6.6.0 - Weak Password Hashing
CVSS 5.3
CVE-2014-9975 CRITICAL
Qualcomm Android - Inadequate Encryption Strength in Full Disk Encryption
CVSS 9.8
CVE-2014-9199
Clorius Controls Java web client <01.00.0009g - Info Disclosure
CVE-2014-2381
Schneider Electric Wonderware Information Server - Info Disclosure
CVE-2014-2380
Schneider Electric Wonderware Information Server - Info Disclosure
CVE-2014-0224 HIGH
SSL Labs API Client
CVSS 7.4
CVE-2014-1491
Mozilla Network Security Services < 3.15.4 - Inadequate Encryption Strength in Diffie-Hellman Key Exchange
CVE-2013-7287 CRITICAL
MobileIron VSP <5.9.1 and Sentry <5.0 - Info Disclosure
CVSS 9.8
CVE-2013-7286 HIGH
MobileIron VSP < 5.9.1 - Info Disclosure
CVSS 7.5
CVE-2013-2166 CRITICAL
python-keystoneclient 0.2.3-0.2.5 - Inadequate Encryption Strength in Memcache Middleware
CVSS 9.8
CVE-2013-7484 HIGH
Zabbix < 5.0 - Inadequate Encryption Strength for User Passwords
CVSS 7.5
CVE-2013-4104 HIGH
Cryptocat < 2.0.22 - Inadequate Encryption Strength in Socialist Millionnaire Protocol
CVSS 7.5
Details
Vulnerabilities 448