CWE-326

Inadequate Encryption Strength

Parent: CWE-693 - Protection Mechanism Failure

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

457 vulnerabilities with CWE-326
CVE-2025-46833 MEDIUM
Python Encryption <6ce60b1 - Info Disclosure
CVE-2025-20667 HIGH
MediaTek LR12A, LR13, NR15, NR16, NR17, NR17R - Remote Information Disclosure via Rogue Base Station
CVSS 7.5
CVE-2025-46626 HIGH
Tenda RX2 Pro 16.03.30.14 - Info Disclosure
CVSS 7.3
CVE-2025-2516 CRITICAL
WPS Office >=12.1.0.18276 - Weak Cryptographic Key Pair in Signature Verification
CVE-2025-2349 LOW
IROAD Dash Cam FX2 <20250308 - Info Disclosure
CVSS 3.1
CVE-2024-23564 CRITICAL
HCL Software Aftermarket Epc - Inadequate Encryption Strength
CVSS 9.1
CVE-2024-38341 MEDIUM
IBM Sterling Secure Proxy <6.2.0.1 - Info Disclosure
CVSS 5.9
CVE-2024-42177 LOW
HCL MyXalytics - Inadequate Encryption Strength via SSL/TLS Protocol
CVSS 2.6
CVE-2024-54089 HIGH
APOGEE PXC Series - Info Disclosure
CVSS 7.5
CVE-2024-10026 MEDIUM
gVisor < 20231030.0 - Weak Hashing and Small Seed/Secret Sizes
CVSS 5.3
CVE-2024-13454 MEDIUM
Easy-RSA 3.0.5-3.1.7 - Info Disclosure
CVSS 5.3
CVE-2024-13026 MEDIUM
Roche Diagnostics Algorithm Suite < 2.1.2 - Inadequate Encryption Strength in Authentication Mechanism
CVE-2024-45719 LOW
Apache Answer <= 1.4.0 - Inadequate Encryption Strength via UUID v1 Token Generation
CVSS 2.6
CVE-2024-52318 MEDIUM
Apache Tomcat <11.0.1-9.0.97 - Memory Corruption
CVSS 6.1
CVE-2024-52317 MEDIUM
Apache Tomcat <11.0.0-M26,<10.1.30,<9.0.95 - Memory Corruption
CVSS 6.5
CVE-2024-43382 MEDIUM
Snowflake JDBC 3.2.6-3.19.1 - Inadequate Encryption Strength in Client-Side Encryption
CVSS 5.9
CVE-2024-50550 HIGH
LiteSpeed Cache <= 6.5.1 - Privilege Escalation via Incorrect Privilege Assignment
CVSS 8.1
CVE-2024-45259 MEDIUM
GL-iNet Firmware - Unauthenticated Arbitrary File Deletion via Download Interface
CVSS 6.5
CVE-2024-45273 HIGH
Helmholz and mbconnectline Devices - Weak Encryption Leading to Information Disclosure
CVSS 8.4
CVE-2024-41594 HIGH
DrayTek Vigor310 <= 4.3.2.6 - Inadequate Encryption Strength via Static PRNG Seed
CVSS 7.5
CVE-2024-33662 HIGH
Portainer < 2.20.2 - Inadequate Encryption Strength in AesEncrypt Function
CVSS 7.5
CVE-2024-8455 HIGH
PLANET Technology - Password Cracking
CVSS 8.1
CVE-2024-47182 MEDIUM
Dozzle < 8.5.3 - Inadequate Encryption Strength for Password Hashing
CVSS 4.8
CVE-2024-22892 HIGH
OpenSlides 4.0.15 - Info Disclosure
CVSS 7.5
CVE-2024-40761 MEDIUM
Apache Answer <1.3.5 - Info Disclosure
CVSS 5.3
Details
Vulnerabilities 457