CWE-326

Inadequate Encryption Strength

Parent: CWE-693 - Protection Mechanism Failure

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

448 vulnerabilities with CWE-326
CVE-2024-37034 MEDIUM
Couchbase Server < 7.2.5 and 7.6.0 < 7.6.1 - Inadequate Encryption Strength in Key-Value Service
CVSS 5.9
CVE-2024-38867 MEDIUM
SIPROTEC 5 - Inadequate Encryption Strength via Weak Cipher Support
CVSS 5.9
CVE-2024-38277 MEDIUM
Moodle - Inadequate Key Generation for QR and Auto-Login
CVSS 5.4
CVE-2024-30119 LOW
HCL DRYiCE Optibot Reset Station - Info Disclosure
CVSS 3.7
CVE-2024-34113 MEDIUM
ColdFusion <2023u7, 2021u13 - Info Disclosure
CVSS 5.5
CVE-2024-36823 HIGH
Ninja Core v7.0.0 - Info Disclosure
CVSS 7.5
CVE-2024-28974 HIGH
Dell Data Protection Advisor 19.9 - Denial of Service via Inadequate Encryption Strength
CVSS 7.6
CVE-2024-23580 MEDIUM
HCL DRYiCE Optibot Reset Station - Info Disclosure
CVSS 6.5
CVE-2024-23579 MEDIUM
HCL DRYiCE Optibot Reset Station - Info Disclosure
CVSS 6.5
CVE-2024-29969 HIGH
Brocade SANnav <2.3.0 - Info Disclosure
CVSS 7.5
CVE-2024-29951 MEDIUM
Brocade SANnav <2.3.1, 2.3.0a - Info Disclosure
CVSS 5.7
CVE-2024-29950 HIGH
Brocade SANnav <2.3.1 - Info Disclosure
CVSS 7.5
CVE-2024-3387 MEDIUM
Palo Alto Networks Panorama - Info Disclosure
CVSS 5.3
CVE-2024-28755 MEDIUM
Mbed TLS 3.5.0-3.5.x - Denial of Service via TLS Version Downgrade
CVSS 6.5
CVE-2024-28860 HIGH
Cilium 1.4.0-1.13.13 - Inadequate Encryption Strength in IPsec Transparent Encryption
CVSS 8.0
CVE-2024-25102 HIGH
AppSamvid Software <= 2.0.1 - Inadequate Encryption Strength in User Login Component
CVSS 7.8
CVE-2024-1224 HIGH
USB Pratirodh <= 3.1.2 - Inadequate Encryption Strength in User Login Component
CVSS 7.1
CVE-2024-22894 MEDIUM
Alpha Innotec and Novelan Heat Pumps Firmware < 2.88.3 - Inadequate Encryption Strength in Password Component
CVSS 6.8
CVE-2024-23656 HIGH
dex 2.37.0-2.37.x - Algorithm Downgrade via TLS Config Ignore
CVSS 7.5
CVE-2024-20692 MEDIUM
Microsoft Local Security Authority Subsystem Service - Info Disclosure
CVSS 5.7
CVE-2023-6728 LOW
Nokia SR OS - Buffer Overflow
CVSS 3.3
CVE-2023-37397 LOW
IBM Aspera Faspex 5.0.0-5.0.7 - Inadequate Encryption Strength
CVSS 3.6
CVE-2023-7237 MEDIUM
Lantronix XPort Edge Firmware - Inadequate Encryption Strength in Web Request Headers
CVSS 5.7
CVE-2023-26943 MEDIUM
Yale Keyless Lock v1.0 - Info Disclosure
CVSS 6.5
CVE-2023-26942 MEDIUM
Yale IA-210 Alarm v1.0 - Info Disclosure
CVSS 6.5
Details
Vulnerabilities 448