The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
448 vulnerabilities with CWE-326
CVE-2024-37034
MEDIUM
Couchbase Server < 7.2.5 and 7.6.0 < 7.6.1 - Inadequate Encryption Strength in Key-Value Service
CVSS 5.9
CVE-2024-38867
MEDIUM
SIPROTEC 5 - Inadequate Encryption Strength via Weak Cipher Support
CVSS 5.9
CVE-2024-38277
MEDIUM
Moodle - Inadequate Key Generation for QR and Auto-Login
CVSS 5.4
CVE-2024-30119
LOW
HCL DRYiCE Optibot Reset Station - Info Disclosure
CVSS 3.7
CVE-2024-34113
MEDIUM
ColdFusion <2023u7, 2021u13 - Info Disclosure
CVSS 5.5
CVE-2024-36823
HIGH
Ninja Core v7.0.0 - Info Disclosure
CVSS 7.5
CVE-2024-28974
HIGH
Dell Data Protection Advisor 19.9 - Denial of Service via Inadequate Encryption Strength
CVSS 7.6
CVE-2024-23580
MEDIUM
HCL DRYiCE Optibot Reset Station - Info Disclosure
CVSS 6.5
CVE-2024-23579
MEDIUM
HCL DRYiCE Optibot Reset Station - Info Disclosure
CVSS 6.5
CVE-2024-29969
HIGH
Brocade SANnav <2.3.0 - Info Disclosure
CVSS 7.5
CVE-2024-29951
MEDIUM
Brocade SANnav <2.3.1, 2.3.0a - Info Disclosure
CVSS 5.7
CVE-2024-29950
HIGH
Brocade SANnav <2.3.1 - Info Disclosure
CVSS 7.5
CVE-2024-3387
MEDIUM
Palo Alto Networks Panorama - Info Disclosure
CVSS 5.3
CVE-2024-28755
MEDIUM
Mbed TLS 3.5.0-3.5.x - Denial of Service via TLS Version Downgrade
CVSS 6.5
CVE-2024-28860
HIGH
Cilium 1.4.0-1.13.13 - Inadequate Encryption Strength in IPsec Transparent Encryption
CVSS 8.0
CVE-2024-25102
HIGH
AppSamvid Software <= 2.0.1 - Inadequate Encryption Strength in User Login Component
CVSS 7.8
CVE-2024-1224
HIGH
USB Pratirodh <= 3.1.2 - Inadequate Encryption Strength in User Login Component
CVSS 7.1
CVE-2024-22894
MEDIUM
Alpha Innotec and Novelan Heat Pumps Firmware < 2.88.3 - Inadequate Encryption Strength in Password Component
CVSS 6.8
CVE-2024-23656
HIGH
dex 2.37.0-2.37.x - Algorithm Downgrade via TLS Config Ignore
CVSS 7.5
CVE-2024-20692
MEDIUM
Microsoft Local Security Authority Subsystem Service - Info Disclosure
CVSS 5.7
CVE-2023-6728
LOW
Nokia SR OS - Buffer Overflow
CVSS 3.3
CVE-2023-37397
LOW
IBM Aspera Faspex 5.0.0-5.0.7 - Inadequate Encryption Strength
CVSS 3.6
CVE-2023-7237
MEDIUM
Lantronix XPort Edge Firmware - Inadequate Encryption Strength in Web Request Headers
CVSS 5.7
CVE-2023-26943
MEDIUM
Yale Keyless Lock v1.0 - Info Disclosure
CVSS 6.5
CVE-2023-26942
MEDIUM
Yale IA-210 Alarm v1.0 - Info Disclosure
CVSS 6.5
Details
Vulnerabilities
448