CWE-326

Inadequate Encryption Strength

Parent: CWE-693 - Protection Mechanism Failure

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

457 vulnerabilities with CWE-326
CVE-2024-39928 HIGH
Apache Linkis <= 1.5.0 - Inadequate Encryption Strength in Spark EngineConn Token Generation
CVSS 7.5
CVE-2024-45394 HIGH
Authenticator <7.0.0 - Info Disclosure
CVSS 8.8
CVE-2024-21787 MEDIUM
BMRA software < 22.08 - Authenticated Privilege Escalation via Inadequate Encryption Strength
CVSS 6.4
CVE-2024-41681 MEDIUM
Siemens Location Intelligence < 4.4 - Unauthenticated Weak Cipher Configuration
CVSS 6.7
CVE-2024-5800 HIGH
B&R Automation Runtime < 6.0.2 - Inadequate Encryption Strength in SSL/TLS Stack
CVSS 7.5
CVE-2024-42163 HIGH
FIWARE Keyrock <= 8.4 - Inadequate Encryption Strength in Password Reset Token
CVSS 8.3
CVE-2024-21881 HIGH
Enphase Envoy 4.x and 5.x - Authenticated OS Command Execution via Encrypted Package Upload
CVE-2024-40719 MEDIUM
CHANGING TCBServiSign - Weak Authorization Key Server Spoofing
CVSS 6.5
CVE-2024-32758 HIGH
exacqVision Client and Server < 24.06 - Inadequate Encryption Strength
CVSS 7.5
CVE-2024-37034 MEDIUM
Couchbase Server < 7.2.5 and 7.6.0 < 7.6.1 - Inadequate Encryption Strength in Key-Value Service
CVSS 5.9
CVE-2024-38867 MEDIUM
SIPROTEC 5 - Inadequate Encryption Strength via Weak Cipher Support
CVSS 5.9
CVE-2024-38277 MEDIUM
Moodle - Inadequate Key Generation for QR and Auto-Login
CVSS 5.4
CVE-2024-30119 LOW
HCL DRYiCE Optibot Reset Station - Info Disclosure
CVSS 3.7
CVE-2024-34113 MEDIUM
ColdFusion <2023u7, 2021u13 - Info Disclosure
CVSS 5.5
CVE-2024-36823 HIGH
Ninja Core v7.0.0 - Info Disclosure
CVSS 7.5
CVE-2024-28974 HIGH
Dell Data Protection Advisor 19.9 - Denial of Service via Inadequate Encryption Strength
CVSS 7.6
CVE-2024-23580 MEDIUM
HCL DRYiCE Optibot Reset Station - Info Disclosure
CVSS 6.5
CVE-2024-23579 MEDIUM
HCL DRYiCE Optibot Reset Station - Info Disclosure
CVSS 6.5
CVE-2024-29969 HIGH
Brocade SANnav <2.3.0 - Info Disclosure
CVSS 7.5
CVE-2024-29951 MEDIUM
Brocade SANnav <2.3.1, 2.3.0a - Info Disclosure
CVSS 5.7
CVE-2024-29950 HIGH
Brocade SANnav <2.3.1 - Info Disclosure
CVSS 7.5
CVE-2024-3387 MEDIUM
Palo Alto Networks Panorama - Info Disclosure
CVSS 5.3
CVE-2024-28755 MEDIUM
Mbed TLS 3.5.0-3.5.x - Denial of Service via TLS Version Downgrade
CVSS 6.5
CVE-2024-28860 HIGH
Cilium 1.4.0-1.13.13 - Inadequate Encryption Strength in IPsec Transparent Encryption
CVSS 8.0
CVE-2024-25102 HIGH
AppSamvid Software <= 2.0.1 - Inadequate Encryption Strength in User Login Component
CVSS 7.8
Details
Vulnerabilities 457