CWE-326

Inadequate Encryption Strength

Parent: CWE-693 - Protection Mechanism Failure

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

448 vulnerabilities with CWE-326
CVE-2023-21145 HIGH
Android - Local Privilege Escalation via ActivityRecord Logic Error
CVSS 7.8
CVE-2023-20942 MEDIUM
Android - Unauthenticated Audio Recording Without Microphone Privacy Indicator
CVSS 5.5
CVE-2023-20185 HIGH
Cisco NX-OS - Inadequate Encryption Strength in CloudSec Feature
CVSS 7.4
CVE-2023-35332 MEDIUM
Windows Remote Desktop Protocol - Security Feature Bypass via Inadequate Encryption Strength
CVSS 6.8
CVE-2023-36748 MEDIUM
RUGGEDCOM ROX -<V2.16.0 - Path Traversal
CVSS 5.9
CVE-2023-34337 HIGH
AMI MegaRAC SP-X - Inadequate Encryption Strength via HMAC
CVSS 7.6
CVE-2023-37301 MEDIUM
MediaWiki < 1.39.3 - AbuseFilter Bypass via SubmitEntityAction
CVSS 5.3
CVE-2023-36539 MEDIUM
Zoom Meetings and Poly CCX Firmware - Information Disclosure
CVSS 5.3
CVE-2023-3243 HIGH
Honeywell Alerton BCM-WEB 3.3.X - Authentication Bypass via Session Hash Spoofing
CVSS 8.3
CVE-2023-32414 HIGH
macOS 13.0-13.3 - Sandbox Escape via Inadequate Encryption Strength
CVSS 8.6
CVE-2023-33283 MEDIUM
Marval MSM <14.19.0.12476 - Info Disclosure
CVSS 5.5
CVE-2023-29549 MEDIUM
Firefox and Focus for Android < 112.0 - Inadequate Encryption Strength via Incorrect Realm Binding
CVSS 6.5
CVE-2023-23597 MEDIUM
Firefox < 109.0 - Arbitrary File Read via Web Security Bypass
CVSS 6.5
CVE-2023-33982 MEDIUM
Bramble Handshake Protocol <1.5.3 - Info Disclosure
CVSS 5.9
CVE-2023-31135 LOW
dgraph < 23.0.0 - Inadequate Encryption Strength in Audit Logs
CVSS 3.3
CVE-2023-1764 MEDIUM
Canon IJ Network Tool <4.7.5 - Info Disclosure
CVSS 6.5
CVE-2023-21109 HIGH
Android 11-13 - Local Privilege Escalation via AccessibilityService Logic Error
CVSS 7.8
CVE-2023-2443 HIGH
Rockwell Automation ThinManager < 13.0 - Inadequate Encryption Strength
CVSS 7.5
CVE-2023-30351 HIGH
Tenda CP3 Firmware V11.10.00.2211041355 - Hard-Coded Root Password with Weak Encryption
CVSS 7.5
CVE-2023-2197 LOW
HashiCorp Vault Enterprise <1.13.2 - Info Disclosure
CVSS 2.5
CVE-2023-28124 MEDIUM
UI Desktop < 0.62.3.0 - Inadequate Encryption Strength
CVSS 5.5
CVE-2023-24502 HIGH
Electra Central AC unit - Info Disclosure
CVSS 7.5
CVE-2023-29054 MEDIUM
SCALANCE -<V5.5.2 - Info Disclosure
CVSS 6.7
CVE-2023-27389 HIGH
CONPROSYS IoT Gateway < 3.7.10 - Authenticated Arbitrary Code Execution via Firmware Update
CVSS 7.2
CVE-2023-27987 CRITICAL
Apache Linkis <=1.3.1 - Inadequate Encryption Strength in Default Token Generation
CVSS 9.1
Details
Vulnerabilities 448