The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
457 vulnerabilities with CWE-326
CVE-2023-21109
HIGH
Android 11-13 - Local Privilege Escalation via AccessibilityService Logic Error
CVSS 7.8
CVE-2023-2443
HIGH
Rockwell Automation ThinManager < 13.0 - Inadequate Encryption Strength
CVSS 7.5
CVE-2023-30351
HIGH
Tenda CP3 Firmware V11.10.00.2211041355 - Hard-Coded Root Password with Weak Encryption
CVSS 7.5
CVE-2023-2197
LOW
HashiCorp Vault Enterprise <1.13.2 - Info Disclosure
CVSS 2.5
CVE-2023-28124
MEDIUM
UI Desktop < 0.62.3.0 - Inadequate Encryption Strength
CVSS 5.5
CVE-2023-24502
HIGH
Electra Central AC unit - Info Disclosure
CVSS 7.5
CVE-2023-29054
MEDIUM
SCALANCE -<V5.5.2 - Info Disclosure
CVSS 6.7
CVE-2023-27389
HIGH
CONPROSYS IoT Gateway < 3.7.10 - Authenticated Arbitrary Code Execution via Firmware Update
CVSS 7.2
CVE-2023-27987
CRITICAL
Apache Linkis <=1.3.1 - Inadequate Encryption Strength in Default Token Generation
CVSS 9.1
CVE-2023-22271
MEDIUM
Experience Manager <6.5.15.0 - Info Disclosure
CVSS 5.3
CVE-2023-23911
HIGH
rocket.chat < 6.0.0 - Improper Access Control via Group Key Manipulation
CVSS 7.5
CVE-2023-21444
HIGH
Samsung Flow < 4.9.14.0 - Improper Cryptographic Implementation
CVSS 7.5
CVE-2023-21443
HIGH
Samsung Flow < 4.9.04 - Improper Cryptographic Implementation
CVSS 7.5
CVE-2022-40745
MEDIUM
IBM Aspera Faspex 5.0.0-5.0.7 - Inadequate Encryption Strength
CVSS 5.5
CVE-2022-32753
MEDIUM
IBM Security Verify Directory 10.0.0 - Inadequate Encryption Strength
CVSS 4.5
CVE-2022-48193
MEDIUM
Softing smartLink SW-HT < 1.30 - Inadequate Encryption Strength
CVSS 5.9
CVE-2022-46783
MEDIUM
Stormshield SSL VPN Client <3.2.0 - Info Disclosure
CVSS 5.3
CVE-2022-45453
HIGH
Acronis Cyber Protect 15 < 30984 - Weak TLS/SSL Cipher Suites
CVSS 7.5
CVE-2022-4048
HIGH
CODESYS Dev Sys <V3.5.18.40 - Info Disclosure
CVSS 7.7
CVE-2022-45141
CRITICAL
Samba < 4.15.13 - Inadequate Encryption Strength in Kerberos Ticket Issuance
CVSS 9.8
CVE-2022-34385
MEDIUM
Dell SupportAssist < 3.11.4 (Home) / < 3.2.0 (Business) - Sensitive Info Exposure via Weak Crypto
CVSS 5.5
CVE-2022-43922
MEDIUM
IBM App Connect Enterprise Certified Container <6.2 - Info Disclosure
CVSS 5.3
CVE-2022-2582
MEDIUM
AWS S3 Crypto SDK - Info Disclosure
CVSS 4.3
CVE-2022-24116
CRITICAL
General Electric Renewable Energy <8.3.0 - Info Disclosure
CVSS 9.8
CVE-2022-47931
CRITICAL
iofinnet tss-lib < 2.0.0 - Hash Collision via Inadequate Encryption Strength
CVSS 9.1
Details
Vulnerabilities
457