CWE-326

Inadequate Encryption Strength

Parent: CWE-693 - Protection Mechanism Failure

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

448 vulnerabilities with CWE-326
CVE-2023-22271 MEDIUM
Experience Manager <6.5.15.0 - Info Disclosure
CVSS 5.3
CVE-2023-23911 HIGH
rocket.chat < 6.0.0 - Improper Access Control via Group Key Manipulation
CVSS 7.5
CVE-2023-21444 HIGH
Samsung Flow < 4.9.14.0 - Improper Cryptographic Implementation
CVSS 7.5
CVE-2023-21443 HIGH
Samsung Flow < 4.9.04 - Improper Cryptographic Implementation
CVSS 7.5
CVE-2022-40745 MEDIUM
IBM Aspera Faspex 5.0.0-5.0.7 - Inadequate Encryption Strength
CVSS 5.5
CVE-2022-32753 MEDIUM
IBM Security Verify Directory 10.0.0 - Inadequate Encryption Strength
CVSS 4.5
CVE-2022-48193 MEDIUM
Softing smartLink SW-HT < 1.30 - Inadequate Encryption Strength
CVSS 5.9
CVE-2022-46783 MEDIUM
Stormshield SSL VPN Client <3.2.0 - Info Disclosure
CVSS 5.3
CVE-2022-45453 HIGH
Acronis Cyber Protect 15 < 30984 - Weak TLS/SSL Cipher Suites
CVSS 7.5
CVE-2022-4048 HIGH
CODESYS Dev Sys <V3.5.18.40 - Info Disclosure
CVSS 7.7
CVE-2022-45141 CRITICAL
Samba < 4.15.13 - Inadequate Encryption Strength in Kerberos Ticket Issuance
CVSS 9.8
CVE-2022-34385 MEDIUM
Dell SupportAssist < 3.11.4 (Home) / < 3.2.0 (Business) - Sensitive Info Exposure via Weak Crypto
CVSS 5.5
CVE-2022-43922 MEDIUM
IBM App Connect Enterprise Certified Container <6.2 - Info Disclosure
CVSS 5.3
CVE-2022-2582 MEDIUM
AWS S3 Crypto SDK - Info Disclosure
CVSS 4.3
CVE-2022-24116 CRITICAL
General Electric Renewable Energy <8.3.0 - Info Disclosure
CVSS 9.8
CVE-2022-47931 CRITICAL
iofinnet tss-lib < 2.0.0 - Hash Collision via Inadequate Encryption Strength
CVSS 9.1
CVE-2022-38659 MEDIUM
HCL BigFix Platform 9.5-9.5.19 - Inadequate Encryption Strength of Operator Credentials
CVSS 6.0
CVE-2022-46825 MEDIUM
JetBrains IntelliJ IDEA <2022.3 - Info Disclosure
CVSS 4.0
CVE-2022-2640 HIGH
Horner Automation's RCC 972 <15.40 - Info Disclosure
CVSS 7.5
CVE-2022-4036 MEDIUM
WordPress Appointment Hour Booking <1.3.72 - Auth Bypass
CVSS 5.3
CVE-2022-45379 HIGH
Jenkins Script Security Plugin < 1190.v65867a_a_47126 - Inadequate Encryption Strength via SHA-1 Hash Collision
CVSS 7.5
CVE-2022-41209 MEDIUM
SAP Customer Data Cloud Gigya mobile app for Android <7.4 - Info Di...
CVSS 5.2
CVE-2022-3433 MEDIUM
aeson < 2.0.1.0 - Denial of Service via Hash Collision in JSON Input
CVSS 6.5
CVE-2022-3273 CRITICAL
GitHub ikus060/rdiffweb <2.5.0a4 - DoS
CVSS 9.8
CVE-2022-29835 MEDIUM
WD Discovery < 4.4.396 - Inadequate Encryption Strength via SHA-1 Signed Executables
CVSS 5.3
Details
Vulnerabilities 448