The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
448 vulnerabilities with CWE-326
CVE-2023-22271
MEDIUM
Experience Manager <6.5.15.0 - Info Disclosure
CVSS 5.3
CVE-2023-23911
HIGH
rocket.chat < 6.0.0 - Improper Access Control via Group Key Manipulation
CVSS 7.5
CVE-2023-21444
HIGH
Samsung Flow < 4.9.14.0 - Improper Cryptographic Implementation
CVSS 7.5
CVE-2023-21443
HIGH
Samsung Flow < 4.9.04 - Improper Cryptographic Implementation
CVSS 7.5
CVE-2022-40745
MEDIUM
IBM Aspera Faspex 5.0.0-5.0.7 - Inadequate Encryption Strength
CVSS 5.5
CVE-2022-32753
MEDIUM
IBM Security Verify Directory 10.0.0 - Inadequate Encryption Strength
CVSS 4.5
CVE-2022-48193
MEDIUM
Softing smartLink SW-HT < 1.30 - Inadequate Encryption Strength
CVSS 5.9
CVE-2022-46783
MEDIUM
Stormshield SSL VPN Client <3.2.0 - Info Disclosure
CVSS 5.3
CVE-2022-45453
HIGH
Acronis Cyber Protect 15 < 30984 - Weak TLS/SSL Cipher Suites
CVSS 7.5
CVE-2022-4048
HIGH
CODESYS Dev Sys <V3.5.18.40 - Info Disclosure
CVSS 7.7
CVE-2022-45141
CRITICAL
Samba < 4.15.13 - Inadequate Encryption Strength in Kerberos Ticket Issuance
CVSS 9.8
CVE-2022-34385
MEDIUM
Dell SupportAssist < 3.11.4 (Home) / < 3.2.0 (Business) - Sensitive Info Exposure via Weak Crypto
CVSS 5.5
CVE-2022-43922
MEDIUM
IBM App Connect Enterprise Certified Container <6.2 - Info Disclosure
CVSS 5.3
CVE-2022-2582
MEDIUM
AWS S3 Crypto SDK - Info Disclosure
CVSS 4.3
CVE-2022-24116
CRITICAL
General Electric Renewable Energy <8.3.0 - Info Disclosure
CVSS 9.8
CVE-2022-47931
CRITICAL
iofinnet tss-lib < 2.0.0 - Hash Collision via Inadequate Encryption Strength
CVSS 9.1
CVE-2022-38659
MEDIUM
HCL BigFix Platform 9.5-9.5.19 - Inadequate Encryption Strength of Operator Credentials
CVSS 6.0
CVE-2022-46825
MEDIUM
JetBrains IntelliJ IDEA <2022.3 - Info Disclosure
CVSS 4.0
CVE-2022-2640
HIGH
Horner Automation's RCC 972 <15.40 - Info Disclosure
CVSS 7.5
CVE-2022-4036
MEDIUM
WordPress Appointment Hour Booking <1.3.72 - Auth Bypass
CVSS 5.3
CVE-2022-45379
HIGH
Jenkins Script Security Plugin < 1190.v65867a_a_47126 - Inadequate Encryption Strength via SHA-1 Hash Collision
CVSS 7.5
CVE-2022-41209
MEDIUM
SAP Customer Data Cloud Gigya mobile app for Android <7.4 - Info Di...
CVSS 5.2
CVE-2022-3433
MEDIUM
aeson < 2.0.1.0 - Denial of Service via Hash Collision in JSON Input
CVSS 6.5
CVE-2022-3273
CRITICAL
GitHub ikus060/rdiffweb <2.5.0a4 - DoS
CVSS 9.8
CVE-2022-29835
MEDIUM
WD Discovery < 4.4.396 - Inadequate Encryption Strength via SHA-1 Signed Executables
CVSS 5.3
Details
Vulnerabilities
448