CWE-326

Inadequate Encryption Strength

Parent: CWE-693 - Protection Mechanism Failure

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

457 vulnerabilities with CWE-326
CVE-2023-21109 HIGH
Android 11-13 - Local Privilege Escalation via AccessibilityService Logic Error
CVSS 7.8
CVE-2023-2443 HIGH
Rockwell Automation ThinManager < 13.0 - Inadequate Encryption Strength
CVSS 7.5
CVE-2023-30351 HIGH
Tenda CP3 Firmware V11.10.00.2211041355 - Hard-Coded Root Password with Weak Encryption
CVSS 7.5
CVE-2023-2197 LOW
HashiCorp Vault Enterprise <1.13.2 - Info Disclosure
CVSS 2.5
CVE-2023-28124 MEDIUM
UI Desktop < 0.62.3.0 - Inadequate Encryption Strength
CVSS 5.5
CVE-2023-24502 HIGH
Electra Central AC unit - Info Disclosure
CVSS 7.5
CVE-2023-29054 MEDIUM
SCALANCE -<V5.5.2 - Info Disclosure
CVSS 6.7
CVE-2023-27389 HIGH
CONPROSYS IoT Gateway < 3.7.10 - Authenticated Arbitrary Code Execution via Firmware Update
CVSS 7.2
CVE-2023-27987 CRITICAL
Apache Linkis <=1.3.1 - Inadequate Encryption Strength in Default Token Generation
CVSS 9.1
CVE-2023-22271 MEDIUM
Experience Manager <6.5.15.0 - Info Disclosure
CVSS 5.3
CVE-2023-23911 HIGH
rocket.chat < 6.0.0 - Improper Access Control via Group Key Manipulation
CVSS 7.5
CVE-2023-21444 HIGH
Samsung Flow < 4.9.14.0 - Improper Cryptographic Implementation
CVSS 7.5
CVE-2023-21443 HIGH
Samsung Flow < 4.9.04 - Improper Cryptographic Implementation
CVSS 7.5
CVE-2022-40745 MEDIUM
IBM Aspera Faspex 5.0.0-5.0.7 - Inadequate Encryption Strength
CVSS 5.5
CVE-2022-32753 MEDIUM
IBM Security Verify Directory 10.0.0 - Inadequate Encryption Strength
CVSS 4.5
CVE-2022-48193 MEDIUM
Softing smartLink SW-HT < 1.30 - Inadequate Encryption Strength
CVSS 5.9
CVE-2022-46783 MEDIUM
Stormshield SSL VPN Client <3.2.0 - Info Disclosure
CVSS 5.3
CVE-2022-45453 HIGH
Acronis Cyber Protect 15 < 30984 - Weak TLS/SSL Cipher Suites
CVSS 7.5
CVE-2022-4048 HIGH
CODESYS Dev Sys <V3.5.18.40 - Info Disclosure
CVSS 7.7
CVE-2022-45141 CRITICAL
Samba < 4.15.13 - Inadequate Encryption Strength in Kerberos Ticket Issuance
CVSS 9.8
CVE-2022-34385 MEDIUM
Dell SupportAssist < 3.11.4 (Home) / < 3.2.0 (Business) - Sensitive Info Exposure via Weak Crypto
CVSS 5.5
CVE-2022-43922 MEDIUM
IBM App Connect Enterprise Certified Container <6.2 - Info Disclosure
CVSS 5.3
CVE-2022-2582 MEDIUM
AWS S3 Crypto SDK - Info Disclosure
CVSS 4.3
CVE-2022-24116 CRITICAL
General Electric Renewable Energy <8.3.0 - Info Disclosure
CVSS 9.8
CVE-2022-47931 CRITICAL
iofinnet tss-lib < 2.0.0 - Hash Collision via Inadequate Encryption Strength
CVSS 9.1
Details
Vulnerabilities 457