CWE-326

Inadequate Encryption Strength

Parent: CWE-693 - Protection Mechanism Failure

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

448 vulnerabilities with CWE-326
CVE-2022-35931 LOW
Nextcloud <22.2.10, <23.0.7, <24.0.3 - Info Disclosure
CVSS 2.7
CVE-2022-2758 MEDIUM
LS Electric XG5000 < V4.0 and XGK/XGI/XGR/XGB PLCs - Inadequate Encryption Strength
CVSS 6.5
CVE-2022-36555 CRITICAL
Hytec Inter HWL-2511-SS <v1.05 - Info Disclosure
CVSS 9.8
CVE-2022-21139 HIGH
Intel Wireless Firmware < 22.120 - Unauthenticated Privilege Escalation via Inadequate Encryption Strength
CVSS 8.8
CVE-2022-30285 CRITICAL
Quest KACE Systems Management Appliance <= 12.0 - Authentication Bypass via Hash Collision
CVSS 9.8
CVE-2022-26307 HIGH
LibreOffice 7.2.0-7.2.6 and 7.3.0-7.3.2 - Inadequate Encryption Strength in Password Storage
CVSS 8.8
CVE-2022-26306 HIGH
LibreOffice 7.2.0-7.2.6 and 7.3.0 - Inadequate Encryption Strength in Stored Passwords
CVSS 7.5
CVE-2022-22453 HIGH
IBM Security Verify Identity Manager 10.0 - Info Disclosure
CVSS 7.5
CVE-2022-22464 HIGH
IBM Security Access Manager Appliance - Info Disclosure
CVSS 7.5
CVE-2022-31459 HIGH
Owl Labs Meeting Owl <5.2.0.15 - Info Disclosure
CVSS 7.4
CVE-2022-29249 HIGH
JavaEZ 1.6 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 7.5
CVE-2022-29161 MEDIUM
XWiki < 13.10.6 - Use of Broken Cryptographic Algorithm in X509 Certificate Generation
CVSS 5.4
CVE-2022-22368 HIGH
IBM Spectrum Scale <5.1.4 - Info Disclosure
CVSS 7.5
CVE-2022-29566 HIGH
Bulletproofs - Inadequate Encryption Strength via Frozen Heart Issue
CVSS 8.1
CVE-2022-1318 MEDIUM
Hills ComNav < 3002-19 - Inadequate Encryption Strength in Local Network Configuration Traffic
CVSS 6.2
CVE-2022-20677 MEDIUM
Cisco IOx - Path Traversal
CVSS 5.5
CVE-2022-25156 HIGH
Mitsubishielectric Fx5uc Firmware - Weak Encryption
CVSS 8.1
CVE-2022-25012 MEDIUM
Argus Surveillance DVR 4.0 - Inadequate Encryption Strength
CVSS 5.5
CVE-2022-22321 MEDIUM
IBM MQ Appliance <9.2 - Info Disclosure
CVSS 5.5
CVE-2022-21800 MEDIUM
Airspan Mimosa Management Platform <1.0.3 & C6x/C5x/C5c <2.8.6.1 & A5x <2.5.4.1 Weak Password Hashing
CVSS 6.5
CVE-2022-24318 HIGH
ClearSCADA, EcoStruxure Geo SCADA Expert - Info Disclosure
CVSS 7.5
CVE-2022-21653 MEDIUM
jawn < 1.3.2 - Denial of Service via Hash Collision in SimpleFacade and MutableFacade
CVSS 5.9
CVE-2021-38121 HIGH
NetIQ Advance Auth <6.3.5.1 - Info Disclosure
CVSS 8.3
CVE-2021-40341 HIGH
Hitachi Energy FOXMAN-UN - Info Disclosure
CVSS 7.1
CVE-2021-35226 MEDIUM
Network Configuration Manager - Info Disclosure
CVSS 6.5
Details
Vulnerabilities 448