CWE-327
High likelihoodUse of a Broken or Risky Cryptographic Algorithm
The product uses a broken or risky cryptographic algorithm or protocol.
669 vulnerabilities with CWE-327
CVE-2022-23539
MEDIUM
jsonwebtoken < 8.5.1 - Use of a Broken or Risky Cryptographic Algorithm via Insecure Key Type Configuration
CVSS 5.9
CVE-2022-22461
MEDIUM
IBM Security Verify Governance 10.0.1 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 5.9
CVE-2022-38391
MEDIUM
IBM Spectrum Control <5.4 - Info Disclosure
CVSS 5.1
CVE-2022-4610
LOW
Click Studios Passwordstate - Cryptographic Algorithm
CVSS 1.9
CVE-2022-46834
MEDIUM
SICK RFU65x < v2.21 - Info Disclosure
CVSS 6.5
CVE-2022-46833
MEDIUM
SICK RFU63x < v2.21 - Info Disclosure
CVSS 6.5
CVE-2022-46832
MEDIUM
SICK RFU62x <2.21 - Info Disclosure
CVSS 6.5
CVE-2022-46140
MEDIUM
Siemens Ruggedcom RM1224 LTE and Scalance Devices - Use of Weak Encryption for Debug Files
CVSS 6.5
CVE-2022-27581
MEDIUM
SICK RFU61x Firmware < 2.25 - Use of a Broken or Risky Cryptographic Algorithm via SSH Interface
CVSS 6.5
CVE-2022-34361
MEDIUM
IBM Sterling Secure Proxy 6.0.3 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 5.9
CVE-2022-34320
MEDIUM
IBM CICS TX 11.1 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 5.9
CVE-2022-34319
MEDIUM
IBM CICS TX 11.7 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 5.9
CVE-2022-45195
MEDIUM
SimpleXMQ < 3.4.0 and SimpleX Chat < 4.2 - Use of a Broken Cryptographic Algorithm in X3DH Key Exchange
CVSS 5.3
CVE-2022-39237
MEDIUM
sylabs/sif < 2.8.1 - Use of a Broken or Risky Cryptographic Algorithm in Digital Signature Verification
CVSS 6.3
CVE-2022-2781
MEDIUM
Octopus Server 3.2.10-2022.1.3154 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 5.3
CVE-2022-35513
HIGH
Blink1Control2 <= 2.2.7 - Weak Password Encryption
CVSS 7.5
CVE-2022-37177
HIGH
HireVue Hiring Platform - Use of a Broken or Risky Cryptographic Algorithm
CVSS 7.5
CVE-2022-38493
HIGH
rhonabwy 0.9.99-1.1.x - Denial of Service via Crafted JWE Token
CVSS 7.5
CVE-2022-30320
MEDIUM
Saia PG5 Controls Suite - Authentication Bypass via S-Bus Weak CRC-16 Credential Hashing
CVSS 4.3
CVE-2022-30273
CRITICAL
Motorola MDLC - Insufficient Verification of Data Authenticity in Legacy Encryption Mode
CVSS 9.8
CVE-2022-29965
MEDIUM
Emerson DeltaV DCS < 2022-04-29 - Weak Cryptographic Algorithm in TELNET Password Generation
CVSS 5.5
CVE-2022-34632
CRITICAL
Rocket-Chip Generator - Use of a Broken or Risky Cryptographic Algorithm in RocketCore.scala
CVSS 9.1
CVE-2022-31157
HIGH
LTI 1.3 Tool Library <5.0 - Info Disclosure
CVSS 7.5
CVE-2022-34757
MEDIUM
Easergy P5 Firmware < 01.401.102 - Use of a Broken or Risky Cryptographic Algorithm in SSH Connection
CVSS 6.7
CVE-2022-30187
MEDIUM
Azure Storage Library < 12.13.0 - Information Disclosure via Broken Cryptographic Algorithm
CVSS 4.7
Details
Vulnerabilities
669
Exploit Likelihood
High