CWE-327

High likelihood

Use of a Broken or Risky Cryptographic Algorithm

Parent: CWE-693 - Protection Mechanism Failure

The product uses a broken or risky cryptographic algorithm or protocol.

669 vulnerabilities with CWE-327
CVE-2022-23539 MEDIUM
jsonwebtoken < 8.5.1 - Use of a Broken or Risky Cryptographic Algorithm via Insecure Key Type Configuration
CVSS 5.9
CVE-2022-22461 MEDIUM
IBM Security Verify Governance 10.0.1 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 5.9
CVE-2022-38391 MEDIUM
IBM Spectrum Control <5.4 - Info Disclosure
CVSS 5.1
CVE-2022-4610 LOW
Click Studios Passwordstate - Cryptographic Algorithm
CVSS 1.9
CVE-2022-46834 MEDIUM
SICK RFU65x < v2.21 - Info Disclosure
CVSS 6.5
CVE-2022-46833 MEDIUM
SICK RFU63x < v2.21 - Info Disclosure
CVSS 6.5
CVE-2022-46832 MEDIUM
SICK RFU62x <2.21 - Info Disclosure
CVSS 6.5
CVE-2022-46140 MEDIUM
Siemens Ruggedcom RM1224 LTE and Scalance Devices - Use of Weak Encryption for Debug Files
CVSS 6.5
CVE-2022-27581 MEDIUM
SICK RFU61x Firmware < 2.25 - Use of a Broken or Risky Cryptographic Algorithm via SSH Interface
CVSS 6.5
CVE-2022-34361 MEDIUM
IBM Sterling Secure Proxy 6.0.3 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 5.9
CVE-2022-34320 MEDIUM
IBM CICS TX 11.1 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 5.9
CVE-2022-34319 MEDIUM
IBM CICS TX 11.7 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 5.9
CVE-2022-45195 MEDIUM
SimpleXMQ < 3.4.0 and SimpleX Chat < 4.2 - Use of a Broken Cryptographic Algorithm in X3DH Key Exchange
CVSS 5.3
CVE-2022-39237 MEDIUM
sylabs/sif < 2.8.1 - Use of a Broken or Risky Cryptographic Algorithm in Digital Signature Verification
CVSS 6.3
CVE-2022-2781 MEDIUM
Octopus Server 3.2.10-2022.1.3154 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 5.3
CVE-2022-35513 HIGH
Blink1Control2 <= 2.2.7 - Weak Password Encryption
CVSS 7.5
CVE-2022-37177 HIGH
HireVue Hiring Platform - Use of a Broken or Risky Cryptographic Algorithm
CVSS 7.5
CVE-2022-38493 HIGH
rhonabwy 0.9.99-1.1.x - Denial of Service via Crafted JWE Token
CVSS 7.5
CVE-2022-30320 MEDIUM
Saia PG5 Controls Suite - Authentication Bypass via S-Bus Weak CRC-16 Credential Hashing
CVSS 4.3
CVE-2022-30273 CRITICAL
Motorola MDLC - Insufficient Verification of Data Authenticity in Legacy Encryption Mode
CVSS 9.8
CVE-2022-29965 MEDIUM
Emerson DeltaV DCS < 2022-04-29 - Weak Cryptographic Algorithm in TELNET Password Generation
CVSS 5.5
CVE-2022-34632 CRITICAL
Rocket-Chip Generator - Use of a Broken or Risky Cryptographic Algorithm in RocketCore.scala
CVSS 9.1
CVE-2022-31157 HIGH
LTI 1.3 Tool Library <5.0 - Info Disclosure
CVSS 7.5
CVE-2022-34757 MEDIUM
Easergy P5 Firmware < 01.401.102 - Use of a Broken or Risky Cryptographic Algorithm in SSH Connection
CVSS 6.7
CVE-2022-30187 MEDIUM
Azure Storage Library < 12.13.0 - Information Disclosure via Broken Cryptographic Algorithm
CVSS 4.7
Details
Vulnerabilities 669
Exploit Likelihood High