CWE-327

High likelihood

Use of a Broken or Risky Cryptographic Algorithm

Parent: CWE-693 - Protection Mechanism Failure

The product uses a broken or risky cryptographic algorithm or protocol.

669 vulnerabilities with CWE-327
CVE-2022-2097 MEDIUM
OpenSSL 1.1.1-1.1.1p and 3.0.0-3.0.4 - Data Exposure via AES OCB Mode on 32-bit x86 Platforms
CVSS 5.3
CVE-2022-31230 HIGH
Dell PowerScale OneFS - Cryptographic Algorithm
CVSS 8.1
CVE-2022-28622 HIGH
HPE StoreOnce Software <4.3.2 - RCE
CVSS 7.5
CVE-2022-28166 HIGH
Brocade SANnav < 2.1.1.8 - Use of Static Key Ciphers in TLS/SSL Server
CVSS 7.5
CVE-2022-28382 HIGH
Verbatim drives <2022-03-31 - Info Disclosure
CVSS 7.5
CVE-2022-24296 HIGH
Air Conditioning System <3.21 - Cryptographic Algorithm
CVSS 7.5
CVE-2022-29249 HIGH
JavaEZ 1.6 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 7.5
CVE-2022-29217 HIGH
PyJWT 1.5.0-2.3.0 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 7.4
CVE-2022-30111 MEDIUM
MCK Smartlock 1.0 - Predictable Rolling Code via Insecure Algorithm
CVSS 6.8
CVE-2022-20117 MEDIUM
Android - Local Information Disclosure via Improper Cryptographic Implementation
CVSS 5.5
CVE-2022-28164 MEDIUM
Brocade SANnav < 2.2.0 - Authenticated Password Decryption via Blowfish Encryption
CVSS 6.5
CVE-2022-29161 MEDIUM
XWiki < 13.10.6 - Use of Broken Cryptographic Algorithm in X509 Certificate Generation
CVSS 5.4
CVE-2022-1434 MEDIUM
OpenSSL 3.0.0-3.0.2 - Predictable MAC Key in RC4-MD5 Ciphersuite
CVSS 5.9
CVE-2022-20805 MEDIUM
Cisco Umbrella Secure Web Gateway - Authenticated SSL Decryption Bypass via TLS SNI Extension
CVSS 4.1
CVE-2022-22559 HIGH
Dell PowerScale OneFS <9.3.0 - Info Disclosure
CVSS 7.5
CVE-2022-1252 HIGH
gnuboard <= 5.5.5 - Sensitive Information Exposure via Weak Encryption Algorithm
CVSS 8.2
CVE-2022-26854 HIGH
Dell PowerScale OneFS 8.2.x-9.2.x - Use of a Broken or Risky Cryptographic Algorithm
CVSS 8.1
CVE-2022-22327 HIGH
IBM UrbanCode Deploy <7.1.2 - Info Disclosure
CVSS 7.5
CVE-2022-25218 HIGH
Phicomm K2/K3/K3C/K2G/K2P Firmware - Unauthenticated Remote Code Execution via RSA Padding Oracle Attack
CVSS 8.1
CVE-2022-0377 MEDIUM
LearnPress <4.1.5 - Info Disclosure
CVSS 4.3
CVE-2022-21800 MEDIUM
Airspan Mimosa Management Platform <1.0.3 & C6x/C5x/C5c <2.8.6.1 & A5x <2.5.4.1 Weak Password Hashing
CVSS 6.5
CVE-2021-47712 HIGH
Kentico Xperience < 12.0.102 - Cryptographic Hash Manipulation via URL Hashing Mechanism
CVSS 7.5
CVE-2021-46900 HIGH
Sympa < 6.2.62 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 7.5
CVE-2021-27795 MEDIUM
Brocade Fabric OS - Cryptographic Issue
CVSS 6.4
CVE-2021-38933 MEDIUM
IBM Sterling Connect:Direct for UNIX <1.5 - Info Disclosure
CVSS 5.9
Details
Vulnerabilities 669
Exploit Likelihood High