CWE-327

High likelihood

Use of a Broken or Risky Cryptographic Algorithm

Parent: CWE-693 - Protection Mechanism Failure

The product uses a broken or risky cryptographic algorithm or protocol.

669 vulnerabilities with CWE-327
CVE-2021-36647 MEDIUM
Mbed TLS < 2.16.11 - Use of a Broken or Risky Cryptographic Algorithm in mbedtls_mpi_exp_mod
CVSS 4.7
CVE-2021-27784 MEDIUM
HCL Launch Container - Info Disclosure
CVSS 5.9
CVE-2021-3979 MEDIUM
Red Hat Ceph Storage - Use of a Broken or Risky Cryptographic Algorithm
CVSS 6.5
CVE-2021-20479 HIGH
IBM Cloud Pak System <2.3.3.3 - Info Disclosure
CVSS 7.5
CVE-2021-39082 HIGH
IBM UrbanCode Deploy 7.1.1.2 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 7.5
CVE-2021-39076 HIGH
IBM Security Guardium 10.5 and 11.3 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 7.5
CVE-2021-32593 MEDIUM
FortiWAN < 4.5.8 - Unauthenticated Use of a Broken or Risky Cryptographic Algorithm in Dynamic Tunnel Protocol
CVSS 6.5
CVE-2021-33018 HIGH
Philips Vue PACS <12.2 - Info Disclosure
CVSS 7.5
CVE-2021-27756 HIGH
BigFix Compliance <v2.0.5 - Info Disclosure
CVSS 7.5
CVE-2021-43774 MEDIUM
Fujifilm DocuCentre-VI C4471 1.8 - Info Disclosure
CVSS 4.9
CVE-2021-41835 HIGH
Fresenius Kabi Agilia Link + < 3.0 - Cleartext Transmission of Sensitive Information
CVSS 7.3
CVE-2021-33846 MEDIUM
Fresenius Kabi Vigilant Software Suite - JWT Token Spoofing via Symmetric Key Exposure
CVSS 5.9
CVE-2021-31562 MEDIUM
Fresenius Kabi Agilia Link+ Firmware 3.0 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 6.5
CVE-2021-40006 MEDIUM
HarmonyOS - Use of a Broken or Risky Cryptographic Algorithm
CVSS 4.6
CVE-2021-38921 HIGH
IBM Security Verify <10.0.3 - Info Disclosure
CVSS 7.5
CVE-2021-38542 MEDIUM
Apache James <3.6.1 - Command Injection
CVSS 5.9
CVE-2021-42583 HIGH
Maddy < 0.5.2 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 7.5
CVE-2021-43550 MEDIUM
Philips Patient Information Center iX C.02-C.03 & Efficia CM A.01-C.0x - Weak Cryptographic Algorithm
CVSS 5.9
CVE-2021-45696 CRITICAL
sha2 0.9.7 - Incorrect Hash Calculation via AVX2 Acceleration
CVSS 9.8
CVE-2021-45512 HIGH
NETGEAR Multiple Routers and Extenders - Use of a Broken or Risky Cryptographic Algorithm
CVSS 8.6
CVE-2021-45486 LOW
Linux Kernel < 5.12.4 - Information Disclosure via IPv4 Route Hash Table
CVSS 3.5
CVE-2021-45485 HIGH
Linux Kernel < 5.13.3 - Information Disclosure via IPv6 Source Address Hash Table
CVSS 7.5
CVE-2021-43989 HIGH
mySCADA myPRO <8.20.0 - Info Disclosure
CVSS 7.5
CVE-2021-45451 HIGH
Mbed TLS < 3.1.0 - Policy Bypass and Oracle-Based Decryption via psa_aead_generate_nonce
CVSS 7.5
CVE-2021-45450 HIGH
Mbed TLS < 2.28.0 and 3.x < 3.1.0 - Policy Bypass via PSA Cipher IV Generation
CVSS 7.5
Details
Vulnerabilities 669
Exploit Likelihood High