CWE-327

High likelihood

Use of a Broken or Risky Cryptographic Algorithm

Parent: CWE-693 - Protection Mechanism Failure

The product uses a broken or risky cryptographic algorithm or protocol.

687 vulnerabilities with CWE-327
CVE-2021-33018 HIGH
Philips Vue PACS <12.2 - Info Disclosure
CVSS 7.5
CVE-2021-27756 HIGH
BigFix Compliance <v2.0.5 - Info Disclosure
CVSS 7.5
CVE-2021-43774 MEDIUM
Fujifilm DocuCentre-VI C4471 1.8 - Info Disclosure
CVSS 4.9
CVE-2021-41835 HIGH
Fresenius Kabi Agilia Link + < 3.0 - Cleartext Transmission of Sensitive Information
CVSS 7.3
CVE-2021-33846 MEDIUM
Fresenius Kabi Vigilant Software Suite - JWT Token Spoofing via Symmetric Key Exposure
CVSS 5.9
CVE-2021-31562 MEDIUM
Fresenius Kabi Agilia Link+ Firmware 3.0 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 6.5
CVE-2021-40006 MEDIUM
HarmonyOS - Use of a Broken or Risky Cryptographic Algorithm
CVSS 4.6
CVE-2021-38921 HIGH
IBM Security Verify <10.0.3 - Info Disclosure
CVSS 7.5
CVE-2021-38542 MEDIUM
Apache James <3.6.1 - Command Injection
CVSS 5.9
CVE-2021-42583 HIGH
Maddy < 0.5.2 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 7.5
CVE-2021-43550 MEDIUM
Philips Patient Information Center iX C.02-C.03 & Efficia CM A.01-C.0x - Weak Cryptographic Algorithm
CVSS 5.9
CVE-2021-45696 CRITICAL
sha2 0.9.7 - Incorrect Hash Calculation via AVX2 Acceleration
CVSS 9.8
CVE-2021-45512 HIGH
NETGEAR Multiple Routers and Extenders - Use of a Broken or Risky Cryptographic Algorithm
CVSS 8.6
CVE-2021-45486 LOW
Linux Kernel < 5.12.4 - Information Disclosure via IPv4 Route Hash Table
CVSS 3.5
CVE-2021-45485 HIGH
Linux Kernel < 5.13.3 - Information Disclosure via IPv6 Source Address Hash Table
CVSS 7.5
CVE-2021-43989 HIGH
mySCADA myPRO <8.20.0 - Info Disclosure
CVSS 7.5
CVE-2021-45451 HIGH
Mbed TLS < 3.1.0 - Policy Bypass and Oracle-Based Decryption via psa_aead_generate_nonce
CVSS 7.5
CVE-2021-45450 HIGH
Mbed TLS < 2.28.0 and 3.x < 3.1.0 - Policy Bypass via PSA Cipher IV Generation
CVSS 7.5
CVE-2021-39058 HIGH
IBM Spectrum Copy Data Management < 2.2.13 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 7.5
CVE-2021-39002 HIGH
IBM DB2 9.7, 10.1, 10.5, 11.1, 11.5 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 7.5
CVE-2021-43808 MEDIUM
Laravel <8.75.0, 7.30.6, 6.20.42 - XSS
CVSS 5.3
CVE-2021-22170 MEDIUM
GitLab 11.6.0-13.5.5 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 6.2
CVE-2021-22356 MEDIUM
Huawei IPS/NGFW/USG Modules - Information Disclosure via Weak Cryptographic Algorithm
CVSS 5.9
CVE-2021-41278 MEDIUM
EdgeX Foundry app-functions-sdk-go < 2.1.0 - Use of a Broken or Risky Cryptographic Algorithm in AES Transform
CVSS 5.7
CVE-2021-41263 HIGH
rails_multisite <4 - Info Disclosure
CVSS 8.3
Details
Vulnerabilities 687
Exploit Likelihood High