CWE-327
High likelihoodUse of a Broken or Risky Cryptographic Algorithm
The product uses a broken or risky cryptographic algorithm or protocol.
687 vulnerabilities with CWE-327
CVE-2021-20566
HIGH
IBM Resilient SOAR V38.0 - Info Disclosure
CVSS 7.5
CVE-2021-22212
MEDIUM
ntpsec - Use of a Broken or Risky Cryptographic Algorithm via Key Generation with '#' Characters
CVSS 4.0
CVE-2021-22738
CRITICAL
spaceLYnk and homeLYnk < 2.6.0 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 9.8
CVE-2021-20419
HIGH
IBM Security Guardium 11.2 - Info Disclosure
CVSS 7.5
CVE-2021-27457
HIGH
Emerson Rosemount X-STREAM - Info Disclosure
CVSS 7.5
CVE-2021-29694
HIGH
IBM Spectrum Protect Plus 10.1.0-10.1.7 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 7.5
CVE-2021-20305
HIGH
Nettle < 3.7.2 - Incorrect Signature Verification via Out-of-Range ECC Scalar
CVSS 8.1
CVE-2021-3446
MEDIUM
libtpms < 0.8.2 - Weak Cryptographic IV Handling in OpenSSL Integration
CVSS 5.5
CVE-2021-20441
MEDIUM
IBM Security Verify Bridge - Info Disclosure
CVSS 5.9
CVE-2021-23839
LOW
OpenSSL 1.0.2s-1.0.2x - Version Rollback Attack via RSA Padding Check Inversion
CVSS 3.7
CVE-2021-20406
LOW
IBM Security Verify Information Queue <1.0.8 - Info Disclosure
CVSS 2.2
CVE-2021-25763
MEDIUM
JetBrains Ktor < 1.4.2 - Use of Weak Cryptographic Cipher Suites
CVSS 5.3
CVE-2020-11916
MEDIUM
Siime Eye 14.1.00000001.3.330.0.0.3.14 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 6.3
CVE-2020-4874
MEDIUM
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 5.9
CVE-2020-36516
MEDIUM
Linux Kernel < 5.6.11 - TCP Session Injection via Mixed IPID Assignment
CVSS 5.9
CVE-2020-14264
LOW
HCL Traveler Companion < 12.0.0 - Weak Cryptographic Process via MobileIron AppConnect SDK
CVSS 3.9
CVE-2020-36363
CRITICAL
Amazon CloudFront TLSv1.2_2019 - Use of Weak TLS Ciphers
CVSS 9.8
CVE-2020-26515
HIGH
Intland codeBeamer ALM <10.1.SP4 - Info Disclosure
CVSS 7.5
CVE-2020-26140
MEDIUM
ALFA AWUS036H Firmware - Use of a Broken or Risky Cryptographic Algorithm
CVSS 6.5
CVE-2020-24588
LOW
IEEE 802.11 - Unauthenticated Packet Injection via A-MSDU Flag Manipulation
CVSS 3.5
CVE-2020-24587
LOW
IEEE 802.11 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 2.6
CVE-2020-4965
HIGH
IBM Collaborative Lifecycle Management - Use of a Broken or Risky Cryptographic Algorithm
CVSS 7.5
CVE-2020-36315
MEDIUM
RELIC < 2020-08-01 - RSA PKCS#1 v1.5 Signature Forgery via Inadequate Padding Validation
CVSS 5.3
CVE-2020-4831
HIGH
IBM DataPower Gateway 10.0.0.0-10.0.1.0 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 7.5
CVE-2020-12702
MEDIUM
eWeLink < 4.9.1 (iOS) and < 4.9.2 (Android) - Weak Encryption in Quick Pairing Mode
CVSS 4.6
Details
Vulnerabilities
687
Exploit Likelihood
High