CWE-327

High likelihood

Use of a Broken or Risky Cryptographic Algorithm

Parent: CWE-693 - Protection Mechanism Failure

The product uses a broken or risky cryptographic algorithm or protocol.

669 vulnerabilities with CWE-327
CVE-2020-10601 HIGH
VISAM VBASE Editor <11.5.0.2 - Privilege Escalation
CVSS 7.8
CVE-2020-11500 HIGH
Zoom Meetings < 4.6.9 - Use of ECB Mode in AES Encryption
CVSS 7.5
CVE-2020-7001 HIGH
Moxa EDS-G516E and EDS-510E Firmware < 5.2 - Weak Cryptographic Algorithm
CVSS 7.5
CVE-2020-6987 HIGH
Moxa PT-7528 and PT-7828 Firmware - Use of a Broken or Risky Cryptographic Algorithm
CVSS 7.5
CVE-2020-6984 HIGH
Rockwell Automation MicroLogix 1400 A/B <21.001, MicroLogix 1100, RSLogix 500 <12.001 - Broken Cryptographic Algorithm
CVSS 7.5
CVE-2020-5229 HIGH
Opencast < 8.1 - Use of Broken Cryptographic Algorithm via MD5 Password Hashing
CVSS 7.7
CVE-2020-6857 MEDIUM
CarbonFTP 1.4 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 5.5
CVE-2020-1810 MEDIUM
Huawei CloudEngine 12800 and S5700 Firmware - Use of Weak RSA Cryptographic Algorithm
CVSS 5.3
CVE-2020-1826 MEDIUM
Huawei Honor Magic2 <10.0.0.175 - Info Disclosure
CVSS 4.4
CVE-2019-25651 HIGH
Ubiquiti UniFi Devices Use of AES-CBC Allows Key Recovery and Unauthorized Device Control
CVSS 8.3
CVE-2019-25052 CRITICAL
Linaro OP-TEE <3.7.0 - Info Disclosure
CVSS 9.1
CVE-2019-14852 HIGH
3scale API Management - Use of Broken TLS 1.0 Cryptographic Algorithm
CVSS 7.5
CVE-2019-25006 HIGH
streebog < 0.8.0 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 7.5
CVE-2019-4325 MEDIUM
HCL AppScan Enterprise - Info Disclosure
CVSS 5.3
CVE-2019-14089 HIGH
Snapdragon Auto-SC7180 - Info Disclosure
CVSS 7.8
CVE-2019-13022 CRITICAL
Bond JetSelect - Use of a Broken or Risky Cryptographic Algorithm in Password Generation
CVSS 9.8
CVE-2019-20775 MEDIUM
LG Android 9.0 - Local Information Disclosure via Weak Encryption
CVSS 5.5
CVE-2019-14001 HIGH
Snapdragon Auto-SDM660 - Info Disclosure
CVSS 7.8
CVE-2019-15795 MEDIUM
python-apt <= 1.9.0ubuntu1 - Man-in-the-Middle via MD5 Checksum Validation
CVSS 4.7
CVE-2019-4553 HIGH
IBM API Connect <5.0.8.7 - Info Disclosure
CVSS 7.5
CVE-2019-15075 HIGH
iNextrix ASTPP < 4.0.1 - Use of a Broken or Risky Cryptographic Algorithm in config.php
CVSS 7.5
CVE-2019-15653 HIGH
Comba AP2600-I A02,0202N00PD2 - Insufficiently Protected Credentials via Login Page HTML Source
CVSS 7.5
CVE-2019-5135 MEDIUM
WAGO PFC100/PFC200 Firmware - Timing Discrepancy in Web-Based Management Authentication
CVSS 5.3
CVE-2019-9095 CRITICAL
Moxa MB3170/MB3270 < 4.0, MB3180 < 2.0, MB3280/MB3480 < 3.0, MB3660 < 2.2 - Weak Cryptographic Algorithm
CVSS 9.8
CVE-2019-4427 HIGH
IBM Cloud CLI <0.17 - Code Injection
CVSS 7.5
Details
Vulnerabilities 669
Exploit Likelihood High