CWE-327
High likelihoodUse of a Broken or Risky Cryptographic Algorithm
The product uses a broken or risky cryptographic algorithm or protocol.
669 vulnerabilities with CWE-327
CVE-2020-10601
HIGH
VISAM VBASE Editor <11.5.0.2 - Privilege Escalation
CVSS 7.8
CVE-2020-11500
HIGH
Zoom Meetings < 4.6.9 - Use of ECB Mode in AES Encryption
CVSS 7.5
CVE-2020-7001
HIGH
Moxa EDS-G516E and EDS-510E Firmware < 5.2 - Weak Cryptographic Algorithm
CVSS 7.5
CVE-2020-6987
HIGH
Moxa PT-7528 and PT-7828 Firmware - Use of a Broken or Risky Cryptographic Algorithm
CVSS 7.5
CVE-2020-6984
HIGH
Rockwell Automation MicroLogix 1400 A/B <21.001, MicroLogix 1100, RSLogix 500 <12.001 - Broken Cryptographic Algorithm
CVSS 7.5
CVE-2020-5229
HIGH
Opencast < 8.1 - Use of Broken Cryptographic Algorithm via MD5 Password Hashing
CVSS 7.7
CVE-2020-6857
MEDIUM
CarbonFTP 1.4 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 5.5
CVE-2020-1810
MEDIUM
Huawei CloudEngine 12800 and S5700 Firmware - Use of Weak RSA Cryptographic Algorithm
CVSS 5.3
CVE-2020-1826
MEDIUM
Huawei Honor Magic2 <10.0.0.175 - Info Disclosure
CVSS 4.4
CVE-2019-25651
HIGH
Ubiquiti UniFi Devices Use of AES-CBC Allows Key Recovery and Unauthorized Device Control
CVSS 8.3
CVE-2019-25052
CRITICAL
Linaro OP-TEE <3.7.0 - Info Disclosure
CVSS 9.1
CVE-2019-14852
HIGH
3scale API Management - Use of Broken TLS 1.0 Cryptographic Algorithm
CVSS 7.5
CVE-2019-25006
HIGH
streebog < 0.8.0 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 7.5
CVE-2019-4325
MEDIUM
HCL AppScan Enterprise - Info Disclosure
CVSS 5.3
CVE-2019-14089
HIGH
Snapdragon Auto-SC7180 - Info Disclosure
CVSS 7.8
CVE-2019-13022
CRITICAL
Bond JetSelect - Use of a Broken or Risky Cryptographic Algorithm in Password Generation
CVSS 9.8
CVE-2019-20775
MEDIUM
LG Android 9.0 - Local Information Disclosure via Weak Encryption
CVSS 5.5
CVE-2019-14001
HIGH
Snapdragon Auto-SDM660 - Info Disclosure
CVSS 7.8
CVE-2019-15795
MEDIUM
python-apt <= 1.9.0ubuntu1 - Man-in-the-Middle via MD5 Checksum Validation
CVSS 4.7
CVE-2019-4553
HIGH
IBM API Connect <5.0.8.7 - Info Disclosure
CVSS 7.5
CVE-2019-15075
HIGH
iNextrix ASTPP < 4.0.1 - Use of a Broken or Risky Cryptographic Algorithm in config.php
CVSS 7.5
CVE-2019-15653
HIGH
Comba AP2600-I A02,0202N00PD2 - Insufficiently Protected Credentials via Login Page HTML Source
CVSS 7.5
CVE-2019-5135
MEDIUM
WAGO PFC100/PFC200 Firmware - Timing Discrepancy in Web-Based Management Authentication
CVSS 5.3
CVE-2019-9095
CRITICAL
Moxa MB3170/MB3270 < 4.0, MB3180 < 2.0, MB3280/MB3480 < 3.0, MB3660 < 2.2 - Weak Cryptographic Algorithm
CVSS 9.8
CVE-2019-4427
HIGH
IBM Cloud CLI <0.17 - Code Injection
CVSS 7.5
Details
Vulnerabilities
669
Exploit Likelihood
High