CWE-327

High likelihood

Use of a Broken or Risky Cryptographic Algorithm

Parent: CWE-693 - Protection Mechanism Failure

The product uses a broken or risky cryptographic algorithm or protocol.

687 vulnerabilities with CWE-327
CVE-2020-7689 MEDIUM
node.bcrypt.js < 5.0.0 - Integer Overflow in Data Length Handling
CVSS 5.9
CVE-2020-4452 HIGH
IBM API Connect 2018.4.1.0-2018.4.1.11 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 7.5
CVE-2020-7511 HIGH
Schneider-electric Easergy T300 Firmware < 1.5.2 - Broken Cryptographic Algorithm
CVSS 7.5
CVE-2020-4191 MEDIUM
IBM Security Guardium 11.1 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 4.4
CVE-2020-13777 HIGH
GnuTLS 3.6.4-3.6.13 - Use of a Broken or Risky Cryptographic Algorithm in Session Ticket Encryption
CVSS 7.4
CVE-2020-4367 HIGH
IBM Planning Analytics Local 2.0-2.0.9 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 7.5
CVE-2020-13757 HIGH
Python-RSA < 4.1 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 7.5
CVE-2020-4379 HIGH
IBM Spectrum Scale 5.0.0.0-5.0.4.4 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 7.5
CVE-2020-4350 HIGH
IBM Spectrum Scale 5.0.0.0-5.0.4.4 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 7.5
CVE-2020-4349 HIGH
IBM Spectrum Scale 5.0.0.0-5.0.4.4 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 7.5
CVE-2020-13135 MEDIUM
D-Link DSP-W215 1.26b03 - Info Disclosure
CVSS 6.5
CVE-2020-6861 MEDIUM
Ledger Monero < 1.5.1 - Master Spending Key Extraction via Crafted Messages
CVSS 5.5
CVE-2020-11035 HIGH
GLPI 0.83.3-9.4.6 - Use of a Broken or Risky Cryptographic Algorithm in CSRF Token Generation
CVSS 7.5
CVE-2020-11876 HIGH
Zoom Meetings 4.6.11 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 7.5
CVE-2020-10377 CRITICAL
Mitel MiVoice Connect Client < 214.100.1213.0 - Unauthenticated Weak Encryption
CVSS 9.8
CVE-2020-11872 HIGH
OpenTrace 1.0 - Fabrication Attack via TempID Request Flooding
CVSS 7.5
CVE-2020-10932 MEDIUM
Arm Mbed TLS <2.16.6, <2.7.15 - Memory Corruption
CVSS 4.7
CVE-2020-11005 MEDIUM
WindowsHello <1.0.4 - Info Disclosure
CVSS 5.1
CVE-2020-10601 HIGH
VISAM VBASE Editor <11.5.0.2 - Privilege Escalation
CVSS 7.8
CVE-2020-11500 HIGH
Zoom Meetings < 4.6.9 - Use of ECB Mode in AES Encryption
CVSS 7.5
CVE-2020-7001 HIGH
Moxa EDS-G516E and EDS-510E Firmware < 5.2 - Weak Cryptographic Algorithm
CVSS 7.5
CVE-2020-6987 HIGH
Moxa PT-7528 and PT-7828 Firmware - Use of a Broken or Risky Cryptographic Algorithm
CVSS 7.5
CVE-2020-6984 HIGH
Rockwell Automation MicroLogix 1400 A/B <21.001, MicroLogix 1100, RSLogix 500 <12.001 - Broken Cryptographic Algorithm
CVSS 7.5
CVE-2020-5229 HIGH
Opencast < 8.1 - Use of Broken Cryptographic Algorithm via MD5 Password Hashing
CVSS 7.7
CVE-2020-6857 MEDIUM
CarbonFTP 1.4 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 5.5
Details
Vulnerabilities 687
Exploit Likelihood High