CWE-327

High likelihood

Use of a Broken or Risky Cryptographic Algorithm

Parent: CWE-693 - Protection Mechanism Failure

The product uses a broken or risky cryptographic algorithm or protocol.

687 vulnerabilities with CWE-327
CVE-2020-1810 MEDIUM
Huawei CloudEngine 12800 and S5700 Firmware - Use of Weak RSA Cryptographic Algorithm
CVSS 5.3
CVE-2020-1826 MEDIUM
Huawei Honor Magic2 <10.0.0.175 - Info Disclosure
CVSS 4.4
CVE-2019-25651 HIGH
Ubiquiti UniFi Devices Use of AES-CBC Allows Key Recovery and Unauthorized Device Control
CVSS 8.3
CVE-2019-25052 CRITICAL
Linaro OP-TEE <3.7.0 - Info Disclosure
CVSS 9.1
CVE-2019-14852 HIGH
3scale API Management - Use of Broken TLS 1.0 Cryptographic Algorithm
CVSS 7.5
CVE-2019-25006 HIGH
streebog < 0.8.0 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 7.5
CVE-2019-4325 MEDIUM
HCL AppScan Enterprise - Info Disclosure
CVSS 5.3
CVE-2019-14089 HIGH
Snapdragon Auto-SC7180 - Info Disclosure
CVSS 7.8
CVE-2019-13022 CRITICAL
Bond JetSelect - Use of a Broken or Risky Cryptographic Algorithm in Password Generation
CVSS 9.8
CVE-2019-20775 MEDIUM
LG Android 9.0 - Local Information Disclosure via Weak Encryption
CVSS 5.5
CVE-2019-14001 HIGH
Snapdragon Auto-SDM660 - Info Disclosure
CVSS 7.8
CVE-2019-15795 MEDIUM
python-apt <= 1.9.0ubuntu1 - Man-in-the-Middle via MD5 Checksum Validation
CVSS 4.7
CVE-2019-4553 HIGH
IBM API Connect <5.0.8.7 - Info Disclosure
CVSS 7.5
CVE-2019-15075 HIGH
iNextrix ASTPP < 4.0.1 - Use of a Broken or Risky Cryptographic Algorithm in config.php
CVSS 7.5
CVE-2019-15653 HIGH
Comba AP2600-I A02,0202N00PD2 - Insufficiently Protected Credentials via Login Page HTML Source
CVSS 7.5
CVE-2019-5135 MEDIUM
WAGO PFC100/PFC200 Firmware - Timing Discrepancy in Web-Based Management Authentication
CVSS 5.3
CVE-2019-9095 CRITICAL
Moxa MB3170/MB3270 < 4.0, MB3180 < 2.0, MB3280/MB3480 < 3.0, MB3660 < 2.2 - Weak Cryptographic Algorithm
CVSS 9.8
CVE-2019-4427 HIGH
IBM Cloud CLI <0.17 - Code Injection
CVSS 7.5
CVE-2019-4540 HIGH
IBM Security Directory Server 6.4.0 - Info Disclosure
CVSS 7.5
CVE-2019-4639 HIGH
IBM Security Secret Server 10.7 - Info Disclosure
CVSS 7.5
CVE-2019-3700 LOW
yast2-security < 4.2.6 - Use of Weak DES Password Encryption
CVSS 2.9
CVE-2019-19891 MEDIUM
Mitel SIP-DECT Firmware 8.0-8.1 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 5.9
CVE-2019-20138 HIGH
Nim HTTP Auth <2019-12-27 - Info Disclosure
CVSS 7.5
CVE-2019-4609 HIGH
IBM API Connect 2018.4.1.7 - Info Disclosure
CVSS 7.5
CVE-2019-18832 HIGH
Barco ClickShare Button R9861500D01 <1.9.0 - Privilege Escalation
CVSS 8.1
Details
Vulnerabilities 687
Exploit Likelihood High