CWE-327

High likelihood

Use of a Broken or Risky Cryptographic Algorithm

Parent: CWE-693 - Protection Mechanism Failure

The product uses a broken or risky cryptographic algorithm or protocol.

669 vulnerabilities with CWE-327
CVE-2019-5035 CRITICAL
Nest Cam IQ Indoor <4620002 - Info Disclosure
CVSS 9.0
CVE-2019-9013 HIGH
CODESYS V3 Products 3.0-3.5.16.0 - Insufficient Credential Protection via Non-TLS Encryption
CVSS 8.8
CVE-2019-9506 HIGH
Android - Bluetooth BR/EDR Encryption Key Length Downgrade via KNOB Attack
CVSS 8.1
CVE-2019-10929 MEDIUM
SIMATIC S7-1200 CPU family < V4.4.0 - Message Protection Bypass via Integrity Calculation Flaw
CVSS 5.9
CVE-2019-5502 CRITICAL
Data ONTAP 7-Mode < 8.2.5P3 - Use of a Broken or Risky Cryptographic Algorithm in SMB
CVSS 9.1
CVE-2019-7858 HIGH
Magento <2.1.18-2.3.2 - Info Disclosure
CVSS 7.5
CVE-2019-13604 MEDIUM
HID Global DigitalPersona U.are.U 4500 v24 - Biometric Info Leak via Brute-Force
CVSS 5.9
CVE-2019-13052 MEDIUM
Logitech Unifying Receiver Firmware - Use of a Broken or Risky Cryptographic Algorithm
CVSS 6.5
CVE-2019-9836 MEDIUM
AMD Secure Encrypted Virtualization Firmware < 0.17b11 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 5.3
CVE-2019-4156 MEDIUM
IBM Security Access Manager 9.0.1-9.0.6 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 5.9
CVE-2019-11323 MEDIUM
HAProxy 1.9.2-1.9.6 - Use of Uninitialized HMAC Keys During Reload with Rotated Keys
CVSS 5.9
CVE-2019-1706 HIGH
Cisco Adaptive Security Appliance Software 9.9-9.9.2.50 - Denial of Service via IPsec Session Handling
CVSS 8.6
CVE-2019-0688 HIGH
Windows 10, 8.1, RT 8.1, Server 2012, 2016, 2019 - Information Disclosure via Fragmented IP Packet Handling
CVSS 7.5
CVE-2019-1828 MEDIUM
Cisco Small Business RV320-325 - Info Disclosure
CVSS 5.9
CVE-2019-7477 HIGH
SonicWall <6.5.1.10 - Info Disclosure
CVSS 7.5
CVE-2019-5723 CRITICAL
portier 4.4.4.2 and 4.4.4.6 - Insufficiently Protected Credentials via Reversible Encryption
CVSS 9.8
CVE-2019-5919 CRITICAL
Nablarch 5 and 5u1-5u13 - Use of a Broken or Risky Cryptographic Algorithm in Data Store Function
CVSS 9.1
CVE-2019-1543 HIGH
OpenSSL 1.1.0-1.1.0j - Nonce Reuse in ChaCha20-Poly1305
CVSS 7.4
CVE-2019-0187 CRITICAL
Apache JMeter < 5.1 - Unauthenticated Remote Code Execution via RMI Deserialization
CVSS 9.8
CVE-2019-9483 CRITICAL
Amazon Ring Doorbell <3.4.7 - Info Disclosure
CVSS 9.1
CVE-2019-7006 MEDIUM
Avaya one-X Communicator <6.2.SP13 - Info Disclosure
CVSS 5.5
CVE-2019-6593 MEDIUM
BIG-IP 11.5.1-11.5.4, 11.6.1, 12.1.0 - Chosen Ciphertext Attack via CBC Ciphers
CVSS 5.9
CVE-2019-6485 MEDIUM
Citrix NetScaler Gateway and ADC - TLS Padding Oracle Vulnerability via CBC Cipher Suites
CVSS 5.9
CVE-2019-5754 MEDIUM
Google Chrome < 72.0.3626.81 - Cleartext Exposure via QUIC Networking Proxy
CVSS 6.5
CVE-2019-7673 HIGH
MOBOTIX S14 <MX-V4.2.1.61 - Info Disclosure
CVSS 7.5
Details
Vulnerabilities 669
Exploit Likelihood High