CWE-327

High likelihood

Use of a Broken or Risky Cryptographic Algorithm

Parent: CWE-693 - Protection Mechanism Failure

The product uses a broken or risky cryptographic algorithm or protocol.

687 vulnerabilities with CWE-327
CVE-2019-18340 MEDIUM
SiNVR 3 Central Control Server and Video Server - Use of a Broken or Risky Cryptographic Algorithm
CVSS 5.5
CVE-2019-17428 MEDIUM
Intesync Solismed 3.3sp1 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 5.9
CVE-2019-16863 MEDIUM
STMicroelectronics ST33TPHF2ESPI - Info Disclosure
CVSS 5.9
CVE-2019-16208 HIGH
Brocade SANnav <2.0 - Info Disclosure
CVSS 7.5
CVE-2019-4399 HIGH
IBM Cloud Orchestrator <2.4.0.5, <2.5.0.9 - Info Disclosure
CVSS 7.5
CVE-2019-8237 CRITICAL
Adobe Acrobat and Reader DC < 15.006.30499, 15.008.20082-19.012.20036 - Security Feature Bypass via Weak Encryption
CVSS 9.8
CVE-2019-11341 MEDIUM
Samsung Android P(9.0) - Use of a Broken Cryptographic Algorithm in Service Mode OTP Generation
CVSS 4.6
CVE-2019-13629 MEDIUM
MatrixSSL < 4.2.1 - Timing Side-Channel Attack in ECDSA Signature Generation
CVSS 5.9
CVE-2019-16116 MEDIUM
EnterpriseDT CompleteFTP Server <12.1.3 - Info Disclosure
CVSS 4.3
CVE-2019-3736 HIGH
Dell EMC Integrated Data Protection Appliance <2.3 - Privilege Esca...
CVSS 7.2
CVE-2019-9399 MEDIUM
Android 10 - Remote Information Disclosure via Print Service Man-in-the-Middle
CVSS 5.9
CVE-2019-16370 MEDIUM
Gradle < 6.0 - Use of a Broken or Risky Cryptographic Algorithm via SHA-1 in PGP Signing Plugin
CVSS 5.9
CVE-2019-1563 LOW
OpenSSL 1.0.2-1.0.2s - Bleichenbacher Padding Oracle Attack via CMS/PKCS7 Decryption
CVSS 3.7
CVE-2019-16143 CRITICAL
blake2-rust < 0.8.1 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 9.8
CVE-2019-15955 MEDIUM
Total.js CMS 12.0.0 - Info Disclosure
CVSS 6.5
CVE-2019-12587 HIGH
Espressif ESP-IDF 2.0.0-4.0.0 & ESP8266_NONOS_SDK 2.2.0-3.1.0 - Broken Cryptographic Algorithm via Zero PMK
CVSS 8.1
CVE-2019-9155 MEDIUM
Openpgpjs < 4.2.0 - Broken Cryptographic Algorithm
CVSS 5.9
CVE-2019-12621 HIGH
Cisco HyperFlex Software - Man-in-the-Middle
CVSS 7.4
CVE-2019-5035 CRITICAL
Nest Cam IQ Indoor <4620002 - Info Disclosure
CVSS 9.0
CVE-2019-9013 HIGH
CODESYS V3 Products 3.0-3.5.16.0 - Insufficient Credential Protection via Non-TLS Encryption
CVSS 8.8
CVE-2019-9506 HIGH
Android - Bluetooth BR/EDR Encryption Key Length Downgrade via KNOB Attack
CVSS 8.1
CVE-2019-10929 MEDIUM
SIMATIC S7-1200 CPU family < V4.4.0 - Message Protection Bypass via Integrity Calculation Flaw
CVSS 5.9
CVE-2019-5502 CRITICAL
Data ONTAP 7-Mode < 8.2.5P3 - Use of a Broken or Risky Cryptographic Algorithm in SMB
CVSS 9.1
CVE-2019-7858 HIGH
Magento <2.1.18-2.3.2 - Info Disclosure
CVSS 7.5
CVE-2019-13604 MEDIUM
HID Global DigitalPersona U.are.U 4500 v24 - Biometric Info Leak via Brute-Force
CVSS 5.9
Details
Vulnerabilities 687
Exploit Likelihood High