CWE-327

High likelihood

Use of a Broken or Risky Cryptographic Algorithm

Parent: CWE-693 - Protection Mechanism Failure

The product uses a broken or risky cryptographic algorithm or protocol.

671 vulnerabilities with CWE-327
CVE-2017-8191 MEDIUM
FusionSphere OpenStack V100R006C00SPC102(NFV) - Use of a Broken or Risky Cryptographic Algorithm
CVSS 5.9
CVE-2017-8157 MEDIUM
Huawei OceanStor 5800 V3 and 6900 V3 - Information Disclosure via TLS 1.0 Weak Encryption
CVSS 5.9
CVE-2017-15998 HIGH
NQ Contacts Backup & Restore 1.1 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 7.5
CVE-2017-15997 HIGH
NQ Contacts Backup & Restore 1.1 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 7.8
CVE-2017-14937 MEDIUM
PCU - Predictable Security Access Key in Airbag Detonation Algorithm
CVSS 4.7
CVE-2017-1339 MEDIUM
IBM Spectrum Protect <8.1 - Info Disclosure
CVSS 4.4
CVE-2017-9859 CRITICAL
SMA Solar Technology - Password Cracking
CVSS 9.8
CVE-2017-11133 HIGH
heinekingmedia StashCat <1.7.5 (Android), <0.0.80w (Web), <0.0.86w (Desktop) - Weak Cryptographic Algorithm
CVSS 7.5
CVE-2017-10668 MEDIUM
OSCI Transport Library 1.6.1 (Java) and 1.6 (.NET) - Padding Oracle via CBC Mode
CVSS 5.9
CVE-2017-9466 CRITICAL
TP-Link WR841N V8 - Info Disclosure
CVSS 9.8
CVE-2017-4917 CRITICAL
VMware vSphere Data Protection 5.5.x-6.1.x - Plaintext Credential Exposure via Reversible Encryption
CVSS 9.8
CVE-2017-5243 HIGH
Rapid7 Nexpose <June 2017 - Info Disclosure
CVSS 8.5
CVE-2017-9136 HIGH
Mimosa Client Radios <2.2.3 - Code Injection
CVSS 7.5
CVE-2017-5186 HIGH
Novell iManager <2.7 SP7 Patch 9 - Info Disclosure
CVSS 7.5
CVE-2016-5431 HIGH
php_jose < 2.2.1 - Key Confusion and Algorithm Substitution in JWS Component
CVSS 7.5
CVE-2016-3099 HIGH
Red Hat Enterprise Linux 7 - Use of a Broken or Risky Cryptographic Algorithm in mod_ns
CVSS 7.5
CVE-2016-6485 HIGH
Magento 2 - Use of a Broken or Risky Cryptographic Algorithm in Framework/Encryption/Crypt.php
CVSS 7.5
CVE-2016-8370 HIGH
Mitsubishi Electric Automation - Info Disclosure
CVSS 7.5
CVE-2016-6602 CRITICAL
ZOHO WebNMS Framework 5.2-5.2 SP1 - Info Disclosure
CVSS 9.8
CVE-2016-0923 HIGH
EMC RSA BSAFE Micro Edition Suite - Cryptographic Protection Weakness
CVSS 7.5
CVE-2015-9235 CRITICAL
jsonwebtoken < 4.2.2 - Authentication Bypass via Algorithm Confusion
CVSS 9.8
CVE-2015-0226 HIGH
Apache WSS4J < 1.6.17 and 2.0.0-2.0.1 - Information Disclosure via Decryption Failure Handling
CVSS 7.5
CVE-2015-0535 HIGH
RSA BSAFE Micro Edition Suite 4.0.0-4.0.7, 4.1.0-4.1.2 & SSL-C < 2.8.9 - TLS Cipher Downgrade Attack
CVSS 7.5
CVE-2015-0533 HIGH
RSA BSAFE Micro Edition Suite 4.0.0-4.0.7 and 4.1.0-4.1.2 and RSA BSAFE SSL-C < 2.8.9 - ECDHE-to-ECDH Downgrade Attack
CVSS 7.5
CVE-2015-2808 LOW
Oracle Communications Application Session Controller 3.0.0-3.8.9 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 3.7
Details
Vulnerabilities 671
Exploit Likelihood High