CWE-327

High likelihood

Use of a Broken or Risky Cryptographic Algorithm

Parent: CWE-693 - Protection Mechanism Failure

The product uses a broken or risky cryptographic algorithm or protocol.

669 vulnerabilities with CWE-327
CVE-2024-4563 MEDIUM
Progress MOVEit Automation < 2024.0.0 - Use of a Broken or Risky Cryptographic Algorithm in Configuration Export
CVSS 6.1
CVE-2024-31989 CRITICAL
Argo CD < 2.8.19 - Unauthenticated Privilege Escalation via Redis Server Access
CVSS 9.0
CVE-2024-4765 HIGH
Firefox < 126.0 for Android - Arbitrary Code Execution via Manifest Hash Collision
CVSS 8.1
CVE-2024-25968 MEDIUM
Dell PowerScale OneFS 8.2.x-9.7.0.2 - Unauthenticated Information Disclosure via Broken Cryptographic Algorithm
CVSS 5.9
CVE-2024-33663 MEDIUM
python-jose < 3.3.0 - Algorithm Confusion with OpenSSH ECDSA Keys
CVSS 6.5
CVE-2024-29056 MEDIUM
Windows Server 2008/2012/2016/2019/2022/23H2 Elevation of Privilege via Broken Cryptographic Algorithm
CVSS 4.3
CVE-2024-25963 MEDIUM
Dell PowerScale OneFS 8.2.2.x-9.5.0.x - Unauthenticated Information Disclosure via Broken Cryptographic Algorithm
CVSS 5.9
CVE-2024-28834 MEDIUM
GnuTLS - Timing Side-Channel
CVSS 5.3
CVE-2024-22463 HIGH
Dell PowerScale OneFS <9.6.0.x - Info Disclosure
CVSS 7.4
CVE-2024-27255 MEDIUM
IBM MQ Operator <=2.4.7, 2.3.0-2.3.3, 2.2.0-2.2.2 - Weak Cryptographic Algorithm
CVSS 5.9
CVE-2024-22458 LOW
Dell Secure Connect Gateway 5.18 - Info Disclosure
CVSS 3.7
CVE-2024-22361 MEDIUM
IBM Semeru Runtime <21.0.1.0 - Info Disclosure
CVSS 5.9
CVE-2024-22318 MEDIUM
IBM i Access Client Solutions <1.1.2-1.1.4, <1.1.4.3-1.1.9.4 - Info...
CVSS 5.1
CVE-2024-24559 LOW
vyperlang/vyper < 0.3.10 and pypi/vyper < 0.4.0 - Broken Cryptographic Algorithm in sha3_64
CVSS 3.7
CVE-2024-1040 MEDIUM
Gessler GmbH WEB-MASTER Firmware - Weak Password Hashing
CVSS 4.4
CVE-2024-22192 MEDIUM
Ursa - Privacy Violation via Non-Revocation Proof Unique Identifier Leak
CVSS 6.5
CVE-2024-21670 MEDIUM
Ursa - Use of a Broken or Risky Cryptographic Algorithm in Revocation Schema
CVSS 6.5
CVE-2023-52236 HIGH
RUGGEDCOM Various - Info Disclosure
CVSS 7.0
CVE-2023-37395 LOW
IBM Aspera Faspex 5.0.0-5.0.7 - Sensitive Information Exposure via Improper Encryption
CVSS 2.5
CVE-2023-41928 MEDIUM
Kiloview P1/P2 < 4.8.2605 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 5.3
CVE-2023-41927 MEDIUM
Kiloview P1/P2 - Use of Weak Cipher Suite
CVSS 5.3
CVE-2023-38371 MEDIUM
IBM Security Access Manager Docker <10.0.8 - Info Disclosure
CVSS 5.9
CVE-2023-40696 MEDIUM
IBM Cognos Controller - Info Disclosure
CVSS 5.9
CVE-2023-37396 LOW
IBM Aspera Faspex 5.0.0-5.0.7 - Sensitive Information Exposure via Improper Encryption
CVSS 2.5
CVE-2023-50313 MEDIUM
IBM WebSphere Application Server 8.5 and 9.0 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 5.3
Details
Vulnerabilities 669
Exploit Likelihood High