CWE-328

Use of Weak Hash

Parent: CWE-326 - Inadequate Encryption Strength

The product uses an algorithm that produces a digest (output value) that does not meet security expectations for a hash function that allows an adversary to reasonably determine the original input (preimage attack), find another input that can produce the same hash (2nd preimage attack), or find multiple inputs that evaluate to the same hash (birthday attack).

56 vulnerabilities with CWE-328
CVE-2024-23589 MEDIUM
HCL Glovius Cloud - Info Disclosure
CVSS 6.8
CVE-2024-38341 MEDIUM
IBM Sterling Secure Proxy <6.2.0.1 - Info Disclosure
CVSS 5.9
CVE-2024-47829 MEDIUM
pnpm <10.0.0 - Info Disclosure
CVSS 6.5
CVE-2024-10026 MEDIUM
Google's gVisor - Info Disclosure
CVSS 5.3
CVE-2024-56414 MEDIUM
Acronis Cyber Protect <39169 - Info Disclosure
CVSS 5.5
CVE-2024-56516 MEDIUM
free-one-api <1.0.1 - Info Disclosure
CVE-2024-55885 HIGH
Beego < 2.3.4 - Broken Cryptographic Algorithm
CVSS 7.5
CVE-2024-54143 CRITICAL
OpenWrt - Info Disclosure
CVE-2024-48847 HIGH
ABB Aspect-ent-2 Firmware < 3.08.03 - Broken Cryptographic Algorithm
CVSS 8.2
CVE-2024-52521 LOW
Nextcloud Server <28.0.10-30.0.0 - Info Disclosure
CVSS 2.6
CVE-2024-48924 HIGH
Nuget Messagepack < 2.5.187 - Denial of Service
CVE-2024-8453 MEDIUM
PLANET Technology - Info Disclosure
CVSS 4.9
CVE-2024-8452 HIGH
PLANET Technology - Info Disclosure
CVSS 7.5
CVE-2024-47182 MEDIUM
Dozzle <8.5.3 - Info Disclosure
CVSS 4.8
CVE-2024-40465 HIGH
beego <2.2.0 - Privilege Escalation
CVSS 8.8
CVE-2024-34914 MEDIUM
php-censor <2.1.4 - Info Disclosure
CVSS 5.3
CVE-2023-5962 MEDIUM
Moxa Iologik E1210 Firmware < 3.3 - Broken Cryptographic Algorithm
CVSS 6.5
CVE-2023-44319 MEDIUM
RUGGEDCOM RM1224 LTE(4G) EU/NAM, SCALANCE M804PB/M812-1/M816-1 - In...
CVSS 4.9
CVE-2023-46233 CRITICAL
crypto-js <4.2.0 - Info Disclosure
CVSS 9.1
CVE-2023-46133 CRITICAL
CryptoES <2.1.0 - Info Disclosure
CVSS 9.1
CVE-2023-43635 HIGH
EVE OS - PCR Locking
CVSS 8.8
CVE-2023-43630 HIGH
PCR14 - Info Disclosure
CVSS 8.8
CVE-2023-2900 LOW
Nfine Rapid Development Platform - Broken Cryptographic Algorithm
CVSS 3.7
CVE-2023-0452 CRITICAL
Econolite Eos - Broken Cryptographic Algorithm
CVSS 9.8
CVE-2022-45141 CRITICAL
Samba < 4.15.13 - Weak Encryption
CVSS 9.8
Details
Vulnerabilities 56