CWE-328

Use of Weak Hash

Parent: CWE-326 - Inadequate Encryption Strength

The product uses an algorithm that produces a digest (output value) that does not meet security expectations for a hash function that allows an adversary to reasonably determine the original input (preimage attack), find another input that can produce the same hash (2nd preimage attack), or find multiple inputs that evaluate to the same hash (birthday attack).

90 vulnerabilities with CWE-328
CVE-2023-46233 CRITICAL
crypto-js < 4.2.0 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 9.1
CVE-2023-46133 CRITICAL
CryptoES < 2.1.0 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 9.1
CVE-2023-43635 HIGH
EVE OS - PCR Locking
CVSS 8.8
CVE-2023-43630 HIGH
Linux Foundation Edge Virtualization Engine 9.0.0-9.4.9 - Credentials Exposure via PCR14 Bypass
CVSS 8.8
CVE-2023-2900 LOW
NFine Rapid Development Platform 20230511 - Use of Weak Hash in Login Check
CVSS 3.7
CVE-2023-0452 CRITICAL
Econolite EOS < 3.2.23 - Unauthenticated Weak Hash Algorithm in Configuration File
CVSS 9.8
CVE-2022-45141 CRITICAL
Samba < 4.15.13 - Inadequate Encryption Strength in Kerberos Ticket Issuance
CVSS 9.8
CVE-2022-43922 MEDIUM
IBM App Connect Enterprise Certified Container <6.2 - Info Disclosure
CVSS 5.3
CVE-2022-3433 MEDIUM
aeson < 2.0.1.0 - Denial of Service via Hash Collision in JSON Input
CVSS 6.5
CVE-2022-29835 MEDIUM
WD Discovery < 4.4.396 - Inadequate Encryption Strength via SHA-1 Signed Executables
CVSS 5.3
CVE-2022-29249 HIGH
JavaEZ 1.6 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 7.5
CVE-2021-39182 HIGH
EnroCrypt < 1.1.4 - Use of Broken MD5 Hashing Algorithm
CVSS 7.5
CVE-2020-37168 CRITICAL
Ecommerce Systempay 1.0 Production Key Brute Force
CVSS 9.8
CVE-2019-13539 HIGH
Medtronic Valleylab Exchange Client <3.4 - Info Disclosure
CVSS 7.0
CVE-2004-2761 CRITICAL
Ietf Md5 - Cryptographic Issue
CVSS 9.8
Details
Vulnerabilities 90