The product uses an algorithm that produces a digest (output value) that does not meet security expectations for a hash function that allows an adversary to reasonably determine the original input (preimage attack), find another input that can produce the same hash (2nd preimage attack), or find multiple inputs that evaluate to the same hash (birthday attack).
90 vulnerabilities with CWE-328
CVE-2023-46233
CRITICAL
crypto-js < 4.2.0 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 9.1
CVE-2023-46133
CRITICAL
CryptoES < 2.1.0 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 9.1
CVE-2023-43635
HIGH
EVE OS - PCR Locking
CVSS 8.8
CVE-2023-43630
HIGH
Linux Foundation Edge Virtualization Engine 9.0.0-9.4.9 - Credentials Exposure via PCR14 Bypass
CVSS 8.8
CVE-2023-2900
LOW
NFine Rapid Development Platform 20230511 - Use of Weak Hash in Login Check
CVSS 3.7
CVE-2023-0452
CRITICAL
Econolite EOS < 3.2.23 - Unauthenticated Weak Hash Algorithm in Configuration File
CVSS 9.8
CVE-2022-45141
CRITICAL
Samba < 4.15.13 - Inadequate Encryption Strength in Kerberos Ticket Issuance
CVSS 9.8
CVE-2022-43922
MEDIUM
IBM App Connect Enterprise Certified Container <6.2 - Info Disclosure
CVSS 5.3
CVE-2022-3433
MEDIUM
aeson < 2.0.1.0 - Denial of Service via Hash Collision in JSON Input
CVSS 6.5
CVE-2022-29835
MEDIUM
WD Discovery < 4.4.396 - Inadequate Encryption Strength via SHA-1 Signed Executables
CVSS 5.3
CVE-2022-29249
HIGH
JavaEZ 1.6 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 7.5
CVE-2021-39182
HIGH
EnroCrypt < 1.1.4 - Use of Broken MD5 Hashing Algorithm
CVSS 7.5
CVE-2020-37168
CRITICAL
Ecommerce Systempay 1.0 Production Key Brute Force
CVSS 9.8
CVE-2019-13539
HIGH
Medtronic Valleylab Exchange Client <3.4 - Info Disclosure
CVSS 7.0
CVE-2004-2761
CRITICAL
Ietf Md5 - Cryptographic Issue
CVSS 9.8
Details
Vulnerabilities
90