CWE-330

High likelihood

Use of Insufficiently Random Values

Parent: CWE-693 - Protection Mechanism Failure

The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.

375 vulnerabilities with CWE-330
CVE-2017-5242 HIGH
Nexpose & InsightVM - Info Disclosure
CVSS 7.7
CVE-2017-16031 HIGH
socket.io < 0.9.6 - Predictable Socket ID via Math.random()
CVSS 7.5
CVE-2017-16028 MEDIUM
react-native-meteor-oauth - Info Disclosure
CVSS 5.3
CVE-2017-16924 CRITICAL
ManageEngine Desktop Central MSP <10.0.137 - Info Disclosure
CVSS 9.8
CVE-2017-15654 HIGH
Asus asuswrt <= 3.0.0.4.380.7743 - Info Disclosure
CVSS 8.3
CVE-2017-17704 HIGH
Software House iStar Ultra <6.5.2.20569 - Replay Attack
CVSS 7.4
CVE-2017-17910 MEDIUM
Hoermann BiSecur <2018 - Info Disclosure
CVSS 6.5
CVE-2017-17091 HIGH
WordPress < 4.9.1 - Use of Insufficiently Random Values in User ID Key Generation
CVSS 8.8
CVE-2017-10874 HIGH
PWR-Q200 Firmware - DNS Cache Poisoning via Predictable Source Ports
CVSS 7.5
CVE-2017-12361 MEDIUM
Cisco Jabber for Windows - Info Disclosure
CVSS 4.0
CVE-2017-1000246 MEDIUM
Python pysaml2 <4.4.0 - Info Disclosure
CVSS 5.3
CVE-2017-13088 MEDIUM
WPA/WPA2 - Reinstallation
CVSS 5.3
CVE-2017-13087 MEDIUM
hostapd - Use of Insufficiently Random Values in WPA/WPA2 GTK Reinstallation
CVSS 5.3
CVE-2017-13086 MEDIUM
WPA/WPA2 - Reinstallation
CVSS 6.8
CVE-2017-13084 MEDIUM
Wi-Fi Protected Access - Replay Attack
CVSS 6.8
CVE-2017-13082 HIGH
WPA/WPA2 - Reinstallation
CVSS 8.1
CVE-2017-13081 MEDIUM
WPA/WPA2 - Reinstallation
CVSS 5.3
CVE-2017-13080 MEDIUM
WPA/WPA2 - Reinstallation
CVSS 5.3
CVE-2017-13079 MEDIUM
Wi-Fi Protected Access - Reinstallation
CVSS 5.3
CVE-2017-13078 MEDIUM
WPA/WPA2 - Reinstallation
CVSS 5.3
CVE-2017-13077 MEDIUM
WPA/WPA2 - Replay Attack
CVSS 6.8
CVE-2017-7905 CRITICAL
GE Multilin SR, UR, and URplus Protective Relays - Weak Password Encoding via Non-Random Initialization Vector
CVSS 9.8
CVE-2017-7902 CRITICAL
Rockwell Automation Allen-Bradley - Reuse of Nonce
CVSS 9.8
CVE-2017-7901 HIGH
Rockwellautomation 1763-l16awa Series A < 16.000 - Denial of Service
CVSS 8.6
CVE-2017-6026 CRITICAL
Schneider Electric Modicon PLCs <4.0.5.11 - Info Disclosure
CVSS 9.1
Details
Vulnerabilities 375
Exploit Likelihood High