CWE-330

High likelihood

Use of Insufficiently Random Values

Parent: CWE-693 - Protection Mechanism Failure

The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.

381 vulnerabilities with CWE-330
CVE-2022-26071 HIGH
F5 BIG-IP <16.1.2.2, <15.1.5.1, <14.1.4.6, <13.1.5, <=11.6.x - DoS
CVSS 7.4
CVE-2022-25752 CRITICAL
Siemens SCALANCE X Series - Session Hijacking via Insecure Session ID Generation
CVSS 9.8
CVE-2022-27577 CRITICAL
SICK MSC800 Firmware < 4.15 - TCP Sequence Number Prediction
CVSS 9.1
CVE-2022-29035 LOW
JetBrains Ktor Native <2.0.0 - Info Disclosure
CVSS 3.3
CVE-2022-26851 CRITICAL
Dell PowerScale OneFS <9.3 - Info Disclosure
CVSS 9.1
CVE-2022-22517 HIGH
CODESYS Control Runtime Toolkit < 3.5.18.0 - Unauthenticated Denial of Service via Channel ID Guessing
CVSS 7.5
CVE-2022-28355 HIGH
Scala.js < 1.10.0 - Use of Insufficiently Random Values in randomUUID
CVSS 7.5
CVE-2022-26320 CRITICAL
Rambus SafeZone Basic Crypto Module <10.4.0 - Info Disclosure
CVSS 9.1
CVE-2022-26317 MEDIUM
Mendix Applications <7.23.29 - Info Disclosure
CVSS 6.5
CVE-2022-22700 MEDIUM
CyberArk Identity <= 22.1 - Info Disclosure
CVSS 5.3
CVE-2022-22922 CRITICAL
TP-Link TL-WA850RE <6_200923 - Privilege Escalation
CVSS 9.8
CVE-2022-23408 CRITICAL
wolfSSL 5.0.0-5.1.0 - Use of Insufficiently Random Values in AES-CBC and DES3 Connections
CVSS 9.1
CVE-2021-26407 MEDIUM
AMD RomePI Firmware < 1.0.0.a - Information Disclosure via IV Collision
CVSS 5.5
CVE-2021-4277 LOW
utils_project/utils < 2021-05-14 - Predictable Resource Location via Filename Handler
CVSS 2.6
CVE-2021-4248 MEDIUM
Kapetan DNS <7.0.0 - Insufficient Entropy
CVSS 5.6
CVE-2021-4241 LOW
phpservermon < 3.6.0 - Insufficient Entropy in User Login Token Generation
CVSS 2.6
CVE-2021-4240 LOW
phpservermon - Predictable Algorithm
CVSS 2.6
CVE-2021-23451 MEDIUM
otp-generator <3.0.0 - Info Disclosure
CVSS 6.5
CVE-2021-41994 MEDIUM
PingID < 1.19 - Offline MFA Bypass via RSA Misconfiguration
CVSS 6.6
CVE-2021-41993 MEDIUM
PingID Android <1.19 - Info Disclosure
CVSS 6.6
CVE-2021-40422 CRITICAL
Swift Sensors Gateway SG3-1010 - RCE
CVSS 10.0
CVE-2021-46010 HIGH
Totolink A3100R V5.9c.4577 - Info Disclosure
CVSS 8.8
CVE-2021-36166 CRITICAL
FortiMail < 7.0.1 - Authentication Token Brute-Force via System Property Observation
CVSS 9.8
CVE-2021-20322 HIGH
Linux Kernel < 5.14.21 - UDP Port Scan via ICMP Error Message Processing
CVSS 7.4
CVE-2021-26726 HIGH
Valmet DNA 2012-2021 - Remote Code Execution via TCP Port 1517
CVSS 8.8
Details
Vulnerabilities 381
Exploit Likelihood High