CWE-331

Insufficient Entropy

Parent: CWE-330 - Use of Insufficiently Random Values

The product uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.

131 vulnerabilities with CWE-331
CVE-2025-50122 HIGH
EcoStruxure IT Data Center Expert >=8.3 - Insufficient Entropy in Password Generation
CVE-2025-6931 LOW
D-Link DCS-6517/7517 <2.02.0 - Insufficient Entropy
CVSS 3.7
CVE-2025-52464 HIGH
Meshtastic <2.6.11 - Info Disclosure
CVSS 8.3
CVE-2025-47781 CRITICAL
rallly <= 3.22.1 - Unauthenticated Account Takeover via Weak Email Token Brute Force
CVSS 9.8
CVE-2025-2814 MEDIUM
Crypt::CBC 1.21-3.05 - Weak Cryptographic IV Generation via rand() Fallback
CVSS 4.0
CVE-2025-1860 HIGH
Data::Entropy <0.008 - Info Disclosure
CVSS 7.7
CVE-2025-27552 MEDIUM
DBIx::Class::EncodedColumn <0.00032 - Info Disclosure
CVSS 4.0
CVE-2025-27551 MEDIUM
DBIx::Class::EncodedColumn <0.00032 - Info Disclosure
CVSS 4.0
CVE-2025-29311 HIGH
ONOS 2.7.0 - Insufficient Entropy in LLDP Packet Private Key
CVSS 7.5
CVE-2025-1828 HIGH
Crypt::Random Perl <1.56 - Info Disclosure
CVSS 8.8
CVE-2024-58040 CRITICAL
Crypt::RandomEncryption 0.01 - Insecure RNG
CVSS 9.1
CVE-2024-58134 HIGH
Mojolicious <0.999922 - Info Disclosure
CVSS 8.1
CVE-2024-56370 MEDIUM
Net::Xero <= 0.44 - Insufficient Entropy via rand() Function
CVSS 6.5
CVE-2024-52322 MEDIUM
WebService::Xero <0.11 - Info Disclosure
CVSS 5.5
CVE-2024-58036 MEDIUM
Net::Dropbox::API <1.9 - Info Disclosure
CVSS 5.5
CVE-2024-57868 MEDIUM
Web::API < 2.8 - Insufficient Entropy via rand() Function
CVSS 5.5
CVE-2024-9055 MEDIUM
Silicon Labs Series 2 - Info Disclosure
CVSS 4.2
CVE-2024-53522 HIGH
Bangkok Medical Software HOSxP XE <4.64.11.3 - Info Disclosure
CVSS 7.5
CVE-2024-20331 MEDIUM
Cisco Adaptive Security Appliance Software - Unauthenticated Denial of Service via Session Authentication Handle
CVSS 6.8
CVE-2024-47945 CRITICAL
Session Hijacking - Info Disclosure
CVSS 9.8
CVE-2024-8796 MEDIUM
Devise-Two-Factor >=2.2.0 <6.0.0 - Info Disclosure
CVSS 5.3
CVE-2024-38270 MEDIUM
Zyxel GS1900-10HP <V2.80(AAZI.0)C0 - Info Disclosure
CVSS 5.3
CVE-2024-6508 HIGH
OpenShift Console - Insufficient Entropy in OAuth2 State Parameter
CVSS 8.0
CVE-2024-36400 CRITICAL
nano-id < 0.4.0 - Insufficient Entropy in base62 and base58 Functions
CVSS 9.4
CVE-2024-3411 CRITICAL
Dell iDRAC8 - Insufficient Entropy in IPMI Session Authentication
CVSS 9.1
Details
Vulnerabilities 131