The product uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.
135 vulnerabilities with CWE-331
CVE-2024-38270
MEDIUM
Zyxel GS1900-10HP <V2.80(AAZI.0)C0 - Info Disclosure
CVSS 5.3
CVE-2024-6508
HIGH
OpenShift Console - Insufficient Entropy in OAuth2 State Parameter
CVSS 8.0
CVE-2024-36400
CRITICAL
nano-id < 0.4.0 - Insufficient Entropy in base62 and base58 Functions
CVSS 9.4
CVE-2024-3411
CRITICAL
Dell iDRAC8 - Insufficient Entropy in IPMI Session Authentication
CVSS 9.1
CVE-2024-26329
MEDIUM
Chilkat <9.5.0.98 - Info Disclosure
CVSS 6.2
CVE-2024-25730
CRITICAL
Hitron CODA-4582/4589 - Info Disclosure
CVSS 9.8
CVE-2024-22473
MEDIUM
Gecko SDK < 4.4.0 - Signature Spoofing via Insufficient TRNG Entropy
CVSS 6.8
CVE-2024-25407
HIGH
SteVe 3.6.0 - Denial of Service via Predictable Transaction ID
CVSS 7.5
CVE-2023-37822
HIGH
Eufy Homebase 2 <3.3.4.1h - Info Disclosure
CVSS 8.2
CVE-2023-49927
MEDIUM
Samsung Mobile Processor - Info Disclosure
CVSS 5.3
CVE-2023-49599
CRITICAL
WWBN AVideo - Insufficient Entropy in Salt Generation
CVSS 9.8
CVE-2023-46648
HIGH
GitHub Enterprise Server <3.8.12-3.11.1 - Info Disclosure
CVSS 8.3
CVE-2023-26154
MEDIUM
PubNub <7.4.0, <6.19.0, <7.3.0, <6.1.0, <5.3.0, <0.4.0 - Path Trave...
CVSS 5.9
CVE-2023-31176
HIGH
SEL-451 Firmware r315-v0 to r315-v4 - Unauthenticated Authentication Bypass via Session Token Brute-Force
CVSS 7.5
CVE-2023-31582
HIGH
jose4j < 0.9.3 - Insufficient Entropy via Low Iteration Count
CVSS 7.5
CVE-2023-34973
LOW
QNAP QTS 5.0.1-5.0.1.2424 and QTS 5.1.0-5.1.0.2443 - Insufficient Entropy
CVSS 3.1
CVE-2023-4344
CRITICAL
Broadcom RAID Controller - Info Disclosure
CVSS 9.8
CVE-2023-38357
MEDIUM
RWS WorldServer <11.7.3 - Info Disclosure
CVSS 5.3
CVE-2023-36610
MEDIUM
Ovarro TBox Firmware < 1.50.598 - Insufficient Entropy in Security Token Generation
CVSS 5.9
CVE-2023-3325
HIGH
CMS Commander < 2.287 - Unauthenticated Authorization Bypass via Insufficient Cryptographic Signature
CVSS 8.1
CVE-2023-20107
HIGH
Cisco ASA/FTD - Cryptographic Collision
CVSS 7.5
CVE-2022-43755
HIGH
SUSE Rancher <2.6.10-2.7.1 - Info Disclosure
CVSS 7.1
CVE-2022-20941
MEDIUM
Cisco Firepower Management Center - Unauthenticated Sensitive Information Disclosure via Resource Enumeration
CVSS 5.3
CVE-2022-34746
MEDIUM
Zyxel GS1900 <V2.70 - Info Disclosure
CVSS 5.9
CVE-2022-33989
MEDIUM
dproxy-nexgen - Insufficient Entropy in UDP Source Port Selection
CVSS 5.3
Details
Vulnerabilities
135