CWE-331

Insufficient Entropy

Parent: CWE-330 - Use of Insufficiently Random Values

The product uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.

135 vulnerabilities with CWE-331
CVE-2024-38270 MEDIUM
Zyxel GS1900-10HP <V2.80(AAZI.0)C0 - Info Disclosure
CVSS 5.3
CVE-2024-6508 HIGH
OpenShift Console - Insufficient Entropy in OAuth2 State Parameter
CVSS 8.0
CVE-2024-36400 CRITICAL
nano-id < 0.4.0 - Insufficient Entropy in base62 and base58 Functions
CVSS 9.4
CVE-2024-3411 CRITICAL
Dell iDRAC8 - Insufficient Entropy in IPMI Session Authentication
CVSS 9.1
CVE-2024-26329 MEDIUM
Chilkat <9.5.0.98 - Info Disclosure
CVSS 6.2
CVE-2024-25730 CRITICAL
Hitron CODA-4582/4589 - Info Disclosure
CVSS 9.8
CVE-2024-22473 MEDIUM
Gecko SDK < 4.4.0 - Signature Spoofing via Insufficient TRNG Entropy
CVSS 6.8
CVE-2024-25407 HIGH
SteVe 3.6.0 - Denial of Service via Predictable Transaction ID
CVSS 7.5
CVE-2023-37822 HIGH
Eufy Homebase 2 <3.3.4.1h - Info Disclosure
CVSS 8.2
CVE-2023-49927 MEDIUM
Samsung Mobile Processor - Info Disclosure
CVSS 5.3
CVE-2023-49599 CRITICAL
WWBN AVideo - Insufficient Entropy in Salt Generation
CVSS 9.8
CVE-2023-46648 HIGH
GitHub Enterprise Server <3.8.12-3.11.1 - Info Disclosure
CVSS 8.3
CVE-2023-26154 MEDIUM
PubNub <7.4.0, <6.19.0, <7.3.0, <6.1.0, <5.3.0, <0.4.0 - Path Trave...
CVSS 5.9
CVE-2023-31176 HIGH
SEL-451 Firmware r315-v0 to r315-v4 - Unauthenticated Authentication Bypass via Session Token Brute-Force
CVSS 7.5
CVE-2023-31582 HIGH
jose4j < 0.9.3 - Insufficient Entropy via Low Iteration Count
CVSS 7.5
CVE-2023-34973 LOW
QNAP QTS 5.0.1-5.0.1.2424 and QTS 5.1.0-5.1.0.2443 - Insufficient Entropy
CVSS 3.1
CVE-2023-4344 CRITICAL
Broadcom RAID Controller - Info Disclosure
CVSS 9.8
CVE-2023-38357 MEDIUM
RWS WorldServer <11.7.3 - Info Disclosure
CVSS 5.3
CVE-2023-36610 MEDIUM
Ovarro TBox Firmware < 1.50.598 - Insufficient Entropy in Security Token Generation
CVSS 5.9
CVE-2023-3325 HIGH
CMS Commander < 2.287 - Unauthenticated Authorization Bypass via Insufficient Cryptographic Signature
CVSS 8.1
CVE-2023-20107 HIGH
Cisco ASA/FTD - Cryptographic Collision
CVSS 7.5
CVE-2022-43755 HIGH
SUSE Rancher <2.6.10-2.7.1 - Info Disclosure
CVSS 7.1
CVE-2022-20941 MEDIUM
Cisco Firepower Management Center - Unauthenticated Sensitive Information Disclosure via Resource Enumeration
CVSS 5.3
CVE-2022-34746 MEDIUM
Zyxel GS1900 <V2.70 - Info Disclosure
CVSS 5.9
CVE-2022-33989 MEDIUM
dproxy-nexgen - Insufficient Entropy in UDP Source Port Selection
CVSS 5.3
Details
Vulnerabilities 135