The product uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.
131 vulnerabilities with CWE-331
CVE-2022-33756
HIGH
CA Automic Automation <12.3 - Info Disclosure
CVSS 7.5
CVE-2021-4238
CRITICAL
RandomAlphaNumeric - Info Disclosure
CVSS 9.1
CVE-2021-4241
LOW
phpservermon < 3.6.0 - Insufficient Entropy in User Login Token Generation
CVSS 2.6
CVE-2021-4240
LOW
phpservermon - Predictable Algorithm
CVSS 2.6
CVE-2021-41615
CRITICAL
GoAhead WebServer <2.1.8 - Info Disclosure
CVSS 9.8
CVE-2021-22799
LOW
Schneider Electric Software Update <2.5.1 - SSRF
CVSS 3.8
CVE-2021-36294
CRITICAL
Dell VNX2 OE for File <8.1.21.266 - Auth Bypass
CVSS 9.8
CVE-2021-42138
HIGH
SafeNet Agent for Windows Logon - Info Disclosure
CVSS 7.2
CVE-2021-36320
HIGH
Dell Networking X-Series <3.0.1.8 - Auth Bypass
CVSS 7.5
CVE-2021-31798
MEDIUM
CyberArk Credential Provider <12.1 - Info Disclosure
CVSS 4.4
CVE-2021-31797
MEDIUM
CyberArk Credential Provider < 12.1 - Password Disclosure via Local Host Race Condition
CVSS 5.1
CVE-2021-22727
CRITICAL
EVlink City/EVlink Parking/EVlink Smart Wallbox <R8 V3.4.0.1 - Info...
CVSS 9.8
CVE-2021-33027
CRITICAL
Sylabs Singularity Enterprise <1.6.2 - Info Disclosure
CVSS 9.8
CVE-2021-29471
LOW
Synapse < 1.33.2 - Denial of Service via Push Rule Event Match Pattern
CVSS 3.7
CVE-2021-3505
MEDIUM
libtpms < 0.8.0 - Insufficient Entropy in RSA Key Generation
CVSS 5.5
CVE-2020-36925
CRITICAL
Arteco Web Client DVR/NVR - Auth Bypass
CVSS 9.8
CVE-2020-36732
MEDIUM
crypto-js < 3.2.1 - Insufficient Entropy in Random Number Generation
CVSS 5.3
CVE-2020-29508
MEDIUM
Dell BSAFE <4.1.5-4.6 - Info Disclosure
CVSS 5.3
CVE-2020-29505
HIGH
Dell BSAFE <4.1.5-4.5.2 - Info Disclosure
CVSS 7.1
CVE-2020-25926
HIGH
InterNiche NicheStack TCP/IP 4.0.1 - DNS Cache Poisoning
CVSS 7.5
CVE-2020-28924
HIGH
rclone < 1.53.3 - Insufficient Entropy in Password Generator
CVSS 7.5
CVE-2020-10285
CRITICAL
xArm 5 Lite Firmware < 1.5.0 - Insufficient Entropy in Authentication
CVSS 9.8
CVE-2020-11957
HIGH
Cypress PSoC Creator BLE <3.64 - Info Disclosure
CVSS 7.5
CVE-2020-12735
CRITICAL
DomainMOD 4.13.0 - Insufficient Entropy in Password Reset Requests
CVSS 9.8
CVE-2020-1773
HIGH
OTRS 5.0.0-5.0.41 and 7.0.0-7.0.15 - Insufficient Entropy in Session ID and Token Generation
CVSS 7.3
Details
Vulnerabilities
131