CWE-331

Insufficient Entropy

Parent: CWE-330 - Use of Insufficiently Random Values

The product uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.

135 vulnerabilities with CWE-331
CVE-2022-34294 CRITICAL
totd 1.5.3 - Insufficient Entropy in DNS Query Source Port
CVSS 9.8
CVE-2022-37401 HIGH
Apache OpenOffice <4.1.13 - Info Disclosure
CVSS 8.8
CVE-2022-33738 HIGH
OpenVPN Access Server <2.11 - Info Disclosure
CVSS 7.5
CVE-2022-31034 HIGH
Argo CD 0.11.0-2.1.16 - Insufficient Entropy in OAuth2/OIDC Login Flow Parameters
CVSS 8.3
CVE-2022-33756 HIGH
CA Automic Automation <12.3 - Info Disclosure
CVSS 7.5
CVE-2021-4238 CRITICAL
RandomAlphaNumeric - Info Disclosure
CVSS 9.1
CVE-2021-4241 LOW
phpservermon < 3.6.0 - Insufficient Entropy in User Login Token Generation
CVSS 2.6
CVE-2021-4240 LOW
phpservermon - Predictable Algorithm
CVSS 2.6
CVE-2021-41615 CRITICAL
GoAhead WebServer <2.1.8 - Info Disclosure
CVSS 9.8
CVE-2021-22799 LOW
Schneider Electric Software Update <2.5.1 - SSRF
CVSS 3.8
CVE-2021-36294 CRITICAL
Dell VNX2 OE for File <8.1.21.266 - Auth Bypass
CVSS 9.8
CVE-2021-42138 HIGH
SafeNet Agent for Windows Logon - Info Disclosure
CVSS 7.2
CVE-2021-36320 HIGH
Dell Networking X-Series <3.0.1.8 - Auth Bypass
CVSS 7.5
CVE-2021-31798 MEDIUM
CyberArk Credential Provider <12.1 - Info Disclosure
CVSS 4.4
CVE-2021-31797 MEDIUM
CyberArk Credential Provider < 12.1 - Password Disclosure via Local Host Race Condition
CVSS 5.1
CVE-2021-22727 CRITICAL
EVlink City/EVlink Parking/EVlink Smart Wallbox <R8 V3.4.0.1 - Info...
CVSS 9.8
CVE-2021-33027 CRITICAL
Sylabs Singularity Enterprise <1.6.2 - Info Disclosure
CVSS 9.8
CVE-2021-29471 LOW
Synapse < 1.33.2 - Denial of Service via Push Rule Event Match Pattern
CVSS 3.7
CVE-2021-3505 MEDIUM
libtpms < 0.8.0 - Insufficient Entropy in RSA Key Generation
CVSS 5.5
CVE-2020-36925 CRITICAL
Arteco Web Client DVR/NVR - Auth Bypass
CVSS 9.8
CVE-2020-36732 MEDIUM
crypto-js < 3.2.1 - Insufficient Entropy in Random Number Generation
CVSS 5.3
CVE-2020-29508 MEDIUM
Dell BSAFE <4.1.5-4.6 - Info Disclosure
CVSS 5.3
CVE-2020-29505 HIGH
Dell BSAFE <4.1.5-4.5.2 - Info Disclosure
CVSS 7.1
CVE-2020-25926 HIGH
InterNiche NicheStack TCP/IP 4.0.1 - DNS Cache Poisoning
CVSS 7.5
CVE-2020-28924 HIGH
rclone < 1.53.3 - Insufficient Entropy in Password Generator
CVSS 7.5
Details
Vulnerabilities 135