Skip to main content

CWE archive

CWE-327 CVEs

Programmatic archive

685 CVEs tagged with CWE-32765 Critical, 256 High, 300 Medium, 64 Low, 0 Unrated.

CVE-2023-21115

Published Jun 15, 2023

In btm_sec_encrypt_change of btm_sec.cc, there is a possible way to downgrade the link key type due to improperly used crypto. This could lead to paired device escalation of privi…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-43949

Published Jun 13, 2023

A use of a broken or risky cryptographic algorithm [CWE-327] in Fortinet FortiSIEM before 6.7.1 allows a remote unauthenticated attacker to perform brute force attacks on GUI end…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-28043

Published Jun 1, 2023

Dell SCG 5.14 contains an information disclosure vulnerability during the SRS to SCG upgrade path. A remote low privileged malicious user could potentially exploit this vulnerabil…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-28076

Published May 16, 2023

CloudLink 7.1.2 and all prior versions contain a broken or risky cryptographic algorithm vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerabi…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-36937

Published May 10, 2023

HHVM 4.172.0 and all prior versions use TLS 1.0 for secure connections when handling tls:// URLs in the stream extension. TLS1.0 has numerous published vulnerabilities and is depr…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-22313

Published May 6, 2023

IBM QRadar Data Synchronization App 1.0 through 3.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-45858

Published May 3, 2023

A use of a weak cryptographic algorithm vulnerability [CWE-327] in FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.0 all versions, 8.8.0 all versions, 8.7.0 all versions may increa…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-27557

Published Apr 28, 2023

IBM Counter Fraud Management for Safer Payments 6.1.0.00 through 6.1.1.02, 6.2.0.00 through 6.2.2.02, 6.3.0.00 through 6.3.1.02, 6.4.0.00 through 6.4.2.01, and 6.5.0.00 uses weake…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-45170

Published Apr 14, 2023

An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Cryptographic Issue can occur under the /api/v1/vencrypt/decrypt/file endpoint. A malicious user, logged int…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-22812

Published Mar 24, 2023

SanDisk PrivateAccess versions prior to 6.4.9 support insecure TLS 1.0 and TLS 1.1 protocols which are susceptible to man-in-the-middle attacks thereby compromising confidentialit…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2023-23695

Published Feb 17, 2023

Dell Secure Connect Gateway (SCG) version 5.14.00.12 contains a broken cryptographic algorithm vulnerability. A remote unauthenticated attacker could potentially exploit this vuln…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-34444

Published Feb 11, 2023

Dell PowerScale OneFS, versions 9.2.0.x through 9.4.0.x contain an information vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to cause…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-0452

Published Jan 26, 2023

Econolite EOS versions prior to 3.2.23 use a weak hash algorithm for encrypting privileged user credentials. A configuration file that is accessible without authentication uses MD…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-0296

Published Jan 17, 2023

The Birthday attack against 64-bit block ciphers flaw (CVE-2016-2183) was reported for the health checks port (9979) on etcd grpc-proxy component. Even though the CVE-2016-2183 ha…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-36647

Published Jan 17, 2023

Use of a Broken or Risky Cryptographic Algorithm in the function mbedtls_mpi_exp_mod() in lignum.c in Mbed TLS Mbed TLS all versions before 3.0.0, 2.27.0 or 2.16.11 allows attacke…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort
Showing 301-325 of 685 CVEsPage 13 of 28