Weaknesses of type CWE-326

196 results

Força criptográfica inadequada

A aplicação usa algoritmos ou tamanhos de chave criptográfica insuficientes para proteger dados sensíveis contra ataques conhecidos. Por exemplo, usar DES, MD5 ou chaves RSA de 512 bits fornece proteção que pode ser quebrada em tempo viável com poder computacional moderno, deixando dados expostos.

Example

Um sistema de autenticação que armazena senhas hasheadas com MD5, ou uma API que criptografa dados com DES em vez de AES-256. Um atacante com acesso aos hashes consegue recuperar as senhas por força bruta, ou quebra a criptografia DES em horas.

How to mitigate

Use algoritmos reconhecidos como seguro (AES-256 para cifra simétrica, RSA 2048+ ou ECDSA para assimétrica, bcrypt/scrypt/argon2 para senhas). Revise regularmente o padrão criptográfico da sua stack — o que era seguro em 2015 pode estar comprometido hoje.

CVE-2025-11935MEDIUMForward Secrecy Violation in WolfSSL TLS 1.3EPSS 0.2%CVE-2024-38867HIGHA vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V9.64), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 EPSS 0.2%CVE-2024-54089HIGHA vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions), APOGEE PXC Series (P2 Ethernet) (All versions), TALON TC SEPSS 0.2%CVE-2026-74889CRITICALopenssl_encrypt before 1.4.0 Weak Key Derivation via HKDFEPSS 0.2%CVE-2024-30119LOWHCL DRYiCE Optibot Reset Station is impacted by a missing Strict Transport Security HeaderEPSS 0.2%CVE-2023-34337HIGHInadequate Encryption StrengthEPSS 0.2%CVE-2021-27450—SSH server configuration file does not implement some best practices. This could lead to a weakening of the SSH protocol strength, which couEPSS 0.2%CVE-2019-18263—An issue was found in Philips Veradius Unity, Pulsera, and Endura Dual WAN Router, Veradius Unity (718132) with wireless option (shipped betEPSS 0.2%CVE-2026-49852HIGHjoserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of CVE-2026-45363)EPSS 0.2%CVE-2025-9239MEDIUMelunez eladmin DES Key EncryptUtils.java EncryptUtils inadequate encryptionEPSS 0.2%CVE-2023-21443HIGHImproper cryptographic implementation in Samsung Flow for Android prior to version 4.9.04 allows adjacent attackers to decrypt encrypted mesEPSS 0.2%CVE-2023-21444HIGHImproper cryptographic implementation in Samsung Flow for PC 4.9.14.0 allows adjacent attackers to decrypt encrypted messages or inject commEPSS 0.2%CVE-2025-36106MEDIUMIBM Cognos Analytics Mobile (iOS) information disclosureEPSS 0.2%CVE-2020-10125—NCR SelfServ ATMs running APTRA XFS 04.02.01 and 05.01.00 implement 512-bit RSA certificates to validate bunch note acceptor (BNA) software EPSS 0.2%CVE-2026-35146MEDIUMHCL DFXServer is affected by an Unencrypted Communication vulnerability.EPSS 0.2%CVE-2023-1764MEDIUMCanon IJ Network Tool/Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),IJ Network Tool/Ver.4.7.3 and earlier (supported OS: OS X 1EPSS 0.2%CVE-2024-40719MEDIUMCHANGING Information Technology TCBServiSign Windows Version - Inadequate Encryption StrengthEPSS 0.2%CVE-2021-38121HIGHWeak communication protocol identified in Advance Authentication client applicationEPSS 0.2%CVE-2022-32753MEDIUMIBM Security Verify Directory information disclosureEPSS 0.2%CVE-2025-46409HIGHInadequate encryption strength issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier). If this vulnerability is eEPSS 0.2%