Weaknesses of type CWE-326

196 results

Força criptográfica inadequada

A aplicação usa algoritmos ou tamanhos de chave criptográfica insuficientes para proteger dados sensíveis contra ataques conhecidos. Por exemplo, usar DES, MD5 ou chaves RSA de 512 bits fornece proteção que pode ser quebrada em tempo viável com poder computacional moderno, deixando dados expostos.

Example

Um sistema de autenticação que armazena senhas hasheadas com MD5, ou uma API que criptografa dados com DES em vez de AES-256. Um atacante com acesso aos hashes consegue recuperar as senhas por força bruta, ou quebra a criptografia DES em horas.

How to mitigate

Use algoritmos reconhecidos como seguro (AES-256 para cifra simétrica, RSA 2048+ ou ECDSA para assimétrica, bcrypt/scrypt/argon2 para senhas). Revise regularmente o padrão criptográfico da sua stack — o que era seguro em 2015 pode estar comprometido hoje.

CVE-2024-43382MEDIUMSnowflake JDBC driver versions >= 3.2.6 and <= 3.19.1 have an Incorrect Security Setting that can result in data being uploaded to an encrypEPSS 0.2%CVE-2022-41209MEDIUMSAP Customer Data Cloud (Gigya mobile app for Android) - version 7.4, uses encryption method which lacks proper diffusion and does not hide EPSS 0.2%CVE-2024-28860HIGHInsecure IPsec transport encryption in CiliumEPSS 0.2%CVE-2023-4129MEDIUM Dell Data Protection Central, version 19.9, contains an Inadequate Encryption Strength Vulnerability. An unauthenticated network attacker cEPSS 0.2%CVE-2024-3387MEDIUMPAN-OS: Weak Certificate Strength in Panorama Software Leads to Sensitive Information DisclosureEPSS 0.2%CVE-2023-32414—The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.4. An app may be able to break out of its sandbox.EPSS 0.2%CVE-2026-33361HIGHMeari weak XOR obfuscationEPSS 0.2%CVE-2024-42177LOWHCL MyXalytics is affected by SSL∕TLS Protocol affected with BREACH & LUCKY13 vulnerabilitiesEPSS 0.2%CVE-2024-29951MEDIUMBrocade SANnav has weak encryption in internal SSH portsEPSS 0.2%CVE-2026-59651HIGHBKS keystore accepts legacy version with 16-bit integrity MAC keyEPSS 0.2%CVE-2025-45765CRITICALruby-jwt v3.0.0.beta1 was discovered to contain weak encryption. NOTE: the Supplier's perspective is "keysize is not something that is enforEPSS 0.2%CVE-2025-7398HIGHMedium Strength Cipher Suites detected on port on ports 9000 and 8036EPSS 0.2%CVE-2024-41681MEDIUMA vulnerability has been identified in Location Intelligence family (All versions < V4.4). The web server of affected products is configuredEPSS 0.2%CVE-2022-21139HIGHInadequate encryption strength for some Intel(R) PROSet/Wireless WiFi products may allow an unauthenticated user to potentially enable escalEPSS 0.2%CVE-2024-37034MEDIUMAn issue was discovered in Couchbase Server before 7.2.5 and 7.6.0 before 7.6.1. It does not ensure that credentials are negotiated with theEPSS 0.2%CVE-2018-19001—Philips HealthSuite Health Android App, all versions. The software uses simple encryption that is not strong enough for the level of protectEPSS 0.2%CVE-2025-27524MEDIUMWeak encryption vulnerability in JP1/IT Desktop Management 2 - Smart Device ManagerEPSS 0.2%CVE-2025-2349LOWIROAD Dash Cam FX2 Password Hash passwd weak password hashEPSS 0.2%CVE-2026-28377HIGHS3 SSE-C Encryption Key Exposed in Plaintext via Config Endpoint (CVE-2025-41118 Pattern)EPSS 0.2%CVE-2023-31135LOWDgraph Audit Log Encryption nonce reuseEPSS 0.2%