Weaknesses of type CWE-326

196 results

Força criptográfica inadequada

A aplicação usa algoritmos ou tamanhos de chave criptográfica insuficientes para proteger dados sensíveis contra ataques conhecidos. Por exemplo, usar DES, MD5 ou chaves RSA de 512 bits fornece proteção que pode ser quebrada em tempo viável com poder computacional moderno, deixando dados expostos.

Example

Um sistema de autenticação que armazena senhas hasheadas com MD5, ou uma API que criptografa dados com DES em vez de AES-256. Um atacante com acesso aos hashes consegue recuperar as senhas por força bruta, ou quebra a criptografia DES em horas.

How to mitigate

Use algoritmos reconhecidos como seguro (AES-256 para cifra simétrica, RSA 2048+ ou ECDSA para assimétrica, bcrypt/scrypt/argon2 para senhas). Revise regularmente o padrão criptográfico da sua stack — o que era seguro em 2015 pode estar comprometido hoje.

CVE-2023-31135LOWDgraph Audit Log Encryption nonce reuseEPSS 0.2%CVE-2024-23579MEDIUMHCL DRYiCE Optibot Reset Station is impacted by insecure encryption of security questionsEPSS 0.1%CVE-2024-23580MEDIUMHCL DRYiCE Optibot Reset Station is impacted by insecure encryption of One-Time Passwords (OTPs)EPSS 0.1%CVE-2025-36379MEDIUMIBM Security QRadar EDR Software has multiple vulnerabilitiesEPSS 0.1%CVE-2023-54356CRITICALKyverno before 1.9.5 Sweet32 Medium Strength Cipher SuitesEPSS 0.1%CVE-2014-2381—Schneider Electric Wonderware Inadequate Encryption StrengthEPSS 0.1%CVE-2026-0510LOWObsolete Encryption Algorithm Used in NW AS Java UME User MappingEPSS 0.1%CVE-2022-40745MEDIUMIBM Aspera Faspex information disclosureEPSS 0.1%CVE-2025-43925MEDIUMAn issue was discovered in Unicom Focal Point 7.6.1. The database is encrypted with a hardcoded key, making it easier to recover the clearteEPSS 0.1%CVE-2025-45769MEDIUMphp-jwt v6.11.0 was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key lengths are expected to EPSS 0.1%CVE-2025-2516CRITICALUse of a weak cryptographic key in the signature verification process in WPS OfficeEPSS 0.1%CVE-2026-79084MEDIUMInadequate encryption strength in Notifications in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker leveraging sEPSS 0.1%CVE-2024-25102HIGHInformation Disclosure Vulnerability in CDAC AppSamvid SoftwareEPSS 0.1%CVE-2026-81718HIGHopenssl_encrypt before 1.4.9 Weak Cryptographic ParametersEPSS 0.1%CVE-2025-68703HIGHJervis has a Salt for PBKDF2 derived from passwordEPSS 0.1%CVE-2026-50044HIGHInadequate Encryption Strength in Panduit IntraVUE by PronetiqsEPSS 0.1%CVE-2022-34385MEDIUM SupportAssist for Home PCs (version 3.11.4 and prior) and  SupportAssist for Business PCs (version 3.2.0 and prior) contain cryptographic wEPSS 0.1%CVE-2024-28974HIGHDell Data Protection Advisor, version(s) 19.9, contain(s) an Inadequate Encryption Strength vulnerability. A low privileged attacker with reEPSS 0.1%CVE-2023-21109HIGHIn multiple places of AccessibilityService, there is a possible way to hide the app from the user due to a logic error in the code. This couEPSS 0.1%CVE-2025-1241MEDIUMEncryption vulnerable to brute-force decryption in GoAnywhere MFTEPSS 0.1%