Weaknesses of type CWE-326

196 results

Força criptográfica inadequada

A aplicação usa algoritmos ou tamanhos de chave criptográfica insuficientes para proteger dados sensíveis contra ataques conhecidos. Por exemplo, usar DES, MD5 ou chaves RSA de 512 bits fornece proteção que pode ser quebrada em tempo viável com poder computacional moderno, deixando dados expostos.

Example

Um sistema de autenticação que armazena senhas hasheadas com MD5, ou uma API que criptografa dados com DES em vez de AES-256. Um atacante com acesso aos hashes consegue recuperar as senhas por força bruta, ou quebra a criptografia DES em horas.

How to mitigate

Use algoritmos reconhecidos como seguro (AES-256 para cifra simétrica, RSA 2048+ ou ECDSA para assimétrica, bcrypt/scrypt/argon2 para senhas). Revise regularmente o padrão criptográfico da sua stack — o que era seguro em 2015 pode estar comprometido hoje.

CVE-2024-13026MEDIUMInadequate Encryption Strength Vulnerability in Roche Algo EdgeEPSS 0.1%CVE-2022-38659MEDIUMHCL BigFix Platform is affected by insecure credential storageEPSS 0.1%CVE-2023-4333—Broadcom RAID Controller web interface doesn’t enforce SSL cipher ordering by serverEPSS 0.1%CVE-2025-45770HIGHjwt v5.4.3 was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key lengths are expected to be seEPSS 0.1%CVE-2026-44523CRITICALNote Mark: JWT Secret Weakness allows Full Account Takeover via token forgeryEPSS 0.1%CVE-2026-17520MEDIUMNewsletters < 4.17 - Unauthenticated API Access via Predictable API KeyEPSS 0.1%CVE-2024-1224HIGHInformation Disclosure Vulnerability in CDAC USB PratirodhEPSS 0.1%CVE-2026-4648MEDIUMInsufficient Encryption Level in CasfID Servicios Tecnológicos NFC WristbandsEPSS 0.1%CVE-2026-39349LOWOrangeHRM Uses AES-ECB for Sensitive Data Encryption Enables Pattern DisclosureEPSS 0.1%CVE-2023-33283MEDIUMMarval MSM through 14.19.0.12476 uses a static encryption key for secrets. An attacker that gains access to encrypted secrets can decrypt thEPSS 0.1%CVE-2026-45787MEDIUMelecterm's encrypt method not safe enoughEPSS 0.1%CVE-2023-34971HIGHQTS, QuTS heroEPSS 0.1%CVE-2026-5889MEDIUMCryptographic Flaw in PDFium in Google Chrome prior to 147.0.7727.55 allowed an attacker to read potentially sensitive information from encrEPSS 0.1%CVE-2020-16235LOWEmerson OpenEnterprise - Inadequate Encryption StrengthEPSS 0.1%CVE-2026-86824MEDIUMNewsletter < 9.3.8 - Unauthenticated Subscriber PII Disclosure and Modification via Predictable Tracking Signature KeyEPSS 0.1%CVE-2022-1318MEDIUMHills ComNav Inadequate Encryption StrengthEPSS 0.1%CVE-2025-39889HIGHBluetooth: l2cap: Check encryption key size on incoming connectionEPSS 0.1%CVE-2023-21145—In updatePictureInPictureMode of ActivityRecord.java, there is a possible bypass of background launch restrictions due to a logic error in tEPSS 0.1%CVE-2026-5363MEDIUMUse of weak cryptographic key in TP-Link Archer C7EPSS 0.1%CVE-2023-2197LOWVault Enterprise Vulnerable to Padding Oracle Attacks When Using a CBC-based Encryption Mechanism with a HSMEPSS 0.1%