Weaknesses of type CWE-327

401 results

Uso de algoritmo criptográfico fraco ou quebrado

A aplicação usa algoritmos de criptografia que já foram quebrados ou são reconhecidamente fracos (como MD5, SHA-1, DES, RC4), deixando dados sensíveis vulneráveis a ataques práticos. Mesmo que o algoritmo ainda funcione tecnicamente, um adversário pode recuperar a mensagem ou falsificar assinaturas com esforço computacional viável.

Example

Um sistema armazena senhas de usuários com hash MD5, ou usa SHA-1 para assinar tokens JWT, ou criptografa dados financeiros com DES. Em todos esses casos, há ferramentas públicas que conseguem quebrar a proteção em horas ou dias.

How to mitigate

Substitua por algoritmos modernos: SHA-256 ou melhor para hash (ou Argon2/bcrypt para senhas), AES-256 para criptografia simétrica, ECDSA ou RSA-2048+ para assinaturas. Revise periodicamente o acervo de dependências e remova bibliotecas que só ofereçam primitivas fracas.

CVE-2024-35537HIGHTVS Motor Company Limited TVS Connect Android v4.6.0 and IOS v5.0.0 was discovered to insecurely handle the RSA key pair, allowing attackersEPSS 0.3%CVE-2025-9828MEDIUMTenda CP6 uhttp sub_2B7D04 risky encryptionEPSS 0.3%CVE-2023-28043MEDIUM Dell SCG 5.14 contains an information disclosure vulnerability during the SRS to SCG upgrade path. A remote low privileged malicious user cEPSS 0.3%CVE-2023-50939MEDIUMIBM PowerSC information DisclosureEPSS 0.3%CVE-2024-8603HIGHA “Use of a Broken or Risky Cryptographic Algorithm” vulnerability in the SSL/TLS component used in B&R Automation Runtime versions before 6EPSS 0.3%CVE-2020-11031HIGHInsecure encryption algorithm in GLPIEPSS 0.3%CVE-2024-22347MEDIUMIBM UrbanCode Velocity information disclosureEPSS 0.3%CVE-2024-22361MEDIUMIBM Semeru Runtime information disclosureEPSS 0.3%CVE-2021-41278MEDIUMBroken encryption in app-functions-sdk “AES” transform in EdgeX Foundry releases prior to Jakarta allows attackers to decrypt messages via unspecified vectorsEPSS 0.3%CVE-2022-34757MEDIUMA CWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists where weak cipher suites can be used for the SSH connectionEPSS 0.3%CVE-2023-0296MEDIUMThe Birthday attack against 64-bit block ciphers flaw (CVE-2016-2183) was reported for the health checks port (9979) on etcd grpc-proxy compEPSS 0.3%CVE-2024-25963MEDIUMDell PowerScale OneFS, versions 8.2.2.x through 9.5.0.x contains a use of a broken cryptographic algorithm vulnerability. A remote unauthentEPSS 0.3%CVE-2025-14813CRITICALGOSTCTR implementation unable to process more than 255 blocks correctlyEPSS 0.3%CVE-2023-50937MEDIUMIBM PowerSC information disclosureEPSS 0.3%CVE-2024-22192MEDIUMUrsa CL-Signatures Revocation allows verifiers to generate unique identifiers for holdersEPSS 0.3%CVE-2021-33846MEDIUMFresenius Kabi Agilia Connect Infusion System use of a broken or risky cryptographic algorithmEPSS 0.3%CVE-2023-5627HIGHIncorrect Implementation of Authentication Algorithm VulnerabilityEPSS 0.3%CVE-2022-46832MEDIUMUse of a Broken or Risky Cryptographic Algorithm in SICK RFU62x firmware version < 2.21 allows a low-privileged remote attacker to decrypt tEPSS 0.3%CVE-2022-46833MEDIUMUse of a Broken or Risky Cryptographic Algorithm in SICK RFU63x firmware version < v2.21 allows a low-privileged remote attacker to decrypt EPSS 0.3%CVE-2022-27581MEDIUMUse of a Broken or Risky Cryptographic Algorithm in SICK RFU61x firmware version <v2.25 allows a low-privileged remote attacker to decrypt tEPSS 0.3%