Weaknesses of type CWE-327

401 results

Uso de algoritmo criptográfico fraco ou quebrado

A aplicação usa algoritmos de criptografia que já foram quebrados ou são reconhecidamente fracos (como MD5, SHA-1, DES, RC4), deixando dados sensíveis vulneráveis a ataques práticos. Mesmo que o algoritmo ainda funcione tecnicamente, um adversário pode recuperar a mensagem ou falsificar assinaturas com esforço computacional viável.

Example

Um sistema armazena senhas de usuários com hash MD5, ou usa SHA-1 para assinar tokens JWT, ou criptografa dados financeiros com DES. Em todos esses casos, há ferramentas públicas que conseguem quebrar a proteção em horas ou dias.

How to mitigate

Substitua por algoritmos modernos: SHA-256 ou melhor para hash (ou Argon2/bcrypt para senhas), AES-256 para criptografia simétrica, ECDSA ou RSA-2048+ para assinaturas. Revise periodicamente o acervo de dependências e remova bibliotecas que só ofereçam primitivas fracas.

CVE-2022-46834MEDIUMUse of a Broken or Risky Cryptographic Algorithm in SICK RFU65x firmware version < v2.21 allows a low-privileged remote attacker to decrypt EPSS 0.3%CVE-2023-34130—SonicWall GMS and Analytics use outdated Tiny Encryption Algorithm (TEA) with a hardcoded key to encrypt sensitive data. This issue affects EPSS 0.3%CVE-2026-14738MEDIUMexo-explore exo Vision Feature Cache vision.py _image_cache_key weak hashEPSS 0.3%CVE-2023-22812HIGHSanDisk PrivateAccess Deprecated TLS protocol versions supportedEPSS 0.3%CVE-2025-41711MEDIUMUse of a Broken or Risky Cryptographic Algorithm for firmware images of power analyzerEPSS 0.3%CVE-2026-13510MEDIUMSimStudioAI sim Password Protection deployment.ts weak hashEPSS 0.3%CVE-2025-54426CRITICALPolkadot Frontier contains silent failure in Curve25519 arithmetic precompiles with malformed pointsEPSS 0.3%CVE-2024-41270CRITICALAn issue discovered in the RunHTTPServer function in Gorush v1.18.4 allows attackers to intercept and manipulate data due to use of deprecatEPSS 0.3%CVE-2025-34519HIGHIlevia EVE X1 Server 4.7.18.0.eden Insecure Hashing AlgorithmEPSS 0.3%CVE-2024-33663MEDIUMpython-jose through 3.3.0 has algorithm confusion with OpenSSH ECDSA keys and other key formats. This is similar to CVE-2022-29217.EPSS 0.3%CVE-2025-52026HIGHAn information disclosure vulnerability exists in the /srvs/membersrv/getCashiers endpoint of the Aptsys gemscms backend platform thru 2025-EPSS 0.3%CVE-2021-41835HIGHFresenius Kabi Agilia Connect Infusion System use of a broken or risky cryptographic algorithmEPSS 0.3%CVE-2026-44053HIGHWeak cryptography in DHCAST128 UAMEPSS 0.3%CVE-2024-39745MEDIUMIBM Sterling Connect:Direct Web Services information disclosureEPSS 0.3%CVE-2023-41097MEDIUMPotential Timing vulnerability in CBC PKCS7 padding calculationsEPSS 0.3%CVE-2024-45193MEDIUMAn issue was discovered in Matrix libolm through 3.2.16. There is Ed25519 signature malleability due to lack of validation criteria (does noEPSS 0.3%CVE-2026-77151MEDIUMlin-snow Ech0 crypto.go MD5Encrypt risky encryptionEPSS 0.3%CVE-2026-46395CRITICALHAX CMS Vulnerable to Private Key Disclosure via Broken HMAC ImplementationEPSS 0.3%CVE-2024-39583HIGHDell PowerScale InsightIQ, versions 5.0 through 5.1, contains a Use of a Broken or Risky Cryptographic Algorithm vulnerability. An unauthentEPSS 0.3%CVE-2023-36749HIGHA vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEEPSS 0.3%