Weaknesses of type CWE-327

401 results

Uso de algoritmo criptográfico fraco ou quebrado

A aplicação usa algoritmos de criptografia que já foram quebrados ou são reconhecidamente fracos (como MD5, SHA-1, DES, RC4), deixando dados sensíveis vulneráveis a ataques práticos. Mesmo que o algoritmo ainda funcione tecnicamente, um adversário pode recuperar a mensagem ou falsificar assinaturas com esforço computacional viável.

Example

Um sistema armazena senhas de usuários com hash MD5, ou usa SHA-1 para assinar tokens JWT, ou criptografa dados financeiros com DES. Em todos esses casos, há ferramentas públicas que conseguem quebrar a proteção em horas ou dias.

How to mitigate

Substitua por algoritmos modernos: SHA-256 ou melhor para hash (ou Argon2/bcrypt para senhas), AES-256 para criptografia simétrica, ECDSA ou RSA-2048+ para assinaturas. Revise periodicamente o acervo de dependências e remova bibliotecas que só ofereçam primitivas fracas.

CVE-2024-36440MEDIUMAn issue was discovered on Swissphone DiCal-RED 4009 devices. An attacker with access to the file /etc/deviceconfig may recover the administEPSS 0.3%CVE-2026-50086CRITICALAqara unauthenticated AES oracleEPSS 0.3%CVE-2024-4282HIGHWeak TLS Ciphers on Brocade SANnav OVA SSH port 22EPSS 0.3%CVE-2025-24007HIGHA vulnerability has been identified in SIRIUS 3RK3 Modular Safety System (MSS) (All versions), SIRIUS Safety Relays 3SK2 (All versions). AffEPSS 0.3%CVE-2025-14175MEDIUMWeak Algorithm Support in SSH Server on TL-WR820NEPSS 0.3%CVE-2025-14636MEDIUMTenda AX9 httpd image_check weak hashEPSS 0.3%CVE-2024-22463HIGHDell PowerScale OneFS 8.2.x through 9.6.0.x contains a use of a broken or risky cryptographic algorithm vulnerability. A remote unprivilegedEPSS 0.3%CVE-2024-53441CRITICALAn issue in the index.js decryptCookie function of cookie-encrypter v1.0.1 allows attackers to execute a bit flipping attack.EPSS 0.3%CVE-2026-13482MEDIUMskypilot-org skypilot User ID server.py username.encode weak hashEPSS 0.3%CVE-2023-28509HIGHWeak encryption in UniRPC protocolEPSS 0.3%CVE-2024-39731MEDIUMIBM Datacap Navigator information disclosureEPSS 0.3%CVE-2026-63761MEDIUMSurrealDB before 3.1.0 Algorithm Downgrade via ES512EPSS 0.3%CVE-2026-17467HIGHVulnerabilities exists in IBM Cloud Pak for Data SystemEPSS 0.3%CVE-2024-28972MEDIUMDell InsightIQ, Verion 5.0.0, contains a use of a broken or risky cryptographic algorithm vulnerability. An unauthenticated remote attacker EPSS 0.3%CVE-2024-21670MEDIUMCL-Signatures Revocation Scheme in Ursa has flaws that allow a holder to demonstrate non-revocation of a revoked credentialEPSS 0.3%CVE-2022-38391MEDIUMIBM Spectrum Control information disclosureEPSS 0.3%CVE-2024-4765HIGHWeb application manifests were stored by using an insecure MD5 hash which allowed for a hash collision to overwrite another application's maEPSS 0.3%CVE-2020-4874MEDIUMIBM Cognos Controller information disclosureEPSS 0.3%CVE-2023-40696MEDIUMIBM Cognos Controller information disclosureEPSS 0.3%CVE-2025-62514HIGH`libparsec_crypto` does not check for weak order point of curve 25519EPSS 0.3%