Fallos del tipo CWE-326

195 resultados

Força de criptografia inadequada

A aplicação usa algoritmos ou tamanhos de chave criptográficos abaixo do padrão de segurança esperado para o contexto, deixando dados sensíveis vulneráveis a força bruta ou ataques criptanalíticos. Mesmo que o código implemente criptografia, uma chave pequena ou algoritmo fraco torna a proteção ineficaz.

Ejemplo

Um sistema bancário que salva senhas criptografadas com DES de 56 bits em vez de AES-256, ou que usa chaves RSA de 512 bits para certificados HTTPS. Um atacante com recursos moderados quebra essas chaves em horas ou dias.

Cómo mitigar

Use algoritmos modernos e reconhecidos (AES-256 para simétrico, RSA-2048+ ou curvas elípticas para assimétrico). Valide e atualize periodicamente o tamanho de chaves conforme recomendações de órgãos como NIST. Em Java/Python/.NET, prefira bibliotecas padrão (javax.crypto, cryptography, System.Security.Cryptography) e evite implementações caseiras.

CVE-2025-11935MEDIUMForward Secrecy Violation in WolfSSL TLS 1.3EPSS 0.2%CVE-2024-38867HIGHA vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V9.64), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 EPSS 0.2%CVE-2024-54089HIGHA vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions), APOGEE PXC Series (P2 Ethernet) (All versions), TALON TC SEPSS 0.2%CVE-2026-74889CRITICALopenssl_encrypt before 1.4.0 Weak Key Derivation via HKDFEPSS 0.2%CVE-2024-30119LOWHCL DRYiCE Optibot Reset Station is impacted by a missing Strict Transport Security HeaderEPSS 0.2%CVE-2023-34337HIGHInadequate Encryption StrengthEPSS 0.2%CVE-2021-27450SSH server configuration file does not implement some best practices. This could lead to a weakening of the SSH protocol strength, which couEPSS 0.2%CVE-2019-18263An issue was found in Philips Veradius Unity, Pulsera, and Endura Dual WAN Router, Veradius Unity (718132) with wireless option (shipped betEPSS 0.2%CVE-2026-49852HIGHjoserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of CVE-2026-45363)EPSS 0.2%CVE-2025-9239MEDIUMelunez eladmin DES Key EncryptUtils.java EncryptUtils inadequate encryptionEPSS 0.2%CVE-2023-21444HIGHImproper cryptographic implementation in Samsung Flow for PC 4.9.14.0 allows adjacent attackers to decrypt encrypted messages or inject commEPSS 0.2%CVE-2023-21443HIGHImproper cryptographic implementation in Samsung Flow for Android prior to version 4.9.04 allows adjacent attackers to decrypt encrypted mesEPSS 0.2%CVE-2025-36106MEDIUMIBM Cognos Analytics Mobile (iOS) information disclosureEPSS 0.2%CVE-2026-35146MEDIUMHCL DFXServer is affected by an Unencrypted Communication vulnerability.EPSS 0.2%CVE-2020-10125NCR SelfServ ATMs running APTRA XFS 04.02.01 and 05.01.00 implement 512-bit RSA certificates to validate bunch note acceptor (BNA) software EPSS 0.2%CVE-2023-1764MEDIUMCanon IJ Network Tool/Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),IJ Network Tool/Ver.4.7.3 and earlier (supported OS: OS X 1EPSS 0.2%CVE-2024-40719MEDIUMCHANGING Information Technology TCBServiSign Windows Version - Inadequate Encryption StrengthEPSS 0.2%CVE-2021-38121HIGHWeak communication protocol identified in Advance Authentication client applicationEPSS 0.2%CVE-2022-32753MEDIUMIBM Security Verify Directory information disclosureEPSS 0.2%CVE-2025-46409HIGHInadequate encryption strength issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier). If this vulnerability is eEPSS 0.2%