Fallos del tipo CWE-327

401 resultados

Uso de algoritmo criptográfico fraco ou quebrado

É quando o código utiliza algoritmos de criptografia que foram comprometidos, obsoletos ou nunca foram seguros (como MD5, DES, SHA-1 em contextos sensíveis). Esses algoritmos permitem que um atacante recupere dados criptografados com esforço computacional viável, invalidando a proteção que deveriam oferecer.

Ejemplo

Uma aplicação bancária que criptografa senhas usando MD5 ou MD5(senha + salt), ou que negocia conexão HTTPS com suporte a TLS 1.0. Em ambos os casos, ferramentas públicas conseguem quebrar a proteção em horas ou minutos.

Cómo mitigar

Use algoritmos atuais: SHA-256+ (ou bcrypt/scrypt) para hashing de senhas, AES-256 para dados em repouso, e TLS 1.2+ (idealmente 1.3) para trânsito. Revise regularmente o padrão NIST ou recomendações do OWASP e retire suporte a algoritmos deprecados das suas dependências e configurações.

CVE-2026-26219CRITICALnewbee-mall Unsalted MD5 Password Hashing Enables Offline Credential CrackingEPSS 0.2%CVE-2026-54147MEDIUMhttp4k: `DigestAuthProvider.verify` ignored configured algorithm and did not bind to request URIEPSS 0.2%CVE-2024-31896MEDIUMIBM SPSS Statistics information disclosureEPSS 0.2%CVE-2024-45671MEDIUMIBM Security Verify Information Queue information disclosureEPSS 0.2%CVE-2024-26317MEDIUMIn illumos illumos-gate 2024-02-15, an error occurs in the elliptic curve point addition algorithm that uses mixed Jacobian-affine coordinatEPSS 0.2%CVE-2026-5682MEDIUMMeesho Online Shopping App com.meesho.supply endpoint risky encryptionEPSS 0.2%CVE-2026-7103MEDIUMcode-projects Chat System MD5 Hash update_user.php weak hashEPSS 0.2%CVE-2025-49756LOWOffice Developer Platform Security Feature Bypass VulnerabilityEPSS 0.2%CVE-2026-27519HIGHBinardat 10G08-0800GSM Network Switch Hard-coded RC4 Encryption KeyEPSS 0.2%CVE-2025-27458MEDIUMCVE-2025-27458EPSS 0.2%CVE-2026-66407HIGHDEEBOT PRO M1 and DEEBOT PRO K1VAC improperly implement authentication in WebSocket communication. The WebSocket private key may be retrievEPSS 0.2%CVE-2026-9261HIGHUse of weak SSH cryptographic algorithms in Canon EOS Network Setting Tool Version 1.5.0 or earlierEPSS 0.2%CVE-2025-43723MEDIUMDell PowerScale OneFS, versions prior to 9.10.1.3 and versions 9.11.0.0 through 9.12.0.0, contains a use of a broken or risky cryptographic EPSS 0.2%CVE-2026-8803MEDIUMopensourcepos Open Source Point of Sale Employee Login Employee.php login weak hashEPSS 0.2%CVE-2025-2545LOWDeprecated 3DES cryptographic algorithm used by Request Tracker in emails encrypted with S/MIMEEPSS 0.2%CVE-2026-5926MEDIUMSecurity vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify AccessEPSS 0.2%CVE-2024-5559MEDIUMCWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists that could cause denial of service, device reboot, or an attaEPSS 0.2%CVE-2026-28479HIGHOpenClaw < 2026.2.15 - Cache Poisoning via Deprecated SHA-1 Hash in Sandbox ConfigurationEPSS 0.2%CVE-2026-81438LOWDell OpenManage Server Administrator, versions prior to 11.1.0.3, contains Use of a Broken or Risky Cryptographic Algorithm vulnerability. AEPSS 0.2%CVE-2026-27871LOWTL280EPSS 0.2%