Fallos del tipo CWE-327

401 resultados

Uso de algoritmo criptográfico fraco ou quebrado

É quando o código utiliza algoritmos de criptografia que foram comprometidos, obsoletos ou nunca foram seguros (como MD5, DES, SHA-1 em contextos sensíveis). Esses algoritmos permitem que um atacante recupere dados criptografados com esforço computacional viável, invalidando a proteção que deveriam oferecer.

Ejemplo

Uma aplicação bancária que criptografa senhas usando MD5 ou MD5(senha + salt), ou que negocia conexão HTTPS com suporte a TLS 1.0. Em ambos os casos, ferramentas públicas conseguem quebrar a proteção em horas ou minutos.

Cómo mitigar

Use algoritmos atuais: SHA-256+ (ou bcrypt/scrypt) para hashing de senhas, AES-256 para dados em repouso, e TLS 1.2+ (idealmente 1.3) para trânsito. Revise regularmente o padrão NIST ou recomendações do OWASP e retire suporte a algoritmos deprecados das suas dependências e configurações.

CVE-2026-11929HIGHSecurity vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify AccessEPSS 0.2%CVE-2025-43909LOWDell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2025 releasEPSS 0.2%CVE-2026-11479LOWyoanbernabeu grepai Qdrant Backend chunker.go weak hashEPSS 0.2%CVE-2026-6411HIGHMAXHUB Pivot Client Application Use of a Broken or Risky Cryptographic AlgorithmEPSS 0.2%CVE-2026-67336CRITICALbetter-auth before 1.6.11 Insecure Cryptographic Defaults via oidcProviderEPSS 0.2%CVE-2025-66598HIGHA vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product supports old SSL/TLS versions, potenEPSS 0.2%CVE-2025-11650LOWTomofun Furbo 360/Furbo Mini Password shadow weak hashEPSS 0.2%CVE-2024-52884HIGHAn issue was discovered in AudioCodes Mediant Session Border Controller (SBC) before 7.40A.501.841. Due to the use of weak password obfuscatEPSS 0.2%CVE-2024-48016MEDIUMDell Secure Connect Gateway (SCG) 5.0 Appliance - SRS, version(s) 5.24, contains a Use of a Broken or Risky Cryptographic Algorithm vulnerabEPSS 0.2%CVE-2026-56582LOWHCL MyCloud was affected with SSL/TLS Protocol Affected with LUCKY13 Vulnerability.EPSS 0.2%CVE-2023-50350HIGHA broken cryptographic algorithm impacts MyXalyticsEPSS 0.2%CVE-2024-47921HIGHSmadar SPS – CWE-327: Use of a Broken or Risky Cryptographic AlgorithmEPSS 0.2%CVE-2026-65309HIGHStorage of passwords in a reversible formatEPSS 0.2%CVE-2026-8072CRITICALInsecure generation of SAT access credentials in Ingecon EMS BoardEPSS 0.2%CVE-2021-3446A flaw was found in libtpms in versions before 0.8.2. The commonly used integration of libtpms with OpenSSL contained a vulnerability relateEPSS 0.1%CVE-2025-45767HIGHjose v6.0.10 was discovered to contain weak encryption. NOTE: this is disputed by a third party because the claim of "do not meet recommendeEPSS 0.1%CVE-2024-43178MEDIUMMultiple Vulnerabilities in IBM Concert Software.EPSS 0.1%CVE-2026-28490HIGHAuthlib Vulnerable to JWE RSA1_5 Bleichenbacher Padding OracleEPSS 0.1%CVE-2026-7845LOWchatchat-space Langchain-Chatchat Vision Chat Paste Image dialogue.py PIL.Image.tobytes weak hashEPSS 0.1%CVE-2025-34500HIGHShuffle Master Deck Mate 2 Insecure Update ChainEPSS 0.1%