Fallos del tipo CWE-327

401 resultados

Uso de algoritmo criptográfico fraco ou quebrado

É quando o código utiliza algoritmos de criptografia que foram comprometidos, obsoletos ou nunca foram seguros (como MD5, DES, SHA-1 em contextos sensíveis). Esses algoritmos permitem que um atacante recupere dados criptografados com esforço computacional viável, invalidando a proteção que deveriam oferecer.

Ejemplo

Uma aplicação bancária que criptografa senhas usando MD5 ou MD5(senha + salt), ou que negocia conexão HTTPS com suporte a TLS 1.0. Em ambos os casos, ferramentas públicas conseguem quebrar a proteção em horas ou minutos.

Cómo mitigar

Use algoritmos atuais: SHA-256+ (ou bcrypt/scrypt) para hashing de senhas, AES-256 para dados em repouso, e TLS 1.2+ (idealmente 1.3) para trânsito. Revise regularmente o padrão NIST ou recomendações do OWASP e retire suporte a algoritmos deprecados das suas dependências e configurações.

CVE-2025-68698HIGHJervis has an RSA PKCS#1 v1.5 Padding VulnerabilityEPSS 0.1%CVE-2025-37127HIGHAuthenticated Replay Attack contains Cryptographic VulnerabilityEPSS 0.1%CVE-2026-25834MEDIUMMbed TLS v3.3.0 up to 3.6.5 and 4.0.0 allows Algorithm Downgrade.EPSS 0.1%CVE-2025-63912MEDIUMCohesity TranZman Migration Appliance Release 4.0 Build 14614 was discovered to use a weak cryptography algorithm for data encryption, allowEPSS 0.1%CVE-2023-41927MEDIUMWeak TLS Cipher Suites Supported in Kiloview P1/P2 devicesEPSS 0.1%CVE-2025-3838MEDIUMImproper Authorization in the installer for the EOL OVA based connect componentEPSS 0.1%CVE-2023-41928MEDIUMRemote server offers deprecated TLS protocol in Kiloview P1/P2 devicesEPSS 0.1%CVE-2025-45766HIGHpoco v1.14.1-release was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key lengths are expecteEPSS 0.1%CVE-2022-24403MEDIUMDe-anonymization attack in TETRAEPSS 0.1%CVE-2024-22458LOWDell Secure Connect Gateway, 5.18, contains an Inadequate Encryption Strength Vulnerability. An unauthenticated network attacker could potenEPSS 0.1%CVE-2025-2920LOWNetis WF-2404 passwd weak hashEPSS 0.1%CVE-2026-16693MEDIUMIBM i is Affected By Cryptographic Algorithm Weakness in DCM []EPSS 0.1%CVE-2026-40996MEDIUMInbound WS-Security allows RSA PKCS#1 v1.5 key transport by defaultEPSS 0.1%CVE-2025-26708MEDIUMZTELink has a configuration defect vulnerabilityEPSS 0.1%CVE-2026-24785HIGHClatter has a PSK Validity Rule Violation issueEPSS 0.1%CVE-2024-41986MEDIUMA vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Audit (All versions >=EPSS 0.1%CVE-2025-59484HIGHAutomationDirect CLICK PLUS Use of a Broken or Risky Cryptographic AlgorithmEPSS 0.1%CVE-2023-40371MEDIUMIBM AIX information disclosureEPSS 0.1%CVE-2023-35890MEDIUMIBM WebSphere Application Server information disclosureEPSS 0.1%CVE-2022-35720LOWIBM Sterling External Authentication Server information disclosureEPSS 0.1%