Fallos del tipo CWE-327

401 resultados

Uso de algoritmo criptográfico fraco ou quebrado

É quando o código utiliza algoritmos de criptografia que foram comprometidos, obsoletos ou nunca foram seguros (como MD5, DES, SHA-1 em contextos sensíveis). Esses algoritmos permitem que um atacante recupere dados criptografados com esforço computacional viável, invalidando a proteção que deveriam oferecer.

Ejemplo

Uma aplicação bancária que criptografa senhas usando MD5 ou MD5(senha + salt), ou que negocia conexão HTTPS com suporte a TLS 1.0. Em ambos os casos, ferramentas públicas conseguem quebrar a proteção em horas ou minutos.

Cómo mitigar

Use algoritmos atuais: SHA-256+ (ou bcrypt/scrypt) para hashing de senhas, AES-256 para dados em repouso, e TLS 1.2+ (idealmente 1.3) para trânsito. Revise regularmente o padrão NIST ou recomendações do OWASP e retire suporte a algoritmos deprecados das suas dependências e configurações.

CVE-2025-26486MEDIUMBroken or Risky Cryptographic Algorithm, Use of Password Hash With Insufficient Computational Effort, Use of Weak Hash, Use of a One-Way HEPSS 0.1%CVE-2025-65951HIGHInside Track / Entropy Derby Timelock Encryption Bypassed via Pre-Computed VDF Output LeakageEPSS 0.1%CVE-2025-14763MEDIUMMissing cryptographic key commitment in the Amazon S3 Encryption Client for Java may allow a user with write access to the S3 bucket to intrEPSS 0.1%CVE-2025-41223MEDIUMA vulnerability has been identified in RUGGEDCOM i800 (All versions), RUGGEDCOM i801 (All versions), RUGGEDCOM i802 (All versions), RUGGEDCOEPSS 0.1%CVE-2024-1040MEDIUMUse of a Broken or Risky Cryptographic Algorithm in Gessler GmbH WEB-MASTEREPSS 0.1%CVE-2024-49784MEDIUMIBM OpenPages with Watson information disclosureEPSS 0.1%CVE-2026-44405LOWIn Paramiko through 4.0.0 before a448945, rsakey.py allows the SHA-1 algorithm.EPSS 0.1%CVE-2024-55539LOWWeak algorithm used to sign RPM package. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux) before build 39185, EPSS 0.1%CVE-2025-64429MEDIUMDuckDB Encryption Crypto implementation is vulnerableEPSS 0.1%CVE-2025-36591MEDIUMDell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.4.0.0, contains an Use of a Broken or Risky CryptographiEPSS 0.1%CVE-2026-8470HIGHLangflow is affected by weaknesses in secret handling and sensitive configuration accessEPSS 0.1%CVE-2026-81859MEDIUMMultiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation iFixes for August 2026.EPSS 0.1%CVE-2026-6412LOWContinued acceptance of SHA-1/MD5 digests in certificate processingEPSS 0.1%CVE-2025-14859HIGHSemtech LR11xx Secure Boot BypassEPSS 0.1%CVE-2025-14764MEDIUMMissing cryptographic key commitment in the Amazon S3 Encryption Client for Go may allow a user with write access to the S3 bucket to introdEPSS 0.1%CVE-2019-3700LOWyast: Fallback to DES without configuration in /etc/login.defEPSS 0.1%CVE-2023-23347MEDIUMUse of a broken cryptographic algorithm affects HCL DRYiCE iAutomateEPSS 0.1%CVE-2025-14759MEDIUMMissing cryptographic key commitment in the Amazon S3 Encryption Client for .NET may allow a user with write access to the S3 bucket to intrEPSS 0.1%CVE-2026-49323MEDIUMIndian Scout Bobber 2025 WCM-to-ECM weak authenticationEPSS 0.1%CVE-2026-10783LOWgradio-app gradio Audio Cache Key save_audio_to_cache weak hashEPSS 0.1%