Fallos del tipo CWE-327

401 resultados

Uso de algoritmo criptográfico fraco ou quebrado

É quando o código utiliza algoritmos de criptografia que foram comprometidos, obsoletos ou nunca foram seguros (como MD5, DES, SHA-1 em contextos sensíveis). Esses algoritmos permitem que um atacante recupere dados criptografados com esforço computacional viável, invalidando a proteção que deveriam oferecer.

Ejemplo

Uma aplicação bancária que criptografa senhas usando MD5 ou MD5(senha + salt), ou que negocia conexão HTTPS com suporte a TLS 1.0. Em ambos os casos, ferramentas públicas conseguem quebrar a proteção em horas ou minutos.

Cómo mitigar

Use algoritmos atuais: SHA-256+ (ou bcrypt/scrypt) para hashing de senhas, AES-256 para dados em repouso, e TLS 1.2+ (idealmente 1.3) para trânsito. Revise regularmente o padrão NIST ou recomendações do OWASP e retire suporte a algoritmos deprecados das suas dependências e configurações.

CVE-2024-35537HIGHTVS Motor Company Limited TVS Connect Android v4.6.0 and IOS v5.0.0 was discovered to insecurely handle the RSA key pair, allowing attackersEPSS 0.3%CVE-2025-9828MEDIUMTenda CP6 uhttp sub_2B7D04 risky encryptionEPSS 0.3%CVE-2023-28043MEDIUM Dell SCG 5.14 contains an information disclosure vulnerability during the SRS to SCG upgrade path. A remote low privileged malicious user cEPSS 0.3%CVE-2023-50939MEDIUMIBM PowerSC information DisclosureEPSS 0.3%CVE-2024-8603HIGHA “Use of a Broken or Risky Cryptographic Algorithm” vulnerability in the SSL/TLS component used in B&R Automation Runtime versions before 6EPSS 0.3%CVE-2020-11031HIGHInsecure encryption algorithm in GLPIEPSS 0.3%CVE-2024-22347MEDIUMIBM UrbanCode Velocity information disclosureEPSS 0.3%CVE-2024-22361MEDIUMIBM Semeru Runtime information disclosureEPSS 0.3%CVE-2021-41278MEDIUMBroken encryption in app-functions-sdk “AES” transform in EdgeX Foundry releases prior to Jakarta allows attackers to decrypt messages via unspecified vectorsEPSS 0.3%CVE-2022-34757MEDIUMA CWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists where weak cipher suites can be used for the SSH connectionEPSS 0.3%CVE-2023-0296MEDIUMThe Birthday attack against 64-bit block ciphers flaw (CVE-2016-2183) was reported for the health checks port (9979) on etcd grpc-proxy compEPSS 0.3%CVE-2024-25963MEDIUMDell PowerScale OneFS, versions 8.2.2.x through 9.5.0.x contains a use of a broken cryptographic algorithm vulnerability. A remote unauthentEPSS 0.3%CVE-2025-14813CRITICALGOSTCTR implementation unable to process more than 255 blocks correctlyEPSS 0.3%CVE-2023-50937MEDIUMIBM PowerSC information disclosureEPSS 0.3%CVE-2024-22192MEDIUMUrsa CL-Signatures Revocation allows verifiers to generate unique identifiers for holdersEPSS 0.3%CVE-2021-33846MEDIUMFresenius Kabi Agilia Connect Infusion System use of a broken or risky cryptographic algorithmEPSS 0.3%CVE-2023-5627HIGHIncorrect Implementation of Authentication Algorithm VulnerabilityEPSS 0.3%CVE-2022-46832MEDIUMUse of a Broken or Risky Cryptographic Algorithm in SICK RFU62x firmware version < 2.21 allows a low-privileged remote attacker to decrypt tEPSS 0.3%CVE-2022-46833MEDIUMUse of a Broken or Risky Cryptographic Algorithm in SICK RFU63x firmware version < v2.21 allows a low-privileged remote attacker to decrypt EPSS 0.3%CVE-2022-27581MEDIUMUse of a Broken or Risky Cryptographic Algorithm in SICK RFU61x firmware version <v2.25 allows a low-privileged remote attacker to decrypt tEPSS 0.3%