Fallos del tipo CWE-327

401 resultados

Uso de algoritmo criptográfico fraco ou quebrado

É quando o código utiliza algoritmos de criptografia que foram comprometidos, obsoletos ou nunca foram seguros (como MD5, DES, SHA-1 em contextos sensíveis). Esses algoritmos permitem que um atacante recupere dados criptografados com esforço computacional viável, invalidando a proteção que deveriam oferecer.

Ejemplo

Uma aplicação bancária que criptografa senhas usando MD5 ou MD5(senha + salt), ou que negocia conexão HTTPS com suporte a TLS 1.0. Em ambos os casos, ferramentas públicas conseguem quebrar a proteção em horas ou minutos.

Cómo mitigar

Use algoritmos atuais: SHA-256+ (ou bcrypt/scrypt) para hashing de senhas, AES-256 para dados em repouso, e TLS 1.2+ (idealmente 1.3) para trânsito. Revise regularmente o padrão NIST ou recomendações do OWASP e retire suporte a algoritmos deprecados das suas dependências e configurações.

CVE-2022-46834MEDIUMUse of a Broken or Risky Cryptographic Algorithm in SICK RFU65x firmware version < v2.21 allows a low-privileged remote attacker to decrypt EPSS 0.3%CVE-2023-34130SonicWall GMS and Analytics use outdated Tiny Encryption Algorithm (TEA) with a hardcoded key to encrypt sensitive data. This issue affects EPSS 0.3%CVE-2026-14738MEDIUMexo-explore exo Vision Feature Cache vision.py _image_cache_key weak hashEPSS 0.3%CVE-2023-22812HIGHSanDisk PrivateAccess Deprecated TLS protocol versions supportedEPSS 0.3%CVE-2025-41711MEDIUMUse of a Broken or Risky Cryptographic Algorithm for firmware images of power analyzerEPSS 0.3%CVE-2026-13510MEDIUMSimStudioAI sim Password Protection deployment.ts weak hashEPSS 0.3%CVE-2025-54426CRITICALPolkadot Frontier contains silent failure in Curve25519 arithmetic precompiles with malformed pointsEPSS 0.3%CVE-2024-41270CRITICALAn issue discovered in the RunHTTPServer function in Gorush v1.18.4 allows attackers to intercept and manipulate data due to use of deprecatEPSS 0.3%CVE-2025-34519HIGHIlevia EVE X1 Server 4.7.18.0.eden Insecure Hashing AlgorithmEPSS 0.3%CVE-2024-33663MEDIUMpython-jose through 3.3.0 has algorithm confusion with OpenSSH ECDSA keys and other key formats. This is similar to CVE-2022-29217.EPSS 0.3%CVE-2025-52026HIGHAn information disclosure vulnerability exists in the /srvs/membersrv/getCashiers endpoint of the Aptsys gemscms backend platform thru 2025-EPSS 0.3%CVE-2021-41835HIGHFresenius Kabi Agilia Connect Infusion System use of a broken or risky cryptographic algorithmEPSS 0.3%CVE-2026-44053HIGHWeak cryptography in DHCAST128 UAMEPSS 0.3%CVE-2024-39745MEDIUMIBM Sterling Connect:Direct Web Services information disclosureEPSS 0.3%CVE-2023-41097MEDIUMPotential Timing vulnerability in CBC PKCS7 padding calculationsEPSS 0.3%CVE-2024-45193MEDIUMAn issue was discovered in Matrix libolm through 3.2.16. There is Ed25519 signature malleability due to lack of validation criteria (does noEPSS 0.3%CVE-2026-77151MEDIUMlin-snow Ech0 crypto.go MD5Encrypt risky encryptionEPSS 0.3%CVE-2026-46395CRITICALHAX CMS Vulnerable to Private Key Disclosure via Broken HMAC ImplementationEPSS 0.3%CVE-2024-39583HIGHDell PowerScale InsightIQ, versions 5.0 through 5.1, contains a Use of a Broken or Risky Cryptographic Algorithm vulnerability. An unauthentEPSS 0.3%CVE-2023-36749HIGHA vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEEPSS 0.3%