Fallos del tipo CWE-327

401 resultados

Uso de algoritmo criptográfico fraco ou quebrado

É quando o código utiliza algoritmos de criptografia que foram comprometidos, obsoletos ou nunca foram seguros (como MD5, DES, SHA-1 em contextos sensíveis). Esses algoritmos permitem que um atacante recupere dados criptografados com esforço computacional viável, invalidando a proteção que deveriam oferecer.

Ejemplo

Uma aplicação bancária que criptografa senhas usando MD5 ou MD5(senha + salt), ou que negocia conexão HTTPS com suporte a TLS 1.0. Em ambos os casos, ferramentas públicas conseguem quebrar a proteção em horas ou minutos.

Cómo mitigar

Use algoritmos atuais: SHA-256+ (ou bcrypt/scrypt) para hashing de senhas, AES-256 para dados em repouso, e TLS 1.2+ (idealmente 1.3) para trânsito. Revise regularmente o padrão NIST ou recomendações do OWASP e retire suporte a algoritmos deprecados das suas dependências e configurações.

CVE-2024-36440MEDIUMAn issue was discovered on Swissphone DiCal-RED 4009 devices. An attacker with access to the file /etc/deviceconfig may recover the administEPSS 0.3%CVE-2026-50086CRITICALAqara unauthenticated AES oracleEPSS 0.3%CVE-2024-4282HIGHWeak TLS Ciphers on Brocade SANnav OVA SSH port 22EPSS 0.3%CVE-2025-24007HIGHA vulnerability has been identified in SIRIUS 3RK3 Modular Safety System (MSS) (All versions), SIRIUS Safety Relays 3SK2 (All versions). AffEPSS 0.3%CVE-2025-14175MEDIUMWeak Algorithm Support in SSH Server on TL-WR820NEPSS 0.3%CVE-2025-14636MEDIUMTenda AX9 httpd image_check weak hashEPSS 0.3%CVE-2024-22463HIGHDell PowerScale OneFS 8.2.x through 9.6.0.x contains a use of a broken or risky cryptographic algorithm vulnerability. A remote unprivilegedEPSS 0.3%CVE-2024-53441CRITICALAn issue in the index.js decryptCookie function of cookie-encrypter v1.0.1 allows attackers to execute a bit flipping attack.EPSS 0.3%CVE-2026-13482MEDIUMskypilot-org skypilot User ID server.py username.encode weak hashEPSS 0.3%CVE-2023-28509HIGHWeak encryption in UniRPC protocolEPSS 0.3%CVE-2024-39731MEDIUMIBM Datacap Navigator information disclosureEPSS 0.3%CVE-2026-63761MEDIUMSurrealDB before 3.1.0 Algorithm Downgrade via ES512EPSS 0.3%CVE-2026-17467HIGHVulnerabilities exists in IBM Cloud Pak for Data SystemEPSS 0.3%CVE-2024-28972MEDIUMDell InsightIQ, Verion 5.0.0, contains a use of a broken or risky cryptographic algorithm vulnerability. An unauthenticated remote attacker EPSS 0.3%CVE-2024-21670MEDIUMCL-Signatures Revocation Scheme in Ursa has flaws that allow a holder to demonstrate non-revocation of a revoked credentialEPSS 0.3%CVE-2022-38391MEDIUMIBM Spectrum Control information disclosureEPSS 0.3%CVE-2024-4765HIGHWeb application manifests were stored by using an insecure MD5 hash which allowed for a hash collision to overwrite another application's maEPSS 0.3%CVE-2020-4874MEDIUMIBM Cognos Controller information disclosureEPSS 0.3%CVE-2023-40696MEDIUMIBM Cognos Controller information disclosureEPSS 0.3%CVE-2025-62514HIGH`libparsec_crypto` does not check for weak order point of curve 25519EPSS 0.3%