Fallos del tipo CWE-757

36 resultados

Degradação de Algoritmo de Segurança em Negociação

É quando um protocolo ou aplicação permite que cliente e servidor acordem usar um algoritmo criptográfico mais fraco do que o disponível, tipicamente para manter compatibilidade com versões antigas. O atacante força ou explora essa negociação para rebaixar a segurança e quebrar a criptografia mais facilmente.

Ejemplo

Um cliente TLS oferece tanto TLS 1.3 (seguro) quanto SSL 3.0 (quebrado há anos). Um atacante na rede intercepta a negociação, descarta as opções modernas e força o servidor a aceitar SSL 3.0, permitindo descriptografar o tráfego via ataques conhecidos como POODLE.

Cómo mitigar

Configure cliente e servidor para recusar algoritmos deprecados e versões de protocolo antigas — nunca deixe fallback automático para cifras fracas. Nos clientes, sempre priorize e valide apenas algoritmos modernos; nos servidores, bloqueie conexões que insistirem em protocolos obsoletos.

CVE-2022-33160LOWIBM Security Directory Suite information disclosureEPSS 0.3%CVE-2026-53712HIGHSCRAM: Silent channel-binding authentication downgrade via unsupported certificate algorithmsEPSS 0.3%CVE-2026-4942MEDIUMIBM i is Affected by Algorithm Downgrade in Transport Layer Security []EPSS 0.2%CVE-2026-48747MEDIUMSymfony: Mailomat Mailer Webhook Parser Reads the HMAC Algorithm from the Request: Signature Algorithm DowngradeEPSS 0.2%CVE-2026-1677MEDIUMnet: TLS 1.2 connections allowed on TLS 1.3 socketsEPSS 0.2%CVE-2025-36582MEDIUMDell NetWorker, versions 19.12.0.1 and prior, contains a Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade') vulneEPSS 0.2%CVE-2026-54780LOWCoreWCF: WS-Security Reference DigestMethod Algorithm-Suite BypassEPSS 0.2%CVE-2026-54291HIGHSilent channel-binding authentication downgrade via unsupported certificate algorithmsEPSS 0.2%CVE-2025-59270LOWpsPAS does not enforce TLS 1.2 within Get-PASSAMLResponseEPSS 0.2%CVE-2026-55953CRITICALTLS 1.2 and DTLS client accepts unoffered anonymous cipher suite, bypassing server authenticationEPSS 0.2%CVE-2026-89177HIGHHowyar|WeenyGenius - Use of Insecure ProtocolEPSS 0.2%CVE-2026-18691CRITICALImproper Authentication in MongoDB Intra-Cluster Connections Allows Credential ExposureEPSS 0.2%CVE-2026-59293MEDIUMSMB minimum protocol dialect defaults to SMB1EPSS 0.2%CVE-2026-32650HIGHAnviz CrossChex Standard Algorithm DowngradeEPSS 0.2%CVE-2022-23000HIGHWeak Default SSL use in Port Forwarding ServiceEPSS 0.2%CVE-2026-6550MEDIUMKey commitment policy bypass via shared key cache in AWS Encryption SDK for PythonEPSS 0.1%