Falhas do tipo CWE-326

195 resultados

Criptografia com força inadequada

Ocorre quando um desenvolvedor implementa criptografia, mas usa algoritmos, tamanhos de chave ou modos de operação insuficientes para proteger dados sensíveis contra força bruta ou criptoanálise. Um exemplo clássico é usar DES em vez de AES, ou chaves RSA de 512 bits quando o padrão mínimo aceitável é 2048 bits.

Exemplo

Uma aplicação que armazena senhas usando MD5 ou SHA-1 sem salt, ou que criptografa dados de cartão de crédito com AES-128 quando deveria ser AES-256. Um atacante consegue quebrar essas chaves com recursos computacionais modernos em tempo viável.

Como mitigar

Use algoritmos criptográficos modernos e fortes: AES-256 para simetria, RSA-2048 (ou superiores) para assimetria, bcrypt/Argon2 para hashing de senhas, e sempre com salt ou IV aleatório. Siga as recomendações de órgãos como NIST ou BSI para tamanhos mínimos de chave.

CVE-2025-11935MEDIUMForward Secrecy Violation in WolfSSL TLS 1.3EPSS 0.2%CVE-2024-38867HIGHA vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V9.64), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 EPSS 0.2%CVE-2024-54089HIGHA vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions), APOGEE PXC Series (P2 Ethernet) (All versions), TALON TC SEPSS 0.2%CVE-2026-74889CRITICALopenssl_encrypt before 1.4.0 Weak Key Derivation via HKDFEPSS 0.2%CVE-2024-30119LOWHCL DRYiCE Optibot Reset Station is impacted by a missing Strict Transport Security HeaderEPSS 0.2%CVE-2023-34337HIGHInadequate Encryption StrengthEPSS 0.2%CVE-2021-27450SSH server configuration file does not implement some best practices. This could lead to a weakening of the SSH protocol strength, which couEPSS 0.2%CVE-2019-18263An issue was found in Philips Veradius Unity, Pulsera, and Endura Dual WAN Router, Veradius Unity (718132) with wireless option (shipped betEPSS 0.2%CVE-2026-49852HIGHjoserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of CVE-2026-45363)EPSS 0.2%CVE-2025-9239MEDIUMelunez eladmin DES Key EncryptUtils.java EncryptUtils inadequate encryptionEPSS 0.2%CVE-2023-21444HIGHImproper cryptographic implementation in Samsung Flow for PC 4.9.14.0 allows adjacent attackers to decrypt encrypted messages or inject commEPSS 0.2%CVE-2023-21443HIGHImproper cryptographic implementation in Samsung Flow for Android prior to version 4.9.04 allows adjacent attackers to decrypt encrypted mesEPSS 0.2%CVE-2025-36106MEDIUMIBM Cognos Analytics Mobile (iOS) information disclosureEPSS 0.2%CVE-2026-35146MEDIUMHCL DFXServer is affected by an Unencrypted Communication vulnerability.EPSS 0.2%CVE-2020-10125NCR SelfServ ATMs running APTRA XFS 04.02.01 and 05.01.00 implement 512-bit RSA certificates to validate bunch note acceptor (BNA) software EPSS 0.2%CVE-2023-1764MEDIUMCanon IJ Network Tool/Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),IJ Network Tool/Ver.4.7.3 and earlier (supported OS: OS X 1EPSS 0.2%CVE-2024-40719MEDIUMCHANGING Information Technology TCBServiSign Windows Version - Inadequate Encryption StrengthEPSS 0.2%CVE-2021-38121HIGHWeak communication protocol identified in Advance Authentication client applicationEPSS 0.2%CVE-2022-32753MEDIUMIBM Security Verify Directory information disclosureEPSS 0.2%CVE-2025-46409HIGHInadequate encryption strength issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier). If this vulnerability is eEPSS 0.2%