Falhas do tipo CWE-326

195 resultados

Criptografia com força inadequada

Ocorre quando um desenvolvedor implementa criptografia, mas usa algoritmos, tamanhos de chave ou modos de operação insuficientes para proteger dados sensíveis contra força bruta ou criptoanálise. Um exemplo clássico é usar DES em vez de AES, ou chaves RSA de 512 bits quando o padrão mínimo aceitável é 2048 bits.

Exemplo

Uma aplicação que armazena senhas usando MD5 ou SHA-1 sem salt, ou que criptografa dados de cartão de crédito com AES-128 quando deveria ser AES-256. Um atacante consegue quebrar essas chaves com recursos computacionais modernos em tempo viável.

Como mitigar

Use algoritmos criptográficos modernos e fortes: AES-256 para simetria, RSA-2048 (ou superiores) para assimetria, bcrypt/Argon2 para hashing de senhas, e sempre com salt ou IV aleatório. Siga as recomendações de órgãos como NIST ou BSI para tamanhos mínimos de chave.

CVE-2024-43382MEDIUMSnowflake JDBC driver versions >= 3.2.6 and <= 3.19.1 have an Incorrect Security Setting that can result in data being uploaded to an encrypEPSS 0.2%CVE-2022-41209MEDIUMSAP Customer Data Cloud (Gigya mobile app for Android) - version 7.4, uses encryption method which lacks proper diffusion and does not hide EPSS 0.2%CVE-2024-28860HIGHInsecure IPsec transport encryption in CiliumEPSS 0.2%CVE-2023-4129MEDIUM Dell Data Protection Central, version 19.9, contains an Inadequate Encryption Strength Vulnerability. An unauthenticated network attacker cEPSS 0.2%CVE-2024-3387MEDIUMPAN-OS: Weak Certificate Strength in Panorama Software Leads to Sensitive Information DisclosureEPSS 0.2%CVE-2023-32414The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.4. An app may be able to break out of its sandbox.EPSS 0.2%CVE-2026-33361HIGHMeari weak XOR obfuscationEPSS 0.2%CVE-2024-42177LOWHCL MyXalytics is affected by SSL∕TLS Protocol affected with BREACH & LUCKY13 vulnerabilitiesEPSS 0.2%CVE-2026-59651HIGHBKS keystore accepts legacy version with 16-bit integrity MAC keyEPSS 0.2%CVE-2024-29951MEDIUMBrocade SANnav has weak encryption in internal SSH portsEPSS 0.2%CVE-2025-45765CRITICALruby-jwt v3.0.0.beta1 was discovered to contain weak encryption. NOTE: the Supplier's perspective is "keysize is not something that is enforEPSS 0.2%CVE-2025-7398HIGHMedium Strength Cipher Suites detected on port on ports 9000 and 8036EPSS 0.2%CVE-2024-41681MEDIUMA vulnerability has been identified in Location Intelligence family (All versions < V4.4). The web server of affected products is configuredEPSS 0.2%CVE-2022-21139HIGHInadequate encryption strength for some Intel(R) PROSet/Wireless WiFi products may allow an unauthenticated user to potentially enable escalEPSS 0.2%CVE-2018-19001Philips HealthSuite Health Android App, all versions. The software uses simple encryption that is not strong enough for the level of protectEPSS 0.2%CVE-2024-37034MEDIUMAn issue was discovered in Couchbase Server before 7.2.5 and 7.6.0 before 7.6.1. It does not ensure that credentials are negotiated with theEPSS 0.2%CVE-2025-2349LOWIROAD Dash Cam FX2 Password Hash passwd weak password hashEPSS 0.2%CVE-2025-27524MEDIUMWeak encryption vulnerability in JP1/IT Desktop Management 2 - Smart Device ManagerEPSS 0.2%CVE-2026-28377HIGHS3 SSE-C Encryption Key Exposed in Plaintext via Config Endpoint (CVE-2025-41118 Pattern)EPSS 0.2%CVE-2023-31135LOWDgraph Audit Log Encryption nonce reuseEPSS 0.2%