Falhas do tipo CWE-326

195 resultados

Criptografia com força inadequada

Ocorre quando um desenvolvedor implementa criptografia, mas usa algoritmos, tamanhos de chave ou modos de operação insuficientes para proteger dados sensíveis contra força bruta ou criptoanálise. Um exemplo clássico é usar DES em vez de AES, ou chaves RSA de 512 bits quando o padrão mínimo aceitável é 2048 bits.

Exemplo

Uma aplicação que armazena senhas usando MD5 ou SHA-1 sem salt, ou que criptografa dados de cartão de crédito com AES-128 quando deveria ser AES-256. Um atacante consegue quebrar essas chaves com recursos computacionais modernos em tempo viável.

Como mitigar

Use algoritmos criptográficos modernos e fortes: AES-256 para simetria, RSA-2048 (ou superiores) para assimetria, bcrypt/Argon2 para hashing de senhas, e sempre com salt ou IV aleatório. Siga as recomendações de órgãos como NIST ou BSI para tamanhos mínimos de chave.

CVE-2025-9513MEDIUMeditso fuso mod.rs PenetrateRsaAndAesHandshake inadequate encryptionEPSS 0.2%CVE-2024-23579MEDIUMHCL DRYiCE Optibot Reset Station is impacted by insecure encryption of security questionsEPSS 0.1%CVE-2024-23580MEDIUMHCL DRYiCE Optibot Reset Station is impacted by insecure encryption of One-Time Passwords (OTPs)EPSS 0.1%CVE-2025-36379MEDIUMIBM Security QRadar EDR Software has multiple vulnerabilitiesEPSS 0.1%CVE-2023-54356CRITICALKyverno before 1.9.5 Sweet32 Medium Strength Cipher SuitesEPSS 0.1%CVE-2014-2381Schneider Electric Wonderware Inadequate Encryption StrengthEPSS 0.1%CVE-2026-0510LOWObsolete Encryption Algorithm Used in NW AS Java UME User MappingEPSS 0.1%CVE-2025-43925MEDIUMAn issue was discovered in Unicom Focal Point 7.6.1. The database is encrypted with a hardcoded key, making it easier to recover the clearteEPSS 0.1%CVE-2025-45769MEDIUMphp-jwt v6.11.0 was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key lengths are expected to EPSS 0.1%CVE-2022-40745MEDIUMIBM Aspera Faspex information disclosureEPSS 0.1%CVE-2025-2516CRITICALUse of a weak cryptographic key in the signature verification process in WPS OfficeEPSS 0.1%CVE-2026-79084MEDIUMInadequate encryption strength in Notifications in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker leveraging sEPSS 0.1%CVE-2024-25102HIGHInformation Disclosure Vulnerability in CDAC AppSamvid SoftwareEPSS 0.1%CVE-2026-81718HIGHopenssl_encrypt before 1.4.9 Weak Cryptographic ParametersEPSS 0.1%CVE-2025-68703HIGHJervis has a Salt for PBKDF2 derived from passwordEPSS 0.1%CVE-2022-34385MEDIUM SupportAssist for Home PCs (version 3.11.4 and prior) and  SupportAssist for Business PCs (version 3.2.0 and prior) contain cryptographic wEPSS 0.1%CVE-2026-50044HIGHInadequate Encryption Strength in Panduit IntraVUE by PronetiqsEPSS 0.1%CVE-2024-28974HIGHDell Data Protection Advisor, version(s) 19.9, contain(s) an Inadequate Encryption Strength vulnerability. A low privileged attacker with reEPSS 0.1%CVE-2023-21109HIGHIn multiple places of AccessibilityService, there is a possible way to hide the app from the user due to a logic error in the code. This couEPSS 0.1%CVE-2024-13026MEDIUMInadequate Encryption Strength Vulnerability in Roche Algo EdgeEPSS 0.1%