Falhas do tipo CWE-327

401 resultados

Uso de algoritmo criptográfico quebrado ou inseguro

A aplicação usa um algoritmo de criptografia que já foi criptanaliticamente quebrado ou é considerado inseguro para o caso de uso. Isso expõe dados sensíveis a decriptação não autorizada, mesmo que o código implemente corretamente a biblioteca criptográfica escolhida.

Exemplo

Um sistema de autenticação usa MD5 ou SHA1 para hash de senhas, ou uma API de pagamento trafega dados com DES ou RC4 em vez de AES. Um atacante consegue recuperar a senha original via força bruta ou quebra criptanalítica em tempo viável.

Como mitigar

Use apenas algoritmos criptográficos modernos e bem mantidos: SHA-256+ para hash, AES-256 para cifra simétrica, RSA-2048+ ou ECDP-256+ para assimétrica. Audite regularmente o stack criptográfico e mantenha dependências atualizadas; remova suporte a algoritmos legados em produção.

CVE-2026-26219CRITICALnewbee-mall Unsalted MD5 Password Hashing Enables Offline Credential CrackingEPSS 0.2%CVE-2026-54147MEDIUMhttp4k: `DigestAuthProvider.verify` ignored configured algorithm and did not bind to request URIEPSS 0.2%CVE-2024-31896MEDIUMIBM SPSS Statistics information disclosureEPSS 0.2%CVE-2024-45671MEDIUMIBM Security Verify Information Queue information disclosureEPSS 0.2%CVE-2024-26317MEDIUMIn illumos illumos-gate 2024-02-15, an error occurs in the elliptic curve point addition algorithm that uses mixed Jacobian-affine coordinatEPSS 0.2%CVE-2026-7103MEDIUMcode-projects Chat System MD5 Hash update_user.php weak hashEPSS 0.2%CVE-2026-5682MEDIUMMeesho Online Shopping App com.meesho.supply endpoint risky encryptionEPSS 0.2%CVE-2025-27458MEDIUMCVE-2025-27458EPSS 0.2%CVE-2026-27519HIGHBinardat 10G08-0800GSM Network Switch Hard-coded RC4 Encryption KeyEPSS 0.2%CVE-2025-49756LOWOffice Developer Platform Security Feature Bypass VulnerabilityEPSS 0.2%CVE-2026-9261HIGHUse of weak SSH cryptographic algorithms in Canon EOS Network Setting Tool Version 1.5.0 or earlierEPSS 0.2%CVE-2026-66407HIGHDEEBOT PRO M1 and DEEBOT PRO K1VAC improperly implement authentication in WebSocket communication. The WebSocket private key may be retrievEPSS 0.2%CVE-2025-43723MEDIUMDell PowerScale OneFS, versions prior to 9.10.1.3 and versions 9.11.0.0 through 9.12.0.0, contains a use of a broken or risky cryptographic EPSS 0.2%CVE-2026-8803MEDIUMopensourcepos Open Source Point of Sale Employee Login Employee.php login weak hashEPSS 0.2%CVE-2025-2545LOWDeprecated 3DES cryptographic algorithm used by Request Tracker in emails encrypted with S/MIMEEPSS 0.2%CVE-2026-5926MEDIUMSecurity vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify AccessEPSS 0.2%CVE-2024-5559MEDIUMCWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists that could cause denial of service, device reboot, or an attaEPSS 0.2%CVE-2026-28479HIGHOpenClaw < 2026.2.15 - Cache Poisoning via Deprecated SHA-1 Hash in Sandbox ConfigurationEPSS 0.2%CVE-2026-81438LOWDell OpenManage Server Administrator, versions prior to 11.1.0.3, contains Use of a Broken or Risky Cryptographic Algorithm vulnerability. AEPSS 0.2%CVE-2023-50313MEDIUMIBM WebSphere Application Server information disclosureEPSS 0.2%