Falhas do tipo CWE-327

401 resultados

Uso de algoritmo criptográfico quebrado ou inseguro

A aplicação usa um algoritmo de criptografia que já foi criptanaliticamente quebrado ou é considerado inseguro para o caso de uso. Isso expõe dados sensíveis a decriptação não autorizada, mesmo que o código implemente corretamente a biblioteca criptográfica escolhida.

Exemplo

Um sistema de autenticação usa MD5 ou SHA1 para hash de senhas, ou uma API de pagamento trafega dados com DES ou RC4 em vez de AES. Um atacante consegue recuperar a senha original via força bruta ou quebra criptanalítica em tempo viável.

Como mitigar

Use apenas algoritmos criptográficos modernos e bem mantidos: SHA-256+ para hash, AES-256 para cifra simétrica, RSA-2048+ ou ECDP-256+ para assimétrica. Audite regularmente o stack criptográfico e mantenha dependências atualizadas; remova suporte a algoritmos legados em produção.

CVE-2025-43909LOWDell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2025 releasEPSS 0.2%CVE-2026-11929HIGHSecurity vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify AccessEPSS 0.2%CVE-2026-11479LOWyoanbernabeu grepai Qdrant Backend chunker.go weak hashEPSS 0.2%CVE-2026-67336CRITICALbetter-auth before 1.6.11 Insecure Cryptographic Defaults via oidcProviderEPSS 0.2%CVE-2026-6411HIGHMAXHUB Pivot Client Application Use of a Broken or Risky Cryptographic AlgorithmEPSS 0.2%CVE-2025-66598HIGHA vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product supports old SSL/TLS versions, potenEPSS 0.2%CVE-2025-11650LOWTomofun Furbo 360/Furbo Mini Password shadow weak hashEPSS 0.2%CVE-2024-48016MEDIUMDell Secure Connect Gateway (SCG) 5.0 Appliance - SRS, version(s) 5.24, contains a Use of a Broken or Risky Cryptographic Algorithm vulnerabEPSS 0.2%CVE-2024-52884HIGHAn issue was discovered in AudioCodes Mediant Session Border Controller (SBC) before 7.40A.501.841. Due to the use of weak password obfuscatEPSS 0.2%CVE-2026-56582LOWHCL MyCloud was affected with SSL/TLS Protocol Affected with LUCKY13 Vulnerability.EPSS 0.2%CVE-2023-50350HIGHA broken cryptographic algorithm impacts MyXalyticsEPSS 0.2%CVE-2024-47921HIGHSmadar SPS – CWE-327: Use of a Broken or Risky Cryptographic AlgorithmEPSS 0.2%CVE-2026-65309HIGHStorage of passwords in a reversible formatEPSS 0.2%CVE-2026-8072CRITICALInsecure generation of SAT access credentials in Ingecon EMS BoardEPSS 0.2%CVE-2021-3446A flaw was found in libtpms in versions before 0.8.2. The commonly used integration of libtpms with OpenSSL contained a vulnerability relateEPSS 0.1%CVE-2025-45767HIGHjose v6.0.10 was discovered to contain weak encryption. NOTE: this is disputed by a third party because the claim of "do not meet recommendeEPSS 0.1%CVE-2024-43178MEDIUMMultiple Vulnerabilities in IBM Concert Software.EPSS 0.1%CVE-2026-28490HIGHAuthlib Vulnerable to JWE RSA1_5 Bleichenbacher Padding OracleEPSS 0.1%CVE-2026-7845LOWchatchat-space Langchain-Chatchat Vision Chat Paste Image dialogue.py PIL.Image.tobytes weak hashEPSS 0.1%CVE-2025-34500HIGHShuffle Master Deck Mate 2 Insecure Update ChainEPSS 0.1%