Falhas do tipo CWE-327

399 resultados

Uso de algoritmo criptográfico quebrado ou inseguro

A aplicação usa um algoritmo de criptografia que já foi criptanaliticamente quebrado ou é considerado inseguro para o caso de uso. Isso expõe dados sensíveis a decriptação não autorizada, mesmo que o código implemente corretamente a biblioteca criptográfica escolhida.

Exemplo

Um sistema de autenticação usa MD5 ou SHA1 para hash de senhas, ou uma API de pagamento trafega dados com DES ou RC4 em vez de AES. Um atacante consegue recuperar a senha original via força bruta ou quebra criptanalítica em tempo viável.

Como mitigar

Use apenas algoritmos criptográficos modernos e bem mantidos: SHA-256+ para hash, AES-256 para cifra simétrica, RSA-2048+ ou ECDP-256+ para assimétrica. Audite regularmente o stack criptográfico e mantenha dependências atualizadas; remova suporte a algoritmos legados em produção.

CVE-2022-36937CRITICALHHVM 4.172.0 and all prior versions use TLS 1.0 for secure connections when handling tls:// URLs in the stream extension. TLS1.0 has numerouEPSS 0.5%CVE-2025-9146HIGHLinksys E5600 Firmware checkFw.sh verify_gemtek_header risky encryptionEPSS 0.5%CVE-2023-51838HIGHYlianst MeshCentral 1.1.16 suffers from Use of a Broken or Risky Cryptographic Algorithm.EPSS 0.5%CVE-2022-21800MEDIUMAirspan Networks Mimosa Use of a Broken or Risky Cryptographic AlgorithmEPSS 0.5%CVE-2022-34320MEDIUMIBM CICS TX information disclosureEPSS 0.5%CVE-2022-34319MEDIUMIBM CICS TX information disclosureEPSS 0.5%CVE-2023-32043MEDIUMWindows Remote Desktop Security Feature Bypass VulnerabilityEPSS 0.5%CVE-2017-5243The default SSH configuration in Rapid7 Nexpose hardware appliances shipped before June 2017 does not specify desired algorithms for key excEPSS 0.5%CVE-2020-11916MEDIUMAn issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. The password for the root user is hashed using an old and deprecated hashEPSS 0.5%CVE-2021-31562MEDIUMFresenius Kabi Agilia Connect Infusion System use of a broken or risky cryptographic algorithmEPSS 0.5%CVE-2022-34309MEDIUMIBM CICS TX information disclosureEPSS 0.5%CVE-2022-34310MEDIUMIBM CICS TX information disclosureEPSS 0.5%CVE-2022-43934MEDIUMWeak Key-exchange algorithmsEPSS 0.5%CVE-2022-23539MEDIUMjsonwebtoken unrestricted key type could lead to legacy keys usageEPSS 0.5%CVE-2022-22462LOWIBM Security Verify Governance, Identity Manager virtual appliance component information disclosureEPSS 0.5%CVE-2023-38371MEDIUMIBM Security Access Manager Docker information disclosureEPSS 0.5%CVE-2021-27913LOWUse of a Broken or Risky Cryptographic AlgorithmEPSS 0.5%CVE-2022-22564MEDIUMDell EMC Unity versions before 5.2.0.0.5.173 , use(es) broken cryptographic algorithm. A remote unauthenticated attacker could potentially eEPSS 0.5%CVE-2019-15795MEDIUMpython-apt uses MD5 for validationEPSS 0.5%CVE-2026-22585CRITICALUse of a Broken or Risky Cryptographic Algorithm vulnerability in Salesforce Marketing Cloud Engagement (CloudPages, Forward to a Friend, PrEPSS 0.4%