Falhas do tipo CWE-327

401 resultados

Uso de algoritmo criptográfico quebrado ou inseguro

A aplicação usa um algoritmo de criptografia que já foi criptanaliticamente quebrado ou é considerado inseguro para o caso de uso. Isso expõe dados sensíveis a decriptação não autorizada, mesmo que o código implemente corretamente a biblioteca criptográfica escolhida.

Exemplo

Um sistema de autenticação usa MD5 ou SHA1 para hash de senhas, ou uma API de pagamento trafega dados com DES ou RC4 em vez de AES. Um atacante consegue recuperar a senha original via força bruta ou quebra criptanalítica em tempo viável.

Como mitigar

Use apenas algoritmos criptográficos modernos e bem mantidos: SHA-256+ para hash, AES-256 para cifra simétrica, RSA-2048+ ou ECDP-256+ para assimétrica. Audite regularmente o stack criptográfico e mantenha dependências atualizadas; remova suporte a algoritmos legados em produção.

CVE-2024-35537HIGHTVS Motor Company Limited TVS Connect Android v4.6.0 and IOS v5.0.0 was discovered to insecurely handle the RSA key pair, allowing attackersEPSS 0.3%CVE-2025-9828MEDIUMTenda CP6 uhttp sub_2B7D04 risky encryptionEPSS 0.3%CVE-2023-28043MEDIUM Dell SCG 5.14 contains an information disclosure vulnerability during the SRS to SCG upgrade path. A remote low privileged malicious user cEPSS 0.3%CVE-2023-50939MEDIUMIBM PowerSC information DisclosureEPSS 0.3%CVE-2024-8603HIGHA “Use of a Broken or Risky Cryptographic Algorithm” vulnerability in the SSL/TLS component used in B&R Automation Runtime versions before 6EPSS 0.3%CVE-2020-11031HIGHInsecure encryption algorithm in GLPIEPSS 0.3%CVE-2024-22347MEDIUMIBM UrbanCode Velocity information disclosureEPSS 0.3%CVE-2024-22361MEDIUMIBM Semeru Runtime information disclosureEPSS 0.3%CVE-2021-41278MEDIUMBroken encryption in app-functions-sdk “AES” transform in EdgeX Foundry releases prior to Jakarta allows attackers to decrypt messages via unspecified vectorsEPSS 0.3%CVE-2022-34757MEDIUMA CWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists where weak cipher suites can be used for the SSH connectionEPSS 0.3%CVE-2023-0296MEDIUMThe Birthday attack against 64-bit block ciphers flaw (CVE-2016-2183) was reported for the health checks port (9979) on etcd grpc-proxy compEPSS 0.3%CVE-2024-25963MEDIUMDell PowerScale OneFS, versions 8.2.2.x through 9.5.0.x contains a use of a broken cryptographic algorithm vulnerability. A remote unauthentEPSS 0.3%CVE-2025-14813CRITICALGOSTCTR implementation unable to process more than 255 blocks correctlyEPSS 0.3%CVE-2023-50937MEDIUMIBM PowerSC information disclosureEPSS 0.3%CVE-2024-22192MEDIUMUrsa CL-Signatures Revocation allows verifiers to generate unique identifiers for holdersEPSS 0.3%CVE-2021-33846MEDIUMFresenius Kabi Agilia Connect Infusion System use of a broken or risky cryptographic algorithmEPSS 0.3%CVE-2023-5627HIGHIncorrect Implementation of Authentication Algorithm VulnerabilityEPSS 0.3%CVE-2022-46832MEDIUMUse of a Broken or Risky Cryptographic Algorithm in SICK RFU62x firmware version < 2.21 allows a low-privileged remote attacker to decrypt tEPSS 0.3%CVE-2022-46833MEDIUMUse of a Broken or Risky Cryptographic Algorithm in SICK RFU63x firmware version < v2.21 allows a low-privileged remote attacker to decrypt EPSS 0.3%CVE-2022-27581MEDIUMUse of a Broken or Risky Cryptographic Algorithm in SICK RFU61x firmware version <v2.25 allows a low-privileged remote attacker to decrypt tEPSS 0.3%