Falhas do tipo CWE-327

401 resultados

Uso de algoritmo criptográfico quebrado ou inseguro

A aplicação usa um algoritmo de criptografia que já foi criptanaliticamente quebrado ou é considerado inseguro para o caso de uso. Isso expõe dados sensíveis a decriptação não autorizada, mesmo que o código implemente corretamente a biblioteca criptográfica escolhida.

Exemplo

Um sistema de autenticação usa MD5 ou SHA1 para hash de senhas, ou uma API de pagamento trafega dados com DES ou RC4 em vez de AES. Um atacante consegue recuperar a senha original via força bruta ou quebra criptanalítica em tempo viável.

Como mitigar

Use apenas algoritmos criptográficos modernos e bem mantidos: SHA-256+ para hash, AES-256 para cifra simétrica, RSA-2048+ ou ECDP-256+ para assimétrica. Audite regularmente o stack criptográfico e mantenha dependências atualizadas; remova suporte a algoritmos legados em produção.

CVE-2022-46834MEDIUMUse of a Broken or Risky Cryptographic Algorithm in SICK RFU65x firmware version < v2.21 allows a low-privileged remote attacker to decrypt EPSS 0.3%CVE-2023-34130SonicWall GMS and Analytics use outdated Tiny Encryption Algorithm (TEA) with a hardcoded key to encrypt sensitive data. This issue affects EPSS 0.3%CVE-2026-14738MEDIUMexo-explore exo Vision Feature Cache vision.py _image_cache_key weak hashEPSS 0.3%CVE-2023-22812HIGHSanDisk PrivateAccess Deprecated TLS protocol versions supportedEPSS 0.3%CVE-2025-41711MEDIUMUse of a Broken or Risky Cryptographic Algorithm for firmware images of power analyzerEPSS 0.3%CVE-2026-13510MEDIUMSimStudioAI sim Password Protection deployment.ts weak hashEPSS 0.3%CVE-2025-54426CRITICALPolkadot Frontier contains silent failure in Curve25519 arithmetic precompiles with malformed pointsEPSS 0.3%CVE-2024-41270CRITICALAn issue discovered in the RunHTTPServer function in Gorush v1.18.4 allows attackers to intercept and manipulate data due to use of deprecatEPSS 0.3%CVE-2025-34519HIGHIlevia EVE X1 Server 4.7.18.0.eden Insecure Hashing AlgorithmEPSS 0.3%CVE-2024-33663MEDIUMpython-jose through 3.3.0 has algorithm confusion with OpenSSH ECDSA keys and other key formats. This is similar to CVE-2022-29217.EPSS 0.3%CVE-2025-52026HIGHAn information disclosure vulnerability exists in the /srvs/membersrv/getCashiers endpoint of the Aptsys gemscms backend platform thru 2025-EPSS 0.3%CVE-2021-41835HIGHFresenius Kabi Agilia Connect Infusion System use of a broken or risky cryptographic algorithmEPSS 0.3%CVE-2026-44053HIGHWeak cryptography in DHCAST128 UAMEPSS 0.3%CVE-2024-39745MEDIUMIBM Sterling Connect:Direct Web Services information disclosureEPSS 0.3%CVE-2023-41097MEDIUMPotential Timing vulnerability in CBC PKCS7 padding calculationsEPSS 0.3%CVE-2024-45193MEDIUMAn issue was discovered in Matrix libolm through 3.2.16. There is Ed25519 signature malleability due to lack of validation criteria (does noEPSS 0.3%CVE-2026-77151MEDIUMlin-snow Ech0 crypto.go MD5Encrypt risky encryptionEPSS 0.3%CVE-2026-46395CRITICALHAX CMS Vulnerable to Private Key Disclosure via Broken HMAC ImplementationEPSS 0.3%CVE-2024-39583HIGHDell PowerScale InsightIQ, versions 5.0 through 5.1, contains a Use of a Broken or Risky Cryptographic Algorithm vulnerability. An unauthentEPSS 0.3%CVE-2023-36749HIGHA vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEEPSS 0.3%