Falhas do tipo CWE-327

401 resultados

Uso de algoritmo criptográfico quebrado ou inseguro

A aplicação usa um algoritmo de criptografia que já foi criptanaliticamente quebrado ou é considerado inseguro para o caso de uso. Isso expõe dados sensíveis a decriptação não autorizada, mesmo que o código implemente corretamente a biblioteca criptográfica escolhida.

Exemplo

Um sistema de autenticação usa MD5 ou SHA1 para hash de senhas, ou uma API de pagamento trafega dados com DES ou RC4 em vez de AES. Um atacante consegue recuperar a senha original via força bruta ou quebra criptanalítica em tempo viável.

Como mitigar

Use apenas algoritmos criptográficos modernos e bem mantidos: SHA-256+ para hash, AES-256 para cifra simétrica, RSA-2048+ ou ECDP-256+ para assimétrica. Audite regularmente o stack criptográfico e mantenha dependências atualizadas; remova suporte a algoritmos legados em produção.

CVE-2024-36440MEDIUMAn issue was discovered on Swissphone DiCal-RED 4009 devices. An attacker with access to the file /etc/deviceconfig may recover the administEPSS 0.3%CVE-2026-50086CRITICALAqara unauthenticated AES oracleEPSS 0.3%CVE-2024-4282HIGHWeak TLS Ciphers on Brocade SANnav OVA SSH port 22EPSS 0.3%CVE-2025-24007HIGHA vulnerability has been identified in SIRIUS 3RK3 Modular Safety System (MSS) (All versions), SIRIUS Safety Relays 3SK2 (All versions). AffEPSS 0.3%CVE-2025-14175MEDIUMWeak Algorithm Support in SSH Server on TL-WR820NEPSS 0.3%CVE-2025-14636MEDIUMTenda AX9 httpd image_check weak hashEPSS 0.3%CVE-2024-22463HIGHDell PowerScale OneFS 8.2.x through 9.6.0.x contains a use of a broken or risky cryptographic algorithm vulnerability. A remote unprivilegedEPSS 0.3%CVE-2024-53441CRITICALAn issue in the index.js decryptCookie function of cookie-encrypter v1.0.1 allows attackers to execute a bit flipping attack.EPSS 0.3%CVE-2026-13482MEDIUMskypilot-org skypilot User ID server.py username.encode weak hashEPSS 0.3%CVE-2023-28509HIGHWeak encryption in UniRPC protocolEPSS 0.3%CVE-2024-39731MEDIUMIBM Datacap Navigator information disclosureEPSS 0.3%CVE-2026-63761MEDIUMSurrealDB before 3.1.0 Algorithm Downgrade via ES512EPSS 0.3%CVE-2026-17467HIGHVulnerabilities exists in IBM Cloud Pak for Data SystemEPSS 0.3%CVE-2024-28972MEDIUMDell InsightIQ, Verion 5.0.0, contains a use of a broken or risky cryptographic algorithm vulnerability. An unauthenticated remote attacker EPSS 0.3%CVE-2024-21670MEDIUMCL-Signatures Revocation Scheme in Ursa has flaws that allow a holder to demonstrate non-revocation of a revoked credentialEPSS 0.3%CVE-2022-38391MEDIUMIBM Spectrum Control information disclosureEPSS 0.3%CVE-2024-4765HIGHWeb application manifests were stored by using an insecure MD5 hash which allowed for a hash collision to overwrite another application's maEPSS 0.3%CVE-2020-4874MEDIUMIBM Cognos Controller information disclosureEPSS 0.3%CVE-2023-40696MEDIUMIBM Cognos Controller information disclosureEPSS 0.3%CVE-2025-62514HIGH`libparsec_crypto` does not check for weak order point of curve 25519EPSS 0.3%