Vulnerabilities > Inadequate Encryption Strength

DATE CVE VULNERABILITY TITLE RISK
2022-02-24 CVE-2020-10636 Inadequate Encryption Strength vulnerability in Emerson Openenterprise Scada Server 2.8.3/3.1/3.3.3
Inadequate encryption may allow the passwords for Emerson OpenEnterprise versions through 3.3.4 user accounts to be obtained.
network
low complexity
emerson CWE-326
7.5
2022-02-24 CVE-2020-14481 Inadequate Encryption Strength vulnerability in Rockwellautomation Factorytalk View 10.0
The DeskLock tool provided with FactoryTalk View SE uses a weak encryption algorithm that may allow a local, authenticated attacker to decipher user credentials, including the Windows user or Windows DeskLock passwords.
local
low complexity
rockwellautomation CWE-326
7.8
2022-02-18 CVE-2022-21800 Inadequate Encryption Strength vulnerability in Airspan products
MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 uses the MD5 algorithm to hash the passwords before storing them but does not salt the hash.
network
low complexity
airspan CWE-326
6.5
2022-02-16 CVE-2019-4291 Inadequate Encryption Strength vulnerability in IBM Maximo Anywhere 7.6.4.0
IBM Maximo Anywhere 7.6.4.0 could allow an attacker to reverse engineer the application due to the lack of binary protection precautions.
network
low complexity
ibm CWE-326
6.5
2022-02-09 CVE-2022-24318 Inadequate Encryption Strength vulnerability in Schneider-Electric products
A CWE-326: Inadequate Encryption Strength vulnerability exists that could cause non-encrypted communication with the server when outdated versions of the ViewX client are used.
network
low complexity
schneider-electric CWE-326
7.5
2022-01-05 CVE-2022-21653 Inadequate Encryption Strength vulnerability in Typelevel Jawn
Jawn is an open source JSON parser.
network
low complexity
typelevel CWE-326
7.5
2021-12-15 CVE-2021-42216 Inadequate Encryption Strength vulnerability in Anonaddy 0.8.5
A Broken or Risky Cryptographic Algorithm exists in AnonAddy 0.8.5 via VerificationController.php.
network
low complexity
anonaddy CWE-326
critical
9.8
2021-12-13 CVE-2021-38947 Inadequate Encryption Strength vulnerability in IBM Spectrum Copy Data Management 2.2.0.0/2.2.13
IBM Spectrum Copy Data Management 2.2.13 and earlier uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
network
low complexity
ibm CWE-326
7.5
2021-12-01 CVE-2021-20400 Inadequate Encryption Strength vulnerability in IBM Qradar Security Information and Event Manager
IBM QRadar SIEM 7.3 and 7.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
network
low complexity
ibm CWE-326
7.5
2021-11-23 CVE-2021-38891 Inadequate Encryption Strength vulnerability in IBM Sterling Connect:Direct
IBM Sterling Connect:Direct Web Services 1.0 and 6.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
network
low complexity
ibm CWE-326
7.5