Vulnerabilities > Inadequate Encryption Strength

DATE CVE VULNERABILITY TITLE RISK
2021-07-30 CVE-2021-28093 Inadequate Encryption Strength vulnerability in Open-Xchange Documents 7.10.5/7.8.3
OX Documents before 7.10.5-rev5 has Incorrect Access Control of converted images because hash collisions can occur, due to use of Adler32.
network
low complexity
open-xchange CWE-326
6.5
2021-07-30 CVE-2021-28094 Inadequate Encryption Strength vulnerability in Open-Xchange Documents 7.10.5/7.8.3
OX Documents before 7.10.5-rev7 has Incorrect Access Control for converted documents because hash collisions can occur, due to use of CRC32.
network
low complexity
open-xchange CWE-326
6.5
2021-07-30 CVE-2021-28095 Inadequate Encryption Strength vulnerability in Open-Xchange Documents 7.10.5/7.8.3
OX Documents before 7.10.5-rev5 has Incorrect Access Control for documents that contain XML structures because hash collisions can occur, due to use of CRC32.
network
high complexity
open-xchange CWE-326
4.8
2021-07-13 CVE-2021-20360 Inadequate Encryption Strength vulnerability in IBM Cloud PAK for Applications 4.3
IBM Cloud Pak for Applications 4.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
network
low complexity
ibm CWE-326
7.5
2021-07-13 CVE-2021-20369 Inadequate Encryption Strength vulnerability in IBM Cloud PAK for Applications
IBM Cloud Pak for Applications 4.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
network
high complexity
ibm CWE-326
5.9
2021-07-08 CVE-2021-34430 Inadequate Encryption Strength vulnerability in Eclipse Tinydtls 0.8.1/0.8.2/0.9
Eclipse TinyDTLS through 0.9-rc1 relies on the rand function in the C library, which makes it easier for remote attackers to compute the master key and then decrypt DTLS traffic.
network
low complexity
eclipse CWE-326
7.5
2021-06-28 CVE-2021-32496 Inadequate Encryption Strength vulnerability in Sick Visionary-S CX Firmware
SICK Visionary-S CX up version 5.21.2.29154R are vulnerable to an Inadequate Encryption Strength vulnerability concerning the internal SSH interface solely used by SICK for recovering returned devices.
network
high complexity
sick CWE-326
5.3
2021-06-11 CVE-2021-25392 Inadequate Encryption Strength vulnerability in Google Android 10.0/11.0/9.0
Improper protection of backup path configuration in Samsung Dex prior to SMR MAY-2021 Release 1 allows local attackers to get sensitive information via changing the path.
local
low complexity
google CWE-326
5.5
2021-06-09 CVE-2020-15387 Inadequate Encryption Strength vulnerability in Broadcom Brocade Sannav and Fabric Operating System
The host SSH servers of Brocade Fabric OS before Brocade Fabric OS v7.4.2h, v8.2.1c, v8.2.2, v9.0.0, and Brocade SANnav before v2.1.1 utilize keys of less than 2048 bits, which may be vulnerable to man-in-the-middle attacks and/or insecure SSH communications.
network
high complexity
broadcom CWE-326
7.4
2021-05-26 CVE-2018-16499 Inadequate Encryption Strength vulnerability in Versa-Networks Versa Operating System
In VOS compromised, an attacker at network endpoints can possibly view communications between an unsuspecting user and the service using man-in-the-middle attacks.
network
high complexity
versa-networks CWE-326
5.9