Vulnerabilities > Inadequate Encryption Strength

DATE CVE VULNERABILITY TITLE RISK
2020-03-18 CVE-2019-12121 Inadequate Encryption Strength vulnerability in Onap Open Network Automation Platform 3.0.0/3.0.1/3.0.2
An issue was detected in ONAP Portal through Dublin.
network
low complexity
onap CWE-326
7.5
2020-03-10 CVE-2019-19299 Inadequate Encryption Strength vulnerability in Siemens Sinvr/Sivms Video Server
A vulnerability has been identified in SiNVR/SiVMS Video Server (All versions < V5.0.0), SiNVR/SiVMS Video Server (All versions >= V5.0.0 < V5.0.2), SiNVR/SiVMS Video Server (All versions >= V5.0.2).
network
low complexity
siemens CWE-326
7.5
2020-03-09 CVE-2020-10244 Inadequate Encryption Strength vulnerability in Jpaseto Project Jpaseto 0.1.0/0.2.0
JPaseto before 0.3.0 generates weak hashes when using v2.local tokens.
network
low complexity
jpaseto-project CWE-326
7.5
2020-03-04 CVE-2020-9476 Inadequate Encryption Strength vulnerability in Commscope Arris Tg1692A Firmware 9.1.103De2
ARRIS TG1692A devices allow remote attackers to discover the administrator login name and password by reading the /login page and performing base64 decoding.
network
low complexity
commscope CWE-326
7.5
2020-03-02 CVE-2019-18863 Inadequate Encryption Strength vulnerability in Mitel products
A key length vulnerability in the implementation of the SRTP 128-bit key on Mitel 6800 and 6900 SIP series phones, versions 5.1.0.2051 SP2 and earlier, could allow an attacker to launch a man-in-the-middle attack when SRTP is used in a call.
network
high complexity
mitel CWE-326
5.9
2020-02-28 CVE-2015-5361 Inadequate Encryption Strength vulnerability in Juniper Junos
Background For regular, unencrypted FTP traffic, the FTP ALG can inspect the unencrypted control channel and open related sessions for the FTP data channel.
network
low complexity
juniper CWE-326
6.5
2020-02-26 CVE-2020-9337 Inadequate Encryption Strength vulnerability in Golfbuddyglobal Course Manager 1.1
In GolfBuddy Course Manager 1.1, passwords are sent (with base64 encoding) via a GET request.
network
low complexity
golfbuddyglobal CWE-326
6.5
2020-02-25 CVE-2019-4557 Inadequate Encryption Strength vulnerability in IBM Qradar Advisor 1.1/2.5.0
IBM Qradar Advisor 1.1 through 2.5 with Watson uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
network
low complexity
ibm CWE-326
7.5
2020-02-13 CVE-2013-7287 Inadequate Encryption Strength vulnerability in Mobileiron Sentry and Virtual Smartphone Platform
MobileIron VSP < 5.9.1 and Sentry < 5.0 has an insecure encryption scheme.
network
low complexity
mobileiron CWE-326
critical
9.8
2020-02-12 CVE-2013-7286 Inadequate Encryption Strength vulnerability in ATT products
MobileIron VSP < 5.9.1 and Sentry < 5.0 has a weak password obfuscation algorithm
network
low complexity
att CWE-326
7.5