Vulnerabilities > Inadequate Encryption Strength

DATE CVE VULNERABILITY TITLE RISK
2023-12-05 CVE-2023-26943 Inadequate Encryption Strength vulnerability in Assaabloy Yale Keyless Smart Lock Firmware 1.0
Weak encryption mechanisms in RFID Tags in Yale Keyless Lock v1.0 allows attackers to create a cloned tag via physical proximity to the original.
low complexity
assaabloy CWE-326
6.5
2023-12-01 CVE-2023-28896 Inadequate Encryption Strength vulnerability in Preh Mib3 Firmware
Access to critical Unified Diagnostics Services (UDS) of the Modular Infotainment Platform 3 (MIB3) infotainment is transmitted via Controller Area Network (CAN) bus in a form that can be easily decoded by attackers with physical access to the vehicle. Vulnerability discovered on Škoda Superb III (3V3) - 2.0 TDI manufactured in 2022.
low complexity
preh CWE-326
2.4
2023-11-27 CVE-2023-48034 Inadequate Encryption Strength vulnerability in Acer Sk-9662 Firmware
An issue discovered in Acer Wireless Keyboard SK-9662 allows attacker in physical proximity to both decrypt wireless keystrokes and inject arbitrary keystrokes via use of weak encryption.
low complexity
acer CWE-326
6.1
2023-11-20 CVE-2023-48051 Inadequate Encryption Strength vulnerability in Carglglz Upydev 0.4.3
An issue in /upydev/keygen.py in upydev v0.4.3 allows attackers to decrypt sensitive information via weak encryption padding.
network
low complexity
carglglz CWE-326
7.5
2023-11-16 CVE-2023-43757 Inadequate Encryption Strength vulnerability in Elecom products
Inadequate encryption strength vulnerability in multiple routers provided by ELECOM CO.,LTD.
low complexity
elecom CWE-326
6.5
2023-11-09 CVE-2023-46894 Inadequate Encryption Strength vulnerability in Espressif Esptool 4.6.2
An issue discovered in esptool 4.6.2 allows attackers to view sensitive information via weak cryptographic algorithm.
network
low complexity
espressif CWE-326
7.5
2023-11-09 CVE-2023-47368 Inadequate Encryption Strength vulnerability in Linecorp Line 13.6.1
The leakage of channel access token in taketorinoyu Line 13.6.1 allows remote attackers to send malicious notifications to victims.
network
low complexity
linecorp CWE-326
6.5
2023-11-09 CVE-2023-47370 Inadequate Encryption Strength vulnerability in Linecorp Line 13.6.1
The leakage of channel access token in bluetrick Line 13.6.1 allows remote attackers to send malicious notifications to victims.
network
low complexity
linecorp CWE-326
6.5
2023-11-09 CVE-2023-47372 Inadequate Encryption Strength vulnerability in Linecorp Line 13.6.1
The leakage of channel access token in UPDATESALON C-LOUNGE Line 13.6.1 allows remote attackers to send malicious notifications to victims.
network
low complexity
linecorp CWE-326
6.5
2023-11-09 CVE-2023-47373 Inadequate Encryption Strength vulnerability in Linecorp Line 13.6.1
The leakage of channel access token in DRAGON FAMILY Line 13.6.1 allows remote attackers to send malicious notifications to victims.
network
low complexity
linecorp CWE-326
6.5