Vulnerabilities > Inadequate Encryption Strength

DATE CVE VULNERABILITY TITLE RISK
2020-02-07 CVE-2019-13163 Inadequate Encryption Strength vulnerability in Fujitsu products
The Fujitsu TLS library allows a man-in-the-middle attack.
network
high complexity
fujitsu CWE-326
5.9
2020-02-04 CVE-2011-3629 Inadequate Encryption Strength vulnerability in Joomla Joomla!
Joomla! core 1.7.1 allows information disclosure due to weak encryption
network
low complexity
joomla CWE-326
7.5
2020-01-24 CVE-2020-5224 Inadequate Encryption Strength vulnerability in Django-User-Sessions Project Django-User-Sessions
In Django User Sessions (django-user-sessions) before 1.7.1, the views provided allow users to terminate specific sessions.
network
low complexity
django-user-sessions-project CWE-326
8.8
2020-01-24 CVE-2020-6966 Inadequate Encryption Strength vulnerability in Gehealthcare products
In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X, the affected products utilize a weak encryption scheme for remote desktop control, which may allow an attacker to obtain remote code execution of devices on the network.
network
low complexity
gehealthcare CWE-326
critical
10.0
2019-12-20 CVE-2019-18263 Inadequate Encryption Strength vulnerability in Philips products
An issue was found in Philips Veradius Unity, Pulsera, and Endura Dual WAN Router, Veradius Unity (718132) with wireless option (shipped between 2016-August 2018), Veradius Unity (718132) with ViewForum option (shipped between 2016-August 2018), Pulsera (718095) and Endura (718075) with wireless option (shipped between 26-June-2017 through 07-August 2018), Pulsera (718095) and Endura (718075) with ViewForum option (shipped between 26-June-2017 through 07-August 2018).
low complexity
philips CWE-326
6.5
2019-12-10 CVE-2013-2166 Inadequate Encryption Strength vulnerability in multiple products
python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass
network
low complexity
openstack redhat fedoraproject debian CWE-326
critical
9.8
2019-12-06 CVE-2012-2130 Inadequate Encryption Strength vulnerability in multiple products
A Security Bypass vulnerability exists in PolarSSL 0.99pre4 through 1.1.1 due to a weak encryption error when generating Diffie-Hellman values and RSA keys.
network
high complexity
polarssl debian fedoraproject CWE-326
7.4
2019-11-30 CVE-2013-7484 Inadequate Encryption Strength vulnerability in Zabbix 2.0.8/4.4.0
Zabbix before 5.0 represents passwords in the users table with unsalted MD5.
network
low complexity
zabbix CWE-326
7.5
2019-11-26 CVE-2011-4121 Inadequate Encryption Strength vulnerability in Ruby-Lang Ruby
The OpenSSL extension of Ruby (Git trunk) versions after 2011-09-01 up to 2011-11-03 always generated an exponent value of '1' to be used for private RSA key generation.
network
low complexity
ruby-lang CWE-326
critical
9.8
2019-11-26 CVE-2019-18241 Inadequate Encryption Strength vulnerability in Philips products
In Philips IntelliBridge EC40 and EC80, IntelliBridge EC40 Hub all versions, and IntelliBridge EC80 Hub all versions, the SSH server running on the affected products is configured to allow weak ciphers.
low complexity
philips CWE-326
6.5