Vulnerabilities > Inadequate Encryption Strength

DATE CVE VULNERABILITY TITLE RISK
2018-12-20 CVE-2018-18767 Inadequate Encryption Strength vulnerability in multiple products
An issue was discovered in D-Link 'myDlink Baby App' version 2.04.06.
local
high complexity
dlink d-link CWE-326
7.0
2018-12-13 CVE-2018-1814 Inadequate Encryption Strength vulnerability in IBM Security Access Manager
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
network
low complexity
ibm CWE-326
7.5
2018-12-13 CVE-2018-1665 Inadequate Encryption Strength vulnerability in IBM Datapower Gateway
IBM DataPower Gateway 7.6.0.0 through 7.6.0.10, 7.5.2.0 through 7.5.2.17, 7.5.1.0 through 7.5.1.17, 7.5.0.0 through 7.5.0.18, and 7.7.0.0 through 7.7.1.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
network
low complexity
ibm CWE-326
7.5
2018-12-07 CVE-2018-19001 Inadequate Encryption Strength vulnerability in Philips Healthsuite Health
Philips HealthSuite Health Android App, all versions.
low complexity
philips CWE-326
4.3
2018-12-05 CVE-2018-1648 Inadequate Encryption Strength vulnerability in IBM Qradar Incident Forensics
IBM QRadar SIEM 7.2 and 7.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
network
low complexity
ibm CWE-326
7.5
2018-12-01 CVE-2018-19784 Inadequate Encryption Strength vulnerability in PHP-Proxy 5.1.0
The str_rot_pass function in vendor/atholn1600/php-proxy/src/helpers.php in PHP-Proxy 5.1.0 uses weak cryptography, which makes it easier for attackers to calculate the authorization data needed for local file inclusion.
network
low complexity
php-proxy CWE-326
7.5
2018-11-09 CVE-2018-15796 Inadequate Encryption Strength vulnerability in Pivotal Software Bits Service
Cloud Foundry Bits Service Release, versions prior to 2.14.0, uses an insecure hashing algorithm to sign URLs.
network
low complexity
pivotal-software CWE-326
8.1
2018-10-18 CVE-2018-1518 Inadequate Encryption Strength vulnerability in IBM products
IBM InfoSphere Information Server 11.7 is affected by a weak password encryption vulnerability that could allow a local user to obtain highly sensitive information.
local
low complexity
ibm CWE-326
5.5
2018-10-05 CVE-2018-0448 Inadequate Encryption Strength vulnerability in Cisco Digital Network Architecture Center
A vulnerability in the identity management service of Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to bypass authentication and take complete control of identity management functions.
network
low complexity
cisco CWE-326
critical
9.8
2018-10-02 CVE-2018-1593 Inadequate Encryption Strength vulnerability in IBM Multi-Cloud Data Encryption 2.1/2.1.0.1
IBM Multi-Cloud Data Encryption (MDE) 2.1 could allow an unauthorized user to manipulate data due to missing file checksums.
network
low complexity
ibm CWE-326
5.3