Vulnerabilities > Inadequate Encryption Strength

DATE CVE VULNERABILITY TITLE RISK
2018-09-18 CVE-2018-17177 Inadequate Encryption Strength vulnerability in Neatorobotics products
An issue was discovered on Neato Botvac Connected 2.2.0 and Botvac 85 1.2.1 devices.
local
low complexity
neatorobotics CWE-326
2.1
2018-08-14 CVE-2018-0131 Inadequate Encryption Strength vulnerability in Cisco IOS and IOS XE
A vulnerability in the implementation of RSA-encrypted nonces in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to obtain the encrypted nonces of an Internet Key Exchange Version 1 (IKEv1) session.
network
cisco CWE-326
4.3
2018-08-13 CVE-2018-15124 Inadequate Encryption Strength vulnerability in Zipato Zipabox Firmware 118
Weak hashing algorithm in Zipato Zipabox Smart Home Controller BOARD REV - 1 with System Version -118 allows unauthenticated attacker extract clear text passwords and get root access on the device.
network
low complexity
zipato CWE-326
critical
10.0
2018-08-06 CVE-2017-1366 Inadequate Encryption Strength vulnerability in IBM Security Identity Governance and Intelligence
IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
network
low complexity
ibm CWE-326
5.0
2018-06-27 CVE-2017-16726 Inadequate Encryption Strength vulnerability in Beckhoff Twincat
Beckhoff TwinCAT supports communication over ADS.
network
low complexity
beckhoff CWE-326
6.4
2018-06-18 CVE-2018-9028 Inadequate Encryption Strength vulnerability in Broadcom Privileged Access Manager
Weak cryptography used for passwords in CA Privileged Access Manager 2.x reduces the complexity for password cracking.
network
low complexity
broadcom CWE-326
5.0
2018-06-11 CVE-2018-5184 Inadequate Encryption Strength vulnerability in multiple products
Using remote content in encrypted messages can lead to the disclosure of plaintext.
network
low complexity
debian mozilla canonical redhat CWE-326
5.0
2018-05-23 CVE-2017-2598 Inadequate Encryption Strength vulnerability in Jenkins
Jenkins before versions 2.44, 2.32.2 uses AES ECB block cipher mode without IV for encrypting secrets which makes Jenkins and the stored secrets vulnerable to unnecessary risks (SECURITY-304).
network
low complexity
jenkins CWE-326
4.0
2018-05-18 CVE-2017-9635 Inadequate Encryption Strength vulnerability in Schneider-Electric Ampla Manufacturing Execution System
Schneider Electric Ampla MES 6.4 provides capability to configure users and their privileges.
1.9
2018-05-17 CVE-2018-1466 Inadequate Encryption Strength vulnerability in IBM products
IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products (6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) use weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
network
ibm CWE-326
3.5