Vulnerabilities > Inadequate Encryption Strength

DATE CVE VULNERABILITY TITLE RISK
2023-10-17 CVE-2023-43776 Inadequate Encryption Strength vulnerability in Eaton products
Eaton easyE4 PLC offers a device password protection functionality to facilitate a secure connection and prevent unauthorized access.
low complexity
eaton CWE-326
6.6
2023-09-27 CVE-2023-4129 Inadequate Encryption Strength vulnerability in Dell Data Protection Central 19.9.010
Dell Data Protection Central, version 19.9, contains an Inadequate Encryption Strength Vulnerability.
network
low complexity
dell CWE-326
7.5
2023-09-27 CVE-2023-41305 Inadequate Encryption Strength vulnerability in Huawei Emui and Harmonyos
Vulnerability of 5G messages being sent without being encrypted in a VPN environment in the SMS message module.
network
low complexity
huawei CWE-326
7.5
2023-08-28 CVE-2022-46783 Inadequate Encryption Strength vulnerability in Stormshield SSL VPN Client
An issue was discovered in Stormshield SSL VPN Client before 3.2.0.
network
low complexity
stormshield CWE-326
5.3
2023-08-24 CVE-2023-34971 Inadequate Encryption Strength vulnerability in Qnap QTS and Quts Hero
An inadequate encryption strength vulnerability has been reported to affect QNAP operating systems.
low complexity
qnap CWE-326
8.8
2023-08-04 CVE-2023-0525 Inadequate Encryption Strength vulnerability in Mitsubishielectric products
Weak Encoding for Password vulnerability in Mitsubishi Electric Corporation GOT2000 Series GT27 model versions 01.49.000 and prior, GT25 model versions 01.49.000 and prior, GT23 model versions 01.49.000 and prior, GT21 model versions 01.49.000 and prior, GOT SIMPLE Series GS25 model versions 01.49.000 and prior, GS21 model versions 01.49.000 and prior, GT Designer3 Version1 (GOT2000) versions 1.295H and prior and GT SoftGOT2000 versions 1.295H and prior allows a remote unauthenticated attacker to obtain plaintext passwords by sniffing packets containing encrypted passwords and decrypting the encrypted passwords, in the case of transferring data with GT Designer3 Version1(GOT2000) and GOT2000 Series or GOT SIMPLE Series with the Data Transfer Security function enabled, or in the case of transferring data by the SoftGOT-GOT link function with GT SoftGOT2000 and GOT2000 series with the Data Transfer Security function enabled.
network
low complexity
mitsubishielectric CWE-326
7.5
2023-07-18 CVE-2023-28021 Inadequate Encryption Strength vulnerability in Hcltech Bigfix Webui
The BigFix WebUI uses weak cipher suites.
network
low complexity
hcltech CWE-326
7.5
2023-07-12 CVE-2023-20185 Inadequate Encryption Strength vulnerability in Cisco Nx-Os
A vulnerability in the Cisco ACI Multi-Site CloudSec encryption feature of Cisco Nexus 9000 Series Fabric Switches in ACI mode could allow an unauthenticated, remote attacker to read or modify intersite encrypted traffic. This vulnerability is due to an issue with the implementation of the ciphers that are used by the CloudSec encryption feature on affected switches.
network
high complexity
cisco CWE-326
7.4
2023-07-11 CVE-2023-36748 Inadequate Encryption Strength vulnerability in Siemens products
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V2.16.0), RUGGEDCOM ROX RX1501 (All versions < V2.16.0), RUGGEDCOM ROX RX1510 (All versions < V2.16.0), RUGGEDCOM ROX RX1511 (All versions < V2.16.0), RUGGEDCOM ROX RX1512 (All versions < V2.16.0), RUGGEDCOM ROX RX1524 (All versions < V2.16.0), RUGGEDCOM ROX RX1536 (All versions < V2.16.0), RUGGEDCOM ROX RX5000 (All versions < V2.16.0).
network
high complexity
siemens CWE-326
6.8
2023-07-05 CVE-2023-34337 Inadequate Encryption Strength vulnerability in AMI Megarac Sp-X 12/13
AMI SPx contains a vulnerability in the BMC where a user may cause an inadequate encryption strength by hash-based message authentication code (HMAC).
network
low complexity
ami CWE-326
8.8