Vulnerabilities > Inadequate Encryption Strength

DATE CVE VULNERABILITY TITLE RISK
2022-10-10 CVE-2021-35226 Inadequate Encryption Strength vulnerability in Solarwinds Network Configuration Manager
An entity in Network Configuration Manager product is misconfigured and exposing password field to Solarwinds Information Service (SWIS).
network
low complexity
solarwinds CWE-326
6.5
2022-10-10 CVE-2022-3433 Inadequate Encryption Strength vulnerability in Haskell Aeson
The aeson library is not safe to use to consume untrusted JSON input.
network
low complexity
haskell CWE-326
6.5
2022-10-06 CVE-2022-3273 Inadequate Encryption Strength vulnerability in Ikus-Soft Rdiffweb
Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a4.
network
low complexity
ikus-soft CWE-326
critical
9.8
2022-09-19 CVE-2022-29835 Inadequate Encryption Strength vulnerability in Westerndigital WD Discovery 4.0.251.0
WD Discovery software executable files were signed with an unsafe SHA-1 hashing algorithm.
network
low complexity
westerndigital CWE-326
5.3
2022-08-31 CVE-2022-2758 Inadequate Encryption Strength vulnerability in Ls-Electric products
Passwords are not adequately encrypted during the communication process between all versions of LS Industrial Systems (LSIS) Co.
network
high complexity
ls-electric CWE-326
5.9
2022-08-02 CVE-2022-30285 Inadequate Encryption Strength vulnerability in Quest Kace Systems Management Appliance
In Quest KACE Systems Management Appliance (SMA) through 12.0, a hash collision is possible during authentication.
network
low complexity
quest CWE-326
critical
9.8
2022-07-08 CVE-2022-22464 Inadequate Encryption Strength vulnerability in IBM Security Verify Access
IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
network
low complexity
ibm CWE-326
5.0
2022-06-02 CVE-2022-31459 Inadequate Encryption Strength vulnerability in Owllabs Meeting OWL PRO Firmware 5.2.0.15
Owl Labs Meeting Owl 5.2.0.15 allows attackers to retrieve the passcode hash via a certain c 10 value over Bluetooth.
low complexity
owllabs CWE-326
6.5
2022-05-19 CVE-2020-16235 Inadequate Encryption Strength vulnerability in Emerson Openenterprise Scada Server 2.8.3/3.1/3.3.3
Inadequate encryption may allow the credentials used by Emerson OpenEnterprise, up through version 3.3.5, to access field devices and external systems to be obtained.
local
low complexity
emerson CWE-326
2.1
2022-05-06 CVE-2021-27761 Inadequate Encryption Strength vulnerability in Hcltech Bigfix Platform
Weak web transport security (Weak TLS): An attacker may be able to decrypt the data using attacks
network
low complexity
hcltech CWE-326
5.0