Vulnerabilities > Use of a Broken or Risky Cryptographic Algorithm

DATE CVE VULNERABILITY TITLE RISK
2019-09-04 CVE-2019-12587 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Espressif Esp-Idf and Esp8266 Nonos SDK
The EAP peer implementation in Espressif ESP-IDF 2.0.0 through 4.0.0 and ESP8266_NONOS_SDK 2.2.0 through 3.1.0 allows the installation of a zero Pairwise Master Key (PMK) after the completion of any EAP authentication method, which allows attackers in radio range to replay, decrypt, or spoof frames via a rogue access point.
low complexity
espressif CWE-327
4.8
2019-08-30 CVE-2018-18371 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Broadcom Advanced Secure Gateway and Symantec Proxysg
The ASG/ProxySG FTP proxy WebFTP mode allows intercepting FTP connections where a user accesses an FTP server via a ftp:// URL in a web browser.
network
low complexity
broadcom CWE-327
4.0
2019-08-21 CVE-2019-12621 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Cisco products
A vulnerability in Cisco HyperFlex Software could allow an unauthenticated, remote attacker to perform a man-in-the-middle attack.
network
cisco CWE-327
5.8
2019-08-20 CVE-2019-5035 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Google Nest CAM IQ Indoor Firmware 4620002
An exploitable information disclosure vulnerability exists in the Weave PASE pairing functionality of the Nest Cam IQ Indoor, version 4620002.
network
google CWE-327
6.8
2019-08-15 CVE-2019-9013 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Codesys products
An issue was discovered in 3S-Smart CODESYS V3 products.
low complexity
codesys CWE-327
8.8
2019-08-14 CVE-2019-9506 Use of a Broken or Risky Cryptographic Algorithm vulnerability in multiple products
The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation.
4.8
2019-08-13 CVE-2019-10929 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Siemens products
A vulnerability has been identified in SIMATIC CP 1626 (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl.
network
siemens CWE-327
4.3
2019-08-07 CVE-2016-5431 Use of a Broken or Risky Cryptographic Algorithm vulnerability in PHP Jose Project PHP Jose
The PHP JOSE Library by Gree Inc.
network
low complexity
php-jose-project CWE-327
7.5
2019-07-15 CVE-2019-13604 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Assaabloy HID Digitalpersona 4500 Firmware 24
There is a short key vulnerability in HID Global DigitalPersona (formerly Crossmatch) U.are.U 4500 Fingerprint Reader v24.
network
assaabloy CWE-327
4.3
2019-07-08 CVE-2019-12171 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Dropbox 71.4.108.0
Dropbox.exe (and QtWebEngineProcess.exe in the Web Helper) in the Dropbox desktop application 71.4.108.0 store cleartext credentials in memory upon successful login or new account creation.
network
dropbox CWE-327
4.3