Vulnerabilities > Use of a Broken or Risky Cryptographic Algorithm

DATE CVE VULNERABILITY TITLE RISK
2023-05-25 CVE-2023-2900 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Nfine Rapid Development Platform Project Nfine Rapid Development Platform 20230511
A vulnerability was found in NFine Rapid Development Platform 20230511.
7.5
2023-05-16 CVE-2023-28076 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Dell Cloudlink
CloudLink 7.1.2 and all prior versions contain a broken or risky cryptographic algorithm vulnerability.
network
low complexity
dell CWE-327
7.5
2023-05-06 CVE-2022-22313 Use of a Broken or Risky Cryptographic Algorithm vulnerability in IBM Qradar Data Synchronization
IBM QRadar Data Synchronization App 1.0 through 3.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
network
low complexity
ibm CWE-327
7.5
2023-05-03 CVE-2022-45858 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Fortinet Fortinac
A use of a weak cryptographic algorithm vulnerability [CWE-327] in FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.0 all versions, 8.8.0 all versions, 8.7.0 all versions may increase the chances of an attacker to have access to sensitive information or to perform man-in-the-middle attacks.
network
high complexity
fortinet CWE-327
7.4
2023-04-28 CVE-2023-27557 Use of a Broken or Risky Cryptographic Algorithm vulnerability in IBM Safer Payments
IBM Counter Fraud Management for Safer Payments 6.1.0.00 through 6.1.1.02, 6.2.0.00 through 6.2.2.02, 6.3.0.00 through 6.3.1.02, 6.4.0.00 through 6.4.2.01, and 6.5.0.00 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
network
low complexity
ibm CWE-327
7.5
2023-04-25 CVE-2022-40722 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Pingidentity products
A misconfiguration of RSA padding implemented in the PingID Adapter for PingFederate to support Offline MFA with PingID mobile authenticators is vulnerable to pre-computed dictionary attacks, leading to a bypass of offline MFA.
network
high complexity
pingidentity CWE-327
5.8
2023-03-24 CVE-2023-22812 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Westerndigital Sandisk Privateaccess
SanDisk PrivateAccess versions prior to 6.4.9 support insecure TLS 1.0 and TLS 1.1 protocols which are susceptible to man-in-the-middle attacks thereby compromising confidentiality and integrity of data.
network
high complexity
westerndigital CWE-327
7.4
2023-02-22 CVE-2023-23040 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Tp-Link Tl-Wr940N Firmware 63.19.1
TP-Link router TL-WR940N V6 3.19.1 Build 180119 uses a deprecated MD5 algorithm to hash the admin password used for basic authentication.
network
low complexity
tp-link CWE-327
7.5
2023-02-17 CVE-2023-23695 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Dell Secure Connect Gateway 5.12.00.10/5.14.00.12
Dell Secure Connect Gateway (SCG) version 5.14.00.12 contains a broken cryptographic algorithm vulnerability.
network
high complexity
dell CWE-327
5.9
2023-02-14 CVE-2022-22564 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Dell products
Dell EMC Unity versions before 5.2.0.0.5.173 , use(es) broken cryptographic algorithm.
network
high complexity
dell CWE-327
5.9