Vulnerabilities > Use of a Broken or Risky Cryptographic Algorithm

DATE CVE VULNERABILITY TITLE RISK
2023-07-07 CVE-2023-35890 Use of a Broken or Risky Cryptographic Algorithm vulnerability in IBM Websphere Application Server 8.5.5.23/9.0.5.15/9.0.5.16
IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security, caused by the improper encoding in a local configuration file.
local
low complexity
ibm CWE-327
5.5
2023-06-27 CVE-2023-26276 Use of a Broken or Risky Cryptographic Algorithm vulnerability in IBM Qradar Security Information and Event Manager 7.5.0
IBM QRadar SIEM 7.5.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
network
low complexity
ibm CWE-327
7.5
2023-06-22 CVE-2023-28006 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Hcltech Bigfix OSD Bare Metal Server 311.12
The OSD Bare Metal Server uses a cryptographic algorithm that is no longer considered sufficiently secure.
local
low complexity
hcltech CWE-327
7.8
2023-06-15 CVE-2023-21115 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Google Android 11.0/12.0/12.1
In btm_sec_encrypt_change of btm_sec.cc, there is a possible way to downgrade the link key type due to improperly used crypto.
low complexity
google CWE-327
8.8
2023-06-13 CVE-2022-43949 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Fortinet Fortisiem
A use of a broken or risky cryptographic algorithm [CWE-327] in Fortinet FortiSIEM before 6.7.1 allows a remote unauthenticated attacker to perform brute force attacks on GUI endpoints via taking advantage of outdated hashing methods.
network
low complexity
fortinet CWE-327
7.5
2023-05-25 CVE-2023-2900 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Nfine Rapid Development Platform Project Nfine Rapid Development Platform 20230511
A vulnerability was found in NFine Rapid Development Platform 20230511.
7.5
2023-05-03 CVE-2022-45858 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Fortinet Fortinac
A use of a weak cryptographic algorithm vulnerability [CWE-327] in FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.0 all versions, 8.8.0 all versions, 8.7.0 all versions may increase the chances of an attacker to have access to sensitive information or to perform man-in-the-middle attacks.
network
high complexity
fortinet CWE-327
7.4
2023-04-25 CVE-2022-40722 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Pingidentity products
A misconfiguration of RSA padding implemented in the PingID Adapter for PingFederate to support Offline MFA with PingID mobile authenticators is vulnerable to pre-computed dictionary attacks, leading to a bypass of offline MFA.
network
high complexity
pingidentity CWE-327
5.8
2023-04-14 CVE-2022-45170 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Liveboxcloud Vdesk 018
An issue was discovered in LIVEBOX Collaboration vDesk through v018.
network
low complexity
liveboxcloud CWE-327
6.5
2023-03-29 CVE-2023-28509 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Rocketsoftware Unidata and Universe
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 use weak encryption for packet-level security and passwords transferred on the wire.
network
low complexity
rocketsoftware CWE-327
7.5