Vulnerabilities > Use of Insufficiently Random Values

DATE CVE VULNERABILITY TITLE RISK
2018-07-30 CVE-2018-13280 Use of Insufficiently Random Values vulnerability in Synology Diskstation Manager
Use of insufficiently random values vulnerability in SYNO.Encryption.GenRandomKey in Synology DiskStation Manager (DSM) before 6.2-23739 allows man-in-the-middle attackers to compromise non-HTTPS sessions via unspecified vectors.
network
synology CWE-330
4.3
2018-07-11 CVE-2018-11045 Use of Insufficiently Random Values vulnerability in Pivotal Software Operations Manager
Pivotal Operations Manager, versions 2.1 prior to 2.1.6 and 2.0 prior to 2.0.15 and 1.12 prior to 1.12.22, contains a static Linux Random Number Generator (LRNG) seed file embedded in the appliance image.
4.3
2018-06-04 CVE-2017-16031 Use of Insufficiently Random Values vulnerability in Socket Socket.Io
Socket.io is a realtime application framework that provides communication via websockets.
network
low complexity
socket CWE-330
5.0
2018-05-21 CVE-2018-1108 Use of Insufficiently Random Values vulnerability in multiple products
kernel drivers before version 4.17-rc1 are vulnerable to a weakness in the Linux kernel's implementation of random seed data.
network
high complexity
linux canonical debian CWE-330
5.9
2018-03-27 CVE-2018-1266 Use of Insufficiently Random Values vulnerability in Cloudfoundry Capi-Release
Cloud Foundry Cloud Controller, versions prior to 1.52.0, contains information disclosure and path traversal vulnerabilities.
network
low complexity
cloudfoundry CWE-330
6.5
2018-02-19 CVE-2017-16924 Use of Insufficiently Random Values vulnerability in Zohocorp Manageengine Desktop Central 10.0.137
Remote Information Disclosure and Escalation of Privileges in ManageEngine Desktop Central MSP 10.0.137 allows attackers to download unencrypted XML files containing all data for configuration policies via a predictable /client-data/<client_id>/collections/##/usermgmt.xml URL, as demonstrated by passwords and Wi-Fi keys.
network
low complexity
zohocorp CWE-330
5.0
2018-01-31 CVE-2017-15654 Use of Insufficiently Random Values vulnerability in Asus Asuswrt 3.0.0.4.378/3.0.0.4.380.7743
Highly predictable session tokens in the HTTPd server in all current versions (<= 3.0.0.4.380.7743) of Asus asuswrt allow gaining administrative router access.
network
high complexity
asus CWE-330
7.6
2017-12-31 CVE-2017-17704 Use of Insufficiently Random Values vulnerability in Swhouse Istar Ultra Firmware
A door-unlocking issue was discovered on Software House iStar Ultra devices through 6.5.2.20569 when used in conjunction with the IP-ACM Ethernet Door Module.
network
swhouse CWE-330
5.8
2017-12-29 CVE-2017-17910 Use of Insufficiently Random Values vulnerability in Hoermann products
On Hoermann BiSecur devices before 2018, a vulnerability can be exploited by recording a single radio transmission.
low complexity
hoermann CWE-330
3.3
2017-12-02 CVE-2017-17091 Use of Insufficiently Random Values vulnerability in Wordpress
wp-admin/user-new.php in WordPress before 4.9.1 sets the newbloguser key to a string that can be directly derived from the user ID, which allows remote attackers to bypass intended access restrictions by entering this string.
network
low complexity
wordpress CWE-330
6.5