Vulnerabilities > Use of Insufficiently Random Values

DATE CVE VULNERABILITY TITLE RISK
2023-03-31 CVE-2023-0343 Use of Insufficiently Random Values vulnerability in Akuvox E11 Firmware
Akuvox E11 contains a function that encrypts messages which are then forwarded.
network
low complexity
akuvox CWE-330
7.5
2023-03-16 CVE-2022-26080 Use of Insufficiently Random Values vulnerability in ABB products
Use of Insufficiently Random Values vulnerability in ABB Pulsar Plus System Controller NE843_S, ABB Infinity DC Power Plant.This issue affects Pulsar Plus System Controller NE843_S : comcode 150042936; Infinity DC Power Plant: H5692448 G104 G842 G224L G630-4 G451C(2) G461(2) – comcode 150047415.
network
low complexity
abb CWE-330
4.3
2023-03-14 CVE-2022-39216 Use of Insufficiently Random Values vulnerability in Combodo Itop
Combodo iTop is an open source, web-based IT service management platform.
network
low complexity
combodo CWE-330
critical
9.8
2023-02-23 CVE-2023-20016 Use of Insufficiently Random Values vulnerability in Cisco products
A vulnerability in the backup configuration feature of Cisco UCS Manager Software and in the configuration export feature of Cisco FXOS Software could allow an unauthenticated attacker with access to a backup file to decrypt sensitive information stored in the full state and configuration backup files.
local
low complexity
cisco CWE-330
6.5
2023-02-10 CVE-2022-43501 Use of Insufficiently Random Values vulnerability in Elwsc products
KASAGO TCP/IP stack provided by Zuken Elmic generates ISNs(Initial Sequence Number) for TCP connections from an insufficiently random source.
network
low complexity
elwsc CWE-330
critical
9.1
2023-01-20 CVE-2023-22912 Use of Insufficiently Random Values vulnerability in Mediawiki
An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1.
network
low complexity
mediawiki CWE-330
5.3
2023-01-12 CVE-2023-22601 Use of Insufficiently Random Values vulnerability in Inhandnetworks Inrouter302 Firmware and Inrouter615-S Firmware
InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-S-V2.3.0.r5542, contain vulnerability CWE-330: Use of Insufficiently Random Values. They do not properly randomize MQTT ClientID parameters.
network
low complexity
inhandnetworks CWE-330
8.6
2023-01-12 CVE-2017-5242 Use of Insufficiently Random Values vulnerability in Rapid7 Insightvm
Nexpose and InsightVM virtual appliances downloaded between April 5th, 2017 and May 3rd, 2017 contain identical SSH host keys.
network
high complexity
rapid7 CWE-330
7.7
2023-01-11 CVE-2021-26407 Use of Insufficiently Random Values vulnerability in AMD Romepi Firmware
A randomly generated Initialization Vector (IV) may lead to a collision of IVs with the same key potentially resulting in information disclosure.
local
low complexity
amd CWE-330
5.5
2022-12-27 CVE-2019-25089 Use of Insufficiently Random Values vulnerability in Muon Project Muon 0.1.1
A vulnerability has been found in Morgawr Muon 0.1.1 and classified as problematic.
network
low complexity
muon-project CWE-330
7.5