CWE-326
Allowed-with-ReviewInadequate Encryption Strength
Abstraction: Class · Status: Draft
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
664 vulnerabilities reference this CWE, most recent first.
GHSA-67RP-QVHX-GP49
Vulnerability from github – Published: 2022-05-14 04:03 – Updated: 2022-05-14 04:03A vulnerability in Trend Micro ScanMail for Exchange 12.0 exists in which some communications to the update servers are not encrypted.
{
"affected": [],
"aliases": [
"CVE-2017-14090"
],
"database_specific": {
"cwe_ids": [
"CWE-326"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2017-12-16T02:29:00Z",
"severity": "CRITICAL"
},
"details": "A vulnerability in Trend Micro ScanMail for Exchange 12.0 exists in which some communications to the update servers are not encrypted.",
"id": "GHSA-67rp-qvhx-gp49",
"modified": "2022-05-14T04:03:37Z",
"published": "2022-05-14T04:03:37Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2017-14090"
},
{
"type": "WEB",
"url": "https://success.trendmicro.com/solution/1118486"
},
{
"type": "WEB",
"url": "https://www.coresecurity.com/advisories/trend-micro-scanmail-microsoft-exchange-multiple-vulnerabilities"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-68PF-56RH-7FJ8
Vulnerability from github – Published: 2022-05-13 01:53 – Updated: 2022-05-13 01:53comforte SWAP 1049 through 1069 and 20.0.0 through 21.5.3 (as used in SSLOBJ on HPE NonStop SSL T0910, and in the comforte SecurCS, SecurFTP, SecurLib/SSL-AT, and SecurTN products), after executing the RELOAD CERTIFICATES command, does not ensure that clients use a strong TLS cipher suite, which makes it easier for remote attackers to defeat intended cryptographic protection mechanisms by sniffing the network. This is fixed in 21.6.0.
{
"affected": [],
"aliases": [
"CVE-2018-6653"
],
"database_specific": {
"cwe_ids": [
"CWE-326"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2018-03-01T00:29:00Z",
"severity": "MODERATE"
},
"details": "comforte SWAP 1049 through 1069 and 20.0.0 through 21.5.3 (as used in SSLOBJ on HPE NonStop SSL T0910, and in the comforte SecurCS, SecurFTP, SecurLib/SSL-AT, and SecurTN products), after executing the RELOAD CERTIFICATES command, does not ensure that clients use a strong TLS cipher suite, which makes it easier for remote attackers to defeat intended cryptographic protection mechanisms by sniffing the network. This is fixed in 21.6.0.",
"id": "GHSA-68pf-56rh-7fj8",
"modified": "2022-05-13T01:53:09Z",
"published": "2022-05-13T01:53:09Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2018-6653"
},
{
"type": "WEB",
"url": "https://comforte.com/cve-2018-6653"
},
{
"type": "WEB",
"url": "https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US\u0026docId=emr_na-hpesbns03827en_us"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-69H6-426Q-XX8G
Vulnerability from github – Published: 2023-07-05 21:30 – Updated: 2024-04-04 05:23AMI SPx contains a vulnerability in the BMC where a user may cause an inadequate encryption strength by hash-based message authentication code (HMAC). A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity, and availability.
{
"affected": [],
"aliases": [
"CVE-2023-34337"
],
"database_specific": {
"cwe_ids": [
"CWE-326"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-07-05T19:15:09Z",
"severity": "HIGH"
},
"details": "\nAMI SPx contains a vulnerability in the BMC where a user may cause an inadequate encryption strength by hash-based message authentication code (HMAC). A successful exploit of this vulnerability\u00a0may lead to a loss of confidentiality, integrity, and availability. \n\n\n\n",
"id": "GHSA-69h6-426q-xx8g",
"modified": "2024-04-04T05:23:56Z",
"published": "2023-07-05T21:30:17Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-34337"
},
{
"type": "WEB",
"url": "https://9443417.fs1.hubspotusercontent-na1.net/hubfs/9443417/Security%20Advisories/AMI-SA-2023006.pdf"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:A/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-6CH4-944P-WF7J
Vulnerability from github – Published: 2025-08-07 21:31 – Updated: 2025-08-12 15:31ruby-jwt v3.0.0.beta1 was discovered to contain weak encryption. NOTE: the Supplier's perspective is "keysize is not something that is enforced by this library. Currently more recent versions of OpenSSL are enforcing some key sizes and those restrictions apply to the users of this gem also."
{
"affected": [],
"aliases": [
"CVE-2025-45765"
],
"database_specific": {
"cwe_ids": [
"CWE-326"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-08-07T21:15:27Z",
"severity": "CRITICAL"
},
"details": "ruby-jwt v3.0.0.beta1 was discovered to contain weak encryption. NOTE: the Supplier\u0027s perspective is \"keysize is not something that is enforced by this library. Currently more recent versions of OpenSSL are enforcing some key sizes and those restrictions apply to the users of this gem also.\"",
"id": "GHSA-6ch4-944p-wf7j",
"modified": "2025-08-12T15:31:15Z",
"published": "2025-08-07T21:31:08Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45765"
},
{
"type": "WEB",
"url": "https://github.com/jwt/ruby-jwt/issues/668"
},
{
"type": "WEB",
"url": "https://gist.github.com/ZupeiNie/c621253068ce5b64911629534879e8f9"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-6FQJ-W26X-Q42V
Vulnerability from github – Published: 2021-12-02 00:00 – Updated: 2021-12-03 00:00IBM QRadar SIEM 7.3 and 7.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 196074.
{
"affected": [],
"aliases": [
"CVE-2021-20400"
],
"database_specific": {
"cwe_ids": [
"CWE-326"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2021-12-01T17:15:00Z",
"severity": "HIGH"
},
"details": "IBM QRadar SIEM 7.3 and 7.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 196074.",
"id": "GHSA-6fqj-w26x-q42v",
"modified": "2021-12-03T00:00:43Z",
"published": "2021-12-02T00:00:37Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-20400"
},
{
"type": "WEB",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/196074"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/6520488"
}
],
"schema_version": "1.4.0",
"severity": []
}
GHSA-6GCH-63WP-4V5F
Vulnerability from github – Published: 2024-09-25 03:30 – Updated: 2025-05-16 22:14In Apache Linkis <= 1.5.0, a Random string security vulnerability in Spark EngineConn, random string generated by the Token when starting Py4j uses the Commons Lang's RandomStringUtils. Users are recommended to upgrade to version 1.6.0, which fixes this issue.
{
"affected": [
{
"package": {
"ecosystem": "Maven",
"name": "org.apache.linkis:linkis-engineplugin-spark"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.6.0"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2024-39928"
],
"database_specific": {
"cwe_ids": [
"CWE-326"
],
"github_reviewed": true,
"github_reviewed_at": "2024-09-25T14:29:58Z",
"nvd_published_at": "2024-09-25T01:15:40Z",
"severity": "HIGH"
},
"details": "In Apache Linkis \u003c= 1.5.0, a Random string security vulnerability in Spark EngineConn,\u00a0random string generated by the Token when starting Py4j uses the Commons Lang\u0027s RandomStringUtils.\nUsers are recommended to upgrade to version 1.6.0, which fixes this issue.",
"id": "GHSA-6gch-63wp-4v5f",
"modified": "2025-05-16T22:14:57Z",
"published": "2024-09-25T03:30:35Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39928"
},
{
"type": "WEB",
"url": "https://github.com/apache/linkis/commit/82c2f4b201b746e9206bb58ef98f536fc333aa07"
},
{
"type": "PACKAGE",
"url": "https://github.com/apache/linkis"
},
{
"type": "WEB",
"url": "https://lists.apache.org/thread/g664n13nb17rsogcfrn8kjgd8m89p8nw"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2024/09/24/2"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
},
{
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
"type": "CVSS_V4"
}
],
"summary": "Apache Linkis Spark EngineConn: Commons Lang\u0027s RandomStringUtils Random string security vulnerability"
}
GHSA-6H88-QJPV-P32M
Vulnerability from github – Published: 2017-10-24 18:33 – Updated: 2022-04-25 16:33The OpenSSL gem for Ruby uses the same initialization vector (IV) in GCM Mode (aes-*-gcm) when the IV is set before the key, which makes it easier for context-dependent attackers to bypass the encryption protection mechanism.
{
"affected": [
{
"package": {
"ecosystem": "RubyGems",
"name": "openssl"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2.0.0"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2016-7798"
],
"database_specific": {
"cwe_ids": [
"CWE-326"
],
"github_reviewed": true,
"github_reviewed_at": "2020-06-16T21:19:22Z",
"nvd_published_at": null,
"severity": "HIGH"
},
"details": "The OpenSSL gem for Ruby uses the same initialization vector (IV) in GCM Mode (aes-*-gcm) when the IV is set before the key, which makes it easier for context-dependent attackers to bypass the encryption protection mechanism.",
"id": "GHSA-6h88-qjpv-p32m",
"modified": "2022-04-25T16:33:57Z",
"published": "2017-10-24T18:33:35Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2016-7798"
},
{
"type": "WEB",
"url": "https://github.com/ruby/openssl/issues/49"
},
{
"type": "WEB",
"url": "https://github.com/ruby/openssl/commit/8108e0a6db133f3375608303fdd2083eb5115062"
},
{
"type": "ADVISORY",
"url": "https://github.com/advisories/GHSA-6h88-qjpv-p32m"
},
{
"type": "PACKAGE",
"url": "https://github.com/ruby/openssl"
},
{
"type": "WEB",
"url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/openssl/CVE-2016-7798.yml"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2018/07/msg00012.html"
},
{
"type": "WEB",
"url": "https://web.archive.org/web/20210121065227/https://www.securityfocus.com/bid/93031/info"
},
{
"type": "WEB",
"url": "https://www.debian.org/security/2017/dsa-3966"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2016/09/19/9"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2016/09/30/6"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2016/10/01/2"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
}
],
"summary": "OpenSSL gem for Ruby using inadequate encryption strength"
}
GHSA-6J7Q-RMRP-5G6F
Vulnerability from github – Published: 2022-05-24 17:37 – Updated: 2022-05-24 17:37An issue was discovered in Programi Bilanc build 007 release 014 31.01.2020 and possibly below. It relies on broken encryption with a weak and guessable static encryption key.
{
"affected": [],
"aliases": [
"CVE-2020-11719"
],
"database_specific": {
"cwe_ids": [
"CWE-326"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2020-12-23T17:15:00Z",
"severity": "HIGH"
},
"details": "An issue was discovered in Programi Bilanc build 007 release 014 31.01.2020 and possibly below. It relies on broken encryption with a weak and guessable static encryption key.",
"id": "GHSA-6j7q-rmrp-5g6f",
"modified": "2022-05-24T17:37:00Z",
"published": "2022-05-24T17:37:00Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-11719"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/160625/Programi-Bilanc-Build-007-Release-014-31.01.2020-Static-Key.html"
},
{
"type": "WEB",
"url": "http://seclists.org/fulldisclosure/2020/Dec/35"
}
],
"schema_version": "1.4.0",
"severity": []
}
GHSA-6J9J-GVJ5-P6JX
Vulnerability from github – Published: 2022-04-07 00:00 – Updated: 2022-04-14 00:00An issue was discovered in HTCondor 9.0.x before 9.0.10 and 9.1.x before 9.5.1. An attacker who can capture HTCondor network data can interfere with users' jobs and data.
{
"affected": [],
"aliases": [
"CVE-2021-45104"
],
"database_specific": {
"cwe_ids": [
"CWE-326"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2022-04-06T02:15:00Z",
"severity": "HIGH"
},
"details": "An issue was discovered in HTCondor 9.0.x before 9.0.10 and 9.1.x before 9.5.1. An attacker who can capture HTCondor network data can interfere with users\u0027 jobs and data.",
"id": "GHSA-6j9j-gvj5-p6jx",
"modified": "2022-04-14T00:00:31Z",
"published": "2022-04-07T00:00:20Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-45104"
},
{
"type": "WEB",
"url": "https://research.cs.wisc.edu/htcondor/security/vulnerabilities/HTCONDOR-2021-0006"
},
{
"type": "WEB",
"url": "https://research.cs.wisc.edu/htcondor/security/vulnerabilities/HTCONDOR-2022-0002"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-6JVC-Q2X7-PCHV
Vulnerability from github – Published: 2022-12-28 00:30 – Updated: 2026-02-03 17:28The AWS S3 Crypto SDK sends an unencrypted hash of the plaintext alongside the ciphertext as a metadata field. This hash can be used to brute force the plaintext, if the hash is readable to the attacker. AWS now blocks this metadata field, but older SDK versions still send it.
{
"affected": [
{
"package": {
"ecosystem": "Go",
"name": "github.com/aws/aws-sdk-go"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.34.0"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2022-2582"
],
"database_specific": {
"cwe_ids": [
"CWE-326"
],
"github_reviewed": true,
"github_reviewed_at": "2022-12-30T18:53:40Z",
"nvd_published_at": "2022-12-27T22:15:00Z",
"severity": "MODERATE"
},
"details": "The AWS S3 Crypto SDK sends an unencrypted hash of the plaintext alongside the ciphertext as a metadata field. This hash can be used to brute force the plaintext, if the hash is readable to the attacker. AWS now blocks this metadata field, but older SDK versions still send it.",
"id": "GHSA-6jvc-q2x7-pchv",
"modified": "2026-02-03T17:28:52Z",
"published": "2022-12-28T00:30:23Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/google/security-research/security/advisories/GHSA-76wf-9vgp-pj7w"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-2582"
},
{
"type": "WEB",
"url": "https://github.com/aws/aws-sdk-go/commit/35fa6ddf45c061e0f08d3a3b5119f8f4da38f6d1"
},
{
"type": "PACKAGE",
"url": "https://github.com/aws/aws-sdk-go"
},
{
"type": "WEB",
"url": "https://pkg.go.dev/vuln/GO-2022-0391"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"type": "CVSS_V3"
}
],
"summary": "AWS S3 Crypto SDK sends an unencrypted hash of the plaintext alongside the ciphertext as a metadata field"
}
Mitigation
Use an encryption scheme that is currently considered to be strong by experts in the field.
CAPEC-112: Brute Force
In this attack, some asset (information, functionality, identity, etc.) is protected by a finite secret value. The attacker attempts to gain access to this asset by using trial-and-error to exhaustively explore all the possible secret values in the hope of finding the secret (or a value that is functionally equivalent) that will unlock the asset.
CAPEC-192: Protocol Analysis
An adversary engages in activities to decipher and/or decode protocol information for a network or application communication protocol used for transmitting information between interconnected nodes or systems on a packet-switched data network. While this type of analysis involves the analysis of a networking protocol inherently, it does not require the presence of an actual or physical network.
CAPEC-20: Encryption Brute Forcing
An attacker, armed with the cipher text and the encryption algorithm used, performs an exhaustive (brute force) search on the key space to determine the key that decrypts the cipher text to obtain the plaintext.