CWE-326
Allowed-with-ReviewInadequate Encryption Strength
Abstraction: Class · Status: Draft
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
664 vulnerabilities reference this CWE, most recent first.
GHSA-RHCH-PCQ2-7GP3
Vulnerability from github – Published: 2022-05-13 01:07 – Updated: 2025-04-11 03:50The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a "BEAST" attack.
{
"affected": [],
"aliases": [
"CVE-2011-3389"
],
"database_specific": {
"cwe_ids": [
"CWE-20",
"CWE-326"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2011-09-06T19:55:00Z",
"severity": "MODERATE"
},
"details": "The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a \"BEAST\" attack.",
"id": "GHSA-rhch-pcq2-7gp3",
"modified": "2025-04-11T03:50:17Z",
"published": "2022-05-13T01:07:48Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2011-3389"
},
{
"type": "WEB",
"url": "https://blogs.oracle.com/sunsecurity/entry/multiple_vulnerabilities_in_fetchmail"
},
{
"type": "WEB",
"url": "https://bugzilla.novell.com/show_bug.cgi?id=719047"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=737506"
},
{
"type": "WEB",
"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-556833.pdf"
},
{
"type": "WEB",
"url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-006"
},
{
"type": "WEB",
"url": "https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03839862"
},
{
"type": "WEB",
"url": "https://hermes.opensuse.org/messages/13154861"
},
{
"type": "WEB",
"url": "https://hermes.opensuse.org/messages/13155432"
},
{
"type": "WEB",
"url": "https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02"
},
{
"type": "WEB",
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14752"
},
{
"type": "WEB",
"url": "http://blog.mozilla.com/security/2011/09/27/attack-against-tls-protected-communications"
},
{
"type": "WEB",
"url": "http://blogs.technet.com/b/msrc/archive/2011/09/26/microsoft-releases-security-advisory-2588513.aspx"
},
{
"type": "WEB",
"url": "http://blogs.technet.com/b/srd/archive/2011/09/26/is-ssl-broken-more-about-security-advisory-2588513.aspx"
},
{
"type": "WEB",
"url": "http://curl.haxx.se/docs/adv_20120124B.html"
},
{
"type": "WEB",
"url": "http://downloads.asterisk.org/pub/security/AST-2016-001.html"
},
{
"type": "WEB",
"url": "http://ekoparty.org/2011/juliano-rizzo.php"
},
{
"type": "WEB",
"url": "http://eprint.iacr.org/2004/111"
},
{
"type": "WEB",
"url": "http://eprint.iacr.org/2006/136"
},
{
"type": "WEB",
"url": "http://googlechromereleases.blogspot.com/2011/10/chrome-stable-release.html"
},
{
"type": "WEB",
"url": "http://isc.sans.edu/diary/SSL+TLS+part+3+/11635"
},
{
"type": "WEB",
"url": "http://lists.apple.com/archives/Security-announce/2011//Oct/msg00001.html"
},
{
"type": "WEB",
"url": "http://lists.apple.com/archives/Security-announce/2011//Oct/msg00002.html"
},
{
"type": "WEB",
"url": "http://lists.apple.com/archives/security-announce/2012/Feb/msg00000.html"
},
{
"type": "WEB",
"url": "http://lists.apple.com/archives/security-announce/2012/Jul/msg00001.html"
},
{
"type": "WEB",
"url": "http://lists.apple.com/archives/security-announce/2012/May/msg00001.html"
},
{
"type": "WEB",
"url": "http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.html"
},
{
"type": "WEB",
"url": "http://lists.apple.com/archives/security-announce/2013/Oct/msg00004.html"
},
{
"type": "WEB",
"url": "http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00049.html"
},
{
"type": "WEB",
"url": "http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00051.html"
},
{
"type": "WEB",
"url": "http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00009.html"
},
{
"type": "WEB",
"url": "http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html"
},
{
"type": "WEB",
"url": "http://marc.info/?l=bugtraq\u0026m=132750579901589\u0026w=2"
},
{
"type": "WEB",
"url": "http://marc.info/?l=bugtraq\u0026m=132872385320240\u0026w=2"
},
{
"type": "WEB",
"url": "http://marc.info/?l=bugtraq\u0026m=133365109612558\u0026w=2"
},
{
"type": "WEB",
"url": "http://marc.info/?l=bugtraq\u0026m=133728004526190\u0026w=2"
},
{
"type": "WEB",
"url": "http://marc.info/?l=bugtraq\u0026m=134254866602253\u0026w=2"
},
{
"type": "WEB",
"url": "http://marc.info/?l=bugtraq\u0026m=134254957702612\u0026w=2"
},
{
"type": "WEB",
"url": "http://my.opera.com/securitygroup/blog/2011/09/28/the-beast-ssl-tls-issue"
},
{
"type": "WEB",
"url": "http://osvdb.org/74829"
},
{
"type": "WEB",
"url": "http://rhn.redhat.com/errata/RHSA-2012-0508.html"
},
{
"type": "WEB",
"url": "http://rhn.redhat.com/errata/RHSA-2013-1455.html"
},
{
"type": "WEB",
"url": "http://secunia.com/advisories/45791"
},
{
"type": "WEB",
"url": "http://secunia.com/advisories/47998"
},
{
"type": "WEB",
"url": "http://secunia.com/advisories/48256"
},
{
"type": "WEB",
"url": "http://secunia.com/advisories/48692"
},
{
"type": "WEB",
"url": "http://secunia.com/advisories/48915"
},
{
"type": "WEB",
"url": "http://secunia.com/advisories/48948"
},
{
"type": "WEB",
"url": "http://secunia.com/advisories/49198"
},
{
"type": "WEB",
"url": "http://secunia.com/advisories/55322"
},
{
"type": "WEB",
"url": "http://secunia.com/advisories/55350"
},
{
"type": "WEB",
"url": "http://secunia.com/advisories/55351"
},
{
"type": "WEB",
"url": "http://security.gentoo.org/glsa/glsa-201203-02.xml"
},
{
"type": "WEB",
"url": "http://security.gentoo.org/glsa/glsa-201406-32.xml"
},
{
"type": "WEB",
"url": "http://support.apple.com/kb/HT4999"
},
{
"type": "WEB",
"url": "http://support.apple.com/kb/HT5001"
},
{
"type": "WEB",
"url": "http://support.apple.com/kb/HT5130"
},
{
"type": "WEB",
"url": "http://support.apple.com/kb/HT5281"
},
{
"type": "WEB",
"url": "http://support.apple.com/kb/HT5501"
},
{
"type": "WEB",
"url": "http://support.apple.com/kb/HT6150"
},
{
"type": "WEB",
"url": "http://technet.microsoft.com/security/advisory/2588513"
},
{
"type": "WEB",
"url": "http://vnhacker.blogspot.com/2011/09/beast.html"
},
{
"type": "WEB",
"url": "http://www.apcmedia.com/salestools/SJHN-7RKGNM/SJHN-7RKGNM_R4_EN.pdf"
},
{
"type": "WEB",
"url": "http://www.debian.org/security/2012/dsa-2398"
},
{
"type": "WEB",
"url": "http://www.educatedguesswork.org/2011/09/security_impact_of_the_rizzodu.html"
},
{
"type": "WEB",
"url": "http://www.ibm.com/developerworks/java/jdk/alerts"
},
{
"type": "WEB",
"url": "http://www.imperialviolet.org/2011/09/23/chromeandbeast.html"
},
{
"type": "WEB",
"url": "http://www.insecure.cl/Beast-SSL.rar"
},
{
"type": "WEB",
"url": "http://www.kb.cert.org/vuls/id/864643"
},
{
"type": "WEB",
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2012:058"
},
{
"type": "WEB",
"url": "http://www.opera.com/docs/changelogs/mac/1151"
},
{
"type": "WEB",
"url": "http://www.opera.com/docs/changelogs/mac/1160"
},
{
"type": "WEB",
"url": "http://www.opera.com/docs/changelogs/unix/1151"
},
{
"type": "WEB",
"url": "http://www.opera.com/docs/changelogs/unix/1160"
},
{
"type": "WEB",
"url": "http://www.opera.com/docs/changelogs/windows/1151"
},
{
"type": "WEB",
"url": "http://www.opera.com/docs/changelogs/windows/1160"
},
{
"type": "WEB",
"url": "http://www.opera.com/support/kb/view/1004"
},
{
"type": "WEB",
"url": "http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html"
},
{
"type": "WEB",
"url": "http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html"
},
{
"type": "WEB",
"url": "http://www.oracle.com/technetwork/topics/security/javacpuoct2011-443431.html"
},
{
"type": "WEB",
"url": "http://www.redhat.com/support/errata/RHSA-2011-1384.html"
},
{
"type": "WEB",
"url": "http://www.redhat.com/support/errata/RHSA-2012-0006.html"
},
{
"type": "WEB",
"url": "http://www.securityfocus.com/bid/49388"
},
{
"type": "WEB",
"url": "http://www.securityfocus.com/bid/49778"
},
{
"type": "WEB",
"url": "http://www.securitytracker.com/id/1029190"
},
{
"type": "WEB",
"url": "http://www.securitytracker.com/id?1025997"
},
{
"type": "WEB",
"url": "http://www.securitytracker.com/id?1026103"
},
{
"type": "WEB",
"url": "http://www.securitytracker.com/id?1026704"
},
{
"type": "WEB",
"url": "http://www.ubuntu.com/usn/USN-1263-1"
},
{
"type": "WEB",
"url": "http://www.us-cert.gov/cas/techalerts/TA12-010A.html"
}
],
"schema_version": "1.4.0",
"severity": []
}
GHSA-RHXM-F2F4-P3P6
Vulnerability from github – Published: 2022-05-24 17:38 – Updated: 2025-08-12 18:31IBM Security Guardium Data Encryption (GDE) 3.0.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 158577.
{
"affected": [],
"aliases": [
"CVE-2019-4160"
],
"database_specific": {
"cwe_ids": [
"CWE-326"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2021-01-13T18:15:00Z",
"severity": "HIGH"
},
"details": "IBM Security Guardium Data Encryption (GDE) 3.0.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 158577.",
"id": "GHSA-rhxm-f2f4-p3p6",
"modified": "2025-08-12T18:31:16Z",
"published": "2022-05-24T17:38:57Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2019-4160"
},
{
"type": "WEB",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/158577"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/6403331"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-RJHQ-673F-G5H2
Vulnerability from github – Published: 2022-05-13 01:19 – Updated: 2022-05-13 01:19An issue was discovered in D-Link 'myDlink Baby App' version 2.04.06. Whenever actions are performed from the app (e.g., change camera settings or play lullabies), it communicates directly with the Wi-Fi camera (D-Link 825L firmware 1.08) with the credentials (username and password) in base64 cleartext. An attacker could conduct an MitM attack on the local network and very easily obtain these credentials.
{
"affected": [],
"aliases": [
"CVE-2018-18767"
],
"database_specific": {
"cwe_ids": [
"CWE-326"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2018-12-20T23:29:00Z",
"severity": "HIGH"
},
"details": "An issue was discovered in D-Link \u0027myDlink Baby App\u0027 version 2.04.06. Whenever actions are performed from the app (e.g., change camera settings or play lullabies), it communicates directly with the Wi-Fi camera (D-Link 825L firmware 1.08) with the credentials (username and password) in base64 cleartext. An attacker could conduct an MitM attack on the local network and very easily obtain these credentials.",
"id": "GHSA-rjhq-673f-g5h2",
"modified": "2022-05-13T01:19:40Z",
"published": "2022-05-13T01:19:40Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2018-18767"
},
{
"type": "WEB",
"url": "https://dojo.bullguard.com/dojo-by-bullguard/blog/i-got-my-eyeon-you-security-vulnerabilities-in-baby-monitor"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-RM4R-G9MF-XVCM
Vulnerability from github – Published: 2022-08-19 00:00 – Updated: 2022-08-23 00:00Inadequate encryption strength for some Intel(R) PROSet/Wireless WiFi products may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.
{
"affected": [],
"aliases": [
"CVE-2022-21139"
],
"database_specific": {
"cwe_ids": [
"CWE-326"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2022-08-18T20:15:00Z",
"severity": "HIGH"
},
"details": "Inadequate encryption strength for some Intel(R) PROSet/Wireless WiFi products may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.",
"id": "GHSA-rm4r-g9mf-xvcm",
"modified": "2022-08-23T00:00:18Z",
"published": "2022-08-19T00:00:19Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-21139"
},
{
"type": "WEB",
"url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00621.html"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-RQF2-X29Q-CFXH
Vulnerability from github – Published: 2022-05-17 02:34 – Updated: 2022-05-17 02:34A Weak Password Requirements issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-logic controllers 1763-L16AWA, Series A and B, Version 16.00 and prior versions; 1763-L16BBB, Series A and B, Version 16.00 and prior versions; 1763-L16BWA, Series A and B, Version 16.00 and prior versions; and 1763-L16DWD, Series A and B, Version 16.00 and prior versions and Allen-Bradley MicroLogix 1400 programmable logic controllers 1766-L32AWA, Series A and B, Version 16.00 and prior versions; 1766-L32BWA, Series A and B, Version 16.00 and prior versions; 1766-L32BWAA, Series A and B, Version 16.00 and prior versions; 1766-L32BXB, Series A and B, Version 16.00 and prior versions; 1766-L32BXBA, Series A and B, Version 16.00 and prior versions; and 1766-L32AWAA, Series A and B, Version 16.00 and prior versions. The affected products use a numeric password with a small maximum character size for the password.
{
"affected": [],
"aliases": [
"CVE-2017-7903"
],
"database_specific": {
"cwe_ids": [
"CWE-326",
"CWE-521"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2017-06-30T03:29:00Z",
"severity": "CRITICAL"
},
"details": "A Weak Password Requirements issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-logic controllers 1763-L16AWA, Series A and B, Version 16.00 and prior versions; 1763-L16BBB, Series A and B, Version 16.00 and prior versions; 1763-L16BWA, Series A and B, Version 16.00 and prior versions; and 1763-L16DWD, Series A and B, Version 16.00 and prior versions and Allen-Bradley MicroLogix 1400 programmable logic controllers 1766-L32AWA, Series A and B, Version 16.00 and prior versions; 1766-L32BWA, Series A and B, Version 16.00 and prior versions; 1766-L32BWAA, Series A and B, Version 16.00 and prior versions; 1766-L32BXB, Series A and B, Version 16.00 and prior versions; 1766-L32BXBA, Series A and B, Version 16.00 and prior versions; and 1766-L32AWAA, Series A and B, Version 16.00 and prior versions. The affected products use a numeric password with a small maximum character size for the password.",
"id": "GHSA-rqf2-x29q-cfxh",
"modified": "2022-05-17T02:34:08Z",
"published": "2022-05-17T02:34:08Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2017-7903"
},
{
"type": "WEB",
"url": "https://ics-cert.us-cert.gov/advisories/ICSA-17-115-04"
},
{
"type": "WEB",
"url": "http://www.securitytracker.com/id/1038546"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-RQQ3-V54F-727P
Vulnerability from github – Published: 2023-03-11 00:30 – Updated: 2023-03-16 18:30An improper access control vulnerability exists prior to v6 that could allow an attacker to break the E2E encryption of a chat room by a user changing the group key of a chat room.
{
"affected": [],
"aliases": [
"CVE-2023-23911"
],
"database_specific": {
"cwe_ids": [
"CWE-326"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-03-10T22:15:00Z",
"severity": "HIGH"
},
"details": "An improper access control vulnerability exists prior to v6 that could allow an attacker to break the E2E encryption of a chat room by a user changing the group key of a chat room.",
"id": "GHSA-rqq3-v54f-727p",
"modified": "2023-03-16T18:30:29Z",
"published": "2023-03-11T00:30:16Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23911"
},
{
"type": "WEB",
"url": "https://hackerone.com/reports/1757663"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-RR49-V752-XW3C
Vulnerability from github – Published: 2022-05-24 17:43 – Updated: 2022-05-24 17:43Zoho ManageEngine Application Control Plus before 100523 has an insecure SSL configuration setting for Nginx, leading to Privilege Escalation.
{
"affected": [],
"aliases": [
"CVE-2020-29658"
],
"database_specific": {
"cwe_ids": [
"CWE-326"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2021-03-05T09:15:00Z",
"severity": "CRITICAL"
},
"details": "Zoho ManageEngine Application Control Plus before 100523 has an insecure SSL configuration setting for Nginx, leading to Privilege Escalation.",
"id": "GHSA-rr49-v752-xw3c",
"modified": "2022-05-24T17:43:44Z",
"published": "2022-05-24T17:43:44Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-29658"
},
{
"type": "WEB",
"url": "https://www.manageengine.com/application-control/knowledge-base/privilege-escalation-vulnerability-open-SSL.html"
}
],
"schema_version": "1.4.0",
"severity": []
}
GHSA-RV4V-XM8J-QCCG
Vulnerability from github – Published: 2022-05-13 01:32 – Updated: 2022-05-13 01:32An Inadequate Encryption Strength issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, and OCTOPUS Classic Platform Switches. An inadequate encryption strength vulnerability in the web interface has been identified, which may allow an attacker to obtain sensitive information through a successful man-in-the-middle attack.
{
"affected": [],
"aliases": [
"CVE-2018-5461"
],
"database_specific": {
"cwe_ids": [
"CWE-326"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2018-03-06T21:29:00Z",
"severity": "MODERATE"
},
"details": "An Inadequate Encryption Strength issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, and OCTOPUS Classic Platform Switches. An inadequate encryption strength vulnerability in the web interface has been identified, which may allow an attacker to obtain sensitive information through a successful man-in-the-middle attack.",
"id": "GHSA-rv4v-xm8j-qccg",
"modified": "2022-05-13T01:32:08Z",
"published": "2022-05-13T01:32:08Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2018-5461"
},
{
"type": "WEB",
"url": "https://ics-cert.us-cert.gov/advisories/ICSA-18-065-01"
},
{
"type": "WEB",
"url": "http://www.securityfocus.com/bid/103340"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-RVQ2-HQR6-PGQQ
Vulnerability from github – Published: 2022-05-14 04:04 – Updated: 2025-04-20 03:49An issue was discovered in the software on Vaultek Gun Safe VT20i products. There is no encryption of the session between the Android application and the safe. The website and marketing materials advertise that this communication channel is encrypted with "Highest Level Bluetooth Encryption" and "Data transmissions are secure via AES256 bit encryption." These claims, however, are not true. Moreover, AES256 bit encryption is not supported in the Bluetooth Low Energy (BLE) standard, so it would have to be at the application level. This lack of encryption allows an individual to learn the passcode by eavesdropping on the communications between the application and the safe.
{
"affected": [],
"aliases": [
"CVE-2017-17436"
],
"database_specific": {
"cwe_ids": [
"CWE-326"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2017-12-07T00:29:00Z",
"severity": "HIGH"
},
"details": "An issue was discovered in the software on Vaultek Gun Safe VT20i products. There is no encryption of the session between the Android application and the safe. The website and marketing materials advertise that this communication channel is encrypted with \"Highest Level Bluetooth Encryption\" and \"Data transmissions are secure via AES256 bit encryption.\" These claims, however, are not true. Moreover, AES256 bit encryption is not supported in the Bluetooth Low Energy (BLE) standard, so it would have to be at the application level. This lack of encryption allows an individual to learn the passcode by eavesdropping on the communications between the application and the safe.",
"id": "GHSA-rvq2-hqr6-pgqq",
"modified": "2025-04-20T03:49:32Z",
"published": "2022-05-14T04:04:09Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2017-17436"
},
{
"type": "WEB",
"url": "https://vaulteksafe.com/index.php/cve-2017-17435"
},
{
"type": "WEB",
"url": "https://www.twosixlabs.com/bluesteal-popping-gatt-safes"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-RVXX-GX2M-H7RC
Vulnerability from github – Published: 2022-02-15 01:38 – Updated: 2022-02-15 01:38A flaw was found when an OpenSSL security provider is used with Wildfly, the 'enabled-protocols' value in the Wildfly configuration isn't honored. An attacker could target the traffic sent from Wildfly and downgrade the connection to a weaker version of TLS, potentially breaking the encryption. This could lead to a leak of the data being passed over the network. Wildfly version 7.2.0.GA, 7.2.3.GA and 7.2.5.CR2 are believed to be vulnerable.
{
"affected": [],
"aliases": [
"CVE-2019-14887"
],
"database_specific": {
"cwe_ids": [
"CWE-326",
"CWE-757"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2020-03-16T15:15:00Z",
"severity": "MODERATE"
},
"details": "A flaw was found when an OpenSSL security provider is used with Wildfly, the \u0027enabled-protocols\u0027 value in the Wildfly configuration isn\u0027t honored. An attacker could target the traffic sent from Wildfly and downgrade the connection to a weaker version of TLS, potentially breaking the encryption. This could lead to a leak of the data being passed over the network. Wildfly version 7.2.0.GA, 7.2.3.GA and 7.2.5.CR2 are believed to be vulnerable.",
"id": "GHSA-rvxx-gx2m-h7rc",
"modified": "2022-02-15T01:38:58Z",
"published": "2022-02-15T01:38:58Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2019-14887"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14887"
},
{
"type": "WEB",
"url": "https://issues.redhat.com/browse/JBEAP-17965"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20200327-0007"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"type": "CVSS_V3"
}
],
"summary": "Inadequate Encryption Strength and Algorithm Downgrade in Wildfly"
}
Mitigation
Use an encryption scheme that is currently considered to be strong by experts in the field.
CAPEC-112: Brute Force
In this attack, some asset (information, functionality, identity, etc.) is protected by a finite secret value. The attacker attempts to gain access to this asset by using trial-and-error to exhaustively explore all the possible secret values in the hope of finding the secret (or a value that is functionally equivalent) that will unlock the asset.
CAPEC-192: Protocol Analysis
An adversary engages in activities to decipher and/or decode protocol information for a network or application communication protocol used for transmitting information between interconnected nodes or systems on a packet-switched data network. While this type of analysis involves the analysis of a networking protocol inherently, it does not require the presence of an actual or physical network.
CAPEC-20: Encryption Brute Forcing
An attacker, armed with the cipher text and the encryption algorithm used, performs an exhaustive (brute force) search on the key space to determine the key that decrypts the cipher text to obtain the plaintext.