Total
384 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2023-39252 | 1 Dell | 1 Secure Connect Gateway Policy Manager | 2023-12-10 | N/A | 5.9 MEDIUM |
Dell SCG Policy Manager 5.16.00.14 contains a broken cryptographic algorithm vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by performing MitM attacks and let attackers obtain sensitive information. | |||||
CVE-2022-33160 | 1 Ibm | 1 Security Directory Suite Va | 2023-12-10 | N/A | 7.5 HIGH |
IBM Security Directory Suite 8.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 228568. | |||||
CVE-2023-34130 | 1 Sonicwall | 2 Analytics, Global Management System | 2023-12-10 | N/A | 9.8 CRITICAL |
SonicWall GMS and Analytics use outdated Tiny Encryption Algorithm (TEA) with a hardcoded key to encrypt sensitive data. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions. | |||||
CVE-2023-23346 | 1 Hcltech | 1 Dryice Mycloud | 2023-12-10 | N/A | 7.1 HIGH |
HCL DRYiCE MyCloud is affected by the use of a broken cryptographic algorithm. An attacker can potentially compromise the confidentiality and integrity of sensitive information. | |||||
CVE-2023-4331 | 1 Broadcom | 1 Raid Controller Web Interface | 2023-12-10 | N/A | 7.5 HIGH |
Broadcom RAID Controller web interface is vulnerable has an insecure default TLS configuration that support obsolete and vulnerable TLS protocols | |||||
CVE-2023-5627 | 1 Moxa | 54 Nport 6150, Nport 6150-t, Nport 6150-t Firmware and 51 more | 2023-12-10 | N/A | 7.5 HIGH |
A vulnerability has been identified in NPort 6000 Series, making the authentication mechanism vulnerable. This vulnerability arises from the incorrect implementation of sensitive information protection, potentially allowing malicious users to gain unauthorized access to the web service. | |||||
CVE-2023-36608 | 1 Ovarro | 10 Tbox Lt2, Tbox Lt2 Firmware, Tbox Ms-cpu32 and 7 more | 2023-12-10 | N/A | 6.5 MEDIUM |
The affected TBox RTUs store hashed passwords using MD5 encryption, which is an insecure encryption algorithm. | |||||
CVE-2022-43949 | 1 Fortinet | 1 Fortisiem | 2023-12-10 | N/A | 7.5 HIGH |
A use of a broken or risky cryptographic algorithm [CWE-327] in Fortinet FortiSIEM before 6.7.1 allows a remote unauthenticated attacker to perform brute force attacks on GUI endpoints via taking advantage of outdated hashing methods. | |||||
CVE-2023-28509 | 2 Linux, Rocketsoftware | 3 Linux Kernel, Unidata, Universe | 2023-12-10 | N/A | 7.5 HIGH |
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 use weak encryption for packet-level security and passwords transferred on the wire. | |||||
CVE-2022-22313 | 1 Ibm | 1 Qradar Data Synchronization | 2023-12-10 | N/A | 7.5 HIGH |
IBM QRadar Data Synchronization App 1.0 through 3.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 217370. | |||||
CVE-2023-27557 | 1 Ibm | 1 Safer Payments | 2023-12-10 | N/A | 7.5 HIGH |
IBM Counter Fraud Management for Safer Payments 6.1.0.00 through 6.1.1.02, 6.2.0.00 through 6.2.2.02, 6.3.0.00 through 6.3.1.02, 6.4.0.00 through 6.4.2.01, and 6.5.0.00 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 249192. | |||||
CVE-2023-28006 | 1 Hcltech | 1 Bigfix Osd Bare Metal Server | 2023-12-10 | N/A | 7.8 HIGH |
The OSD Bare Metal Server uses a cryptographic algorithm that is no longer considered sufficiently secure. | |||||
CVE-2023-26276 | 2 Ibm, Linux | 2 Qradar Security Information And Event Manager, Linux Kernel | 2023-12-10 | N/A | 7.5 HIGH |
IBM QRadar SIEM 7.5.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 248147. | |||||
CVE-2023-28076 | 1 Dell | 1 Cloudlink | 2023-12-10 | N/A | 7.5 HIGH |
CloudLink 7.1.2 and all prior versions contain a broken or risky cryptographic algorithm vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability leading to some information disclosure. | |||||
CVE-2022-40722 | 1 Pingidentity | 3 Pingfederate, Pingid Adapter For Pingfederate, Pingid Integration Kit | 2023-12-10 | N/A | 5.8 MEDIUM |
A misconfiguration of RSA padding implemented in the PingID Adapter for PingFederate to support Offline MFA with PingID mobile authenticators is vulnerable to pre-computed dictionary attacks, leading to a bypass of offline MFA. | |||||
CVE-2023-22812 | 1 Westerndigital | 1 Sandisk Privateaccess | 2023-12-10 | N/A | 7.4 HIGH |
SanDisk PrivateAccess versions prior to 6.4.9 support insecure TLS 1.0 and TLS 1.1 protocols which are susceptible to man-in-the-middle attacks thereby compromising confidentiality and integrity of data. | |||||
CVE-2023-35890 | 1 Ibm | 1 Websphere Application Server | 2023-12-10 | N/A | 5.5 MEDIUM |
IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security, caused by the improper encoding in a local configuration file. IBM X-Force ID: 258637. | |||||
CVE-2022-45170 | 1 Liveboxcloud | 1 Vdesk | 2023-12-10 | N/A | 6.5 MEDIUM |
An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Cryptographic Issue can occur under the /api/v1/vencrypt/decrypt/file endpoint. A malicious user, logged into a victim's account, is able to decipher a file without knowing the key set by the user. | |||||
CVE-2023-21115 | 1 Google | 1 Android | 2023-12-10 | N/A | 8.8 HIGH |
In btm_sec_encrypt_change of btm_sec.cc, there is a possible way to downgrade the link key type due to improperly used crypto. This could lead to paired device escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12LAndroid ID: A-258834033 | |||||
CVE-2023-28043 | 1 Dell | 1 Secure Connect Gateway | 2023-12-10 | N/A | 6.5 MEDIUM |
Dell SCG 5.14 contains an information disclosure vulnerability during the SRS to SCG upgrade path. A remote low privileged malicious user could potentially exploit this vulnerability to retrieve the plain text. |