CVEbaza.plSłownik CWECWE-1240
Common Weakness Enumeration

CWE-1240

Use of a Cryptographic Primitive with a Risky Implementation

Kategoria: BaseCVE: 22
Opis

Produkt implementuje algorytm kryptograficzny przy użyciu niestandardowej, niedowodzonej lub niedozwolonej/niezgodnej implementacji kryptograficznej w celu spełnienia potrzeby prymitywu kryptograficznego. Takie podejście narażać może system na luki bezpieczeństwa i kompromitację danych.

Description (EN)

To fulfill the need for a cryptographic primitive, the product implements a cryptographic algorithm using a non-standard, unproven, or disallowed/non-compliant cryptographic implementation.

Podatności CVE z CWE-1240 (22)
9.8
CVSS
CRITICAL
CVE-2024-0323

Serwer FTP wbudowany w B&R Automation Runtime obsługuje przestarzałe i niezabezpieczone mechanizmy szyfrowania (SSLv3, TLSv1.0, TLSv1.1). Atakujący w sieci może wykorzystać tę podatność do przechwytywania i odszyfrowywania komunikacji lub przeprowadzenia ataku man-in-the-middle.

pub. 2024-02-05
8.9
CVSS
HIGH
CVE-2026-46654

Plonky3 is a toolkit for polynomial IOPs (PIOPs). Prior to versions 0.4.3 and 0.5.3, an attacker controlling prover-side observations can craft distinct transcripts that produce identical challenges, breaking the binding property of Fiat-Shamir. This issue has been patched in versions 0.4.3 and 0.5.3.

pub. 2026-06-10
8.6
CVSS
HIGH
CVE-2025-24802

Plonky2 is a SNARK implementation based on techniques from PLONK and FRI. Lookup tables, whose length is not divisible by 26 = floor(num_routed_wires / 3) always include the 0 -> 0 input-output pair. Thus a malicious prover can always prove that f(0) = 0 for any lookup table f (unless its length happens to be divisible by 26). The cause of problem is that the LookupTableGate-s are padded with zeros. A workaround from the user side is to extend the table (by repeating some entries) so that its length becomes divisible by 26. This vulnerability is fixed in 1.0.1.

pub. 2025-01-30
8.3
CVSS
HIGH
CVE-2025-62514

Parsec is a cloud-based application for cryptographically secure file sharing. In versions on the 3.x branch prior to 3.6.0, `libparsec_crypto`, a component of the Parsec application, does not check for weak order point of Curve25519 when compiled with its RustCrypto backend. In practice this means an attacker in a man-in-the-middle position would be able to provide weak order points to both parties in the Diffie-Hellman exchange, resulting in a high probability to for both parties to obtain the same shared key (hence leading to a successful SAS code exchange, misleading both parties into thinking no MITM has occurred) which is also known by the attacker. Note only Parsec web is impacted (as Parsec desktop uses `libparsec_crypto` with the libsodium backend). Version 3.6.0 of Parsec patches the issue.

pub. 2026-01-29
8.3
CVSS
HIGH
CVE-2024-0220

B&R Automation Studio Upgrade Service and B&R Technology Guarding use insufficient cryptography for communication to the upgrade and the licensing servers. A network-based attacker could exploit the vulnerability to execute arbitrary code on the products or sniff sensitive data.

pub. 2024-02-22
7.8
CVSS
HIGH
CVE-2025-58720

Use of a cryptographic primitive with a risky implementation in Windows Cryptographic Services allows an authorized attacker to disclose information locally.

pub. 2025-10-14
7.5
CVSS
HIGH
CVE-2026-29146

Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Users are recommended to upgrade to version 11.0.19, 10.1.53 and 9.0.116, which fixes the issue.

pub. 2026-04-09
7.4
CVSS
HIGH
CVE-2026-21751

HCL Hive is affected by a cryptographic primitive with a risky implementation which could allow an attacker unauthorized lateral compromise or widespread credential leakage if a single internal component is breached.

pub. 2026-08-24
6.7
CVSS
MEDIUM
CVE-2025-46424

Dell CloudLink, versions prior to 8.2, contain use of a Cryptographic Primitive with a Risky Implementation vulnerability. A high privileged attacker could potentially exploit this vulnerability leading to Denial of service.

pub. 2025-11-05
6.4
CVSS
MEDIUM
CVE-2026-22705

RustCrypto: Signatures zapewnia obsługę podpisów cyfrowych, które uwierzytelniają dane przy użyciu kryptografii klucza publicznego. Przed wersją 0.1.0-rc.2 wykryto timing side-channel w algorytmie Decompose, który jest wykorzystywany podczas podpisywania ML-DSA do generowania podpowiedzi dla podpisu. Problem został naprawiony w wersji 0.1.0-rc.2.

pub. 2026-01-10
6.2
CVSS
MEDIUM
CVE-2023-51392

Ember ZNet between v7.2.0 and v7.4.0 used software AES-CCM instead of integrated hardware cryptographic accelerators, potentially increasing risk of electromagnetic and differential power analysis sidechannel attacks.

pub. 2024-02-23
5.9
CVSS
MEDIUM
CVE-2025-64647

IBM Concert w wersjach od 1.0.0 do 2.2.0 wykorzystuje słabsze niż oczekiwane algorytmy kryptograficzne, co może pozwolić atakującemu na odszyfrowanie wysoko wrażliwych informacji.

pub. 2026-03-25
5.9
CVSS
MEDIUM
CVE-2025-53960

Podczas wydawania JSON Web Tokens (JWT), Apache StreamPark bezpośrednio używa hasła użytkownika jako klucza HMAC do podpisania tokena (np. z algorytmem HS256). Atakujący może wykorzystać tę lukę do przeprowadzenia offline'owego ataku brute-force na hasło użytkownika przy użyciu przechwyconego JWT, lub do dowolnego sfałszowania tokenów tożsamości użytkownika, jeśli hasło jest już znane, co ostatecznie prowadzi do pełnego przejęcia konta. Problem dotyczy Apache StreamPark: od wersji 2.0.0 do wersji 2.1.6 włącznie. Użytkownikom zaleca się aktualizację do wersji 2.1.7, która usuwa tę lukę.

pub. 2025-12-12
5.6
CVSS
MEDIUM
CVE-2025-14505

Implementacja ECDSA w pakiecie Elliptic generuje nieprawidłowe podpisy, jeśli wartość tymczasowa 'k' (obliczona zgodnie z krokiem 3.2 RFC 6979) zawiera wiodące zera i jest podatna na kryptoanalizę, co może prowadzić do ujawnienia klucza tajnego. Problem wynika z niepoprawnego obliczenia długości bajtu 'k', co powoduje jego obcięcie podczas obliczeń. Wskutek tego legitymarne transakcje lub komunikacja zostaną przerwane. Ponadto, ze względu na naturę tej wady, atakujący mogą – w pewnych warunkach – wyprowadzić klucz tajny, jeśli uzyskają dostęp zarówno do błędnego podpisu wygenerowanego przez podatną wersję Elliptic, jak i prawidłowego podpisu dla tych samych danych wejściowych. Problem dotyczy wszystkich znanych wersji Elliptic (w momencie pisania wersje 6.6.1 i starsze).

pub. 2026-01-08
5.5
CVSS
MEDIUM
CVE-2026-50303

Stosowanie prymitywu kryptograficznego z ryzykowną implementacją w Windows Key Guard umożliwia autoryzowanemu atakującemu obejście lokalnie funkcji bezpieczeństwa.

pub. 2026-07-14
5.5
CVSS
MEDIUM
CVE-2025-29808

Use of a cryptographic primitive with a risky implementation in Windows Cryptographic Services allows an authorized attacker to disclose information locally.

pub. 2025-04-08
5.4
CVSS
MEDIUM
CVE-2025-29779

Post-Quantum Secure Feldman's Verifiable Secret Sharing provides a Python implementation of Feldman's Verifiable Secret Sharing (VSS) scheme. In versions 0.8.0b2 and prior, the `secure_redundant_execution` function in feldman_vss.py attempts to mitigate fault injection attacks by executing a function multiple times and comparing results. However, several critical weaknesses exist. Python's execution environment cannot guarantee true isolation between redundant executions, the constant-time comparison implementation in Python is subject to timing variations, the randomized execution order and timing provide insufficient protection against sophisticated fault attacks, and the error handling may leak timing information about partial execution results. These limitations make the protection ineffective against targeted fault injection attacks, especially from attackers with physical access to the hardware. A successful fault injection attack could allow an attacker to bypass the redundancy check mechanisms, extract secret polynomial coefficients during share generation or verification, force the acceptance of invalid shares during verification, and/or manipulate the commitment verification process to accept fraudulent commitments. This undermines the core security guarantees of the Verifiable Secret Sharing scheme. As of time of publication, no patched versions of Post-Quantum Secure Feldman's Verifiable Secret Sharing exist, but other mitigations are available. Long-term remediation requires reimplementing the security-critical functions in a lower-level language like Rust. Short-term mitigations include deploying the software in environments with physical security controls, increasing the redundancy count (from 5 to a higher number) by modifying the source code, adding external verification of cryptographic operations when possible, considering using hardware security modules (HSMs) for key operations.

pub. 2025-03-14
5.3
CVSS
MEDIUM
CVE-2025-68833

HCL Hive Keycloak IAM Instance is affected by insufficient granularity of access control which could allow an attacker unauthorized access to resources.

pub. 2026-08-24
3.8
CVSS
LOW
CVE-2026-44410

Podatność wynika z błędu w logice biznesowej aplikacji. Atakujący mogą wykorzystać legalne funkcje aplikacji w niezamierzony i anomalny sposób, odchodzący od intencji projektanta, aby przeprowadzić złośliwe ataki.

pub. 2026-05-26
3.8
CVSS
LOW
CVE-2024-37137

Dell Key Trust Platform w wersji 3.0.6 i starszych zawiera vulnerability Use of a Cryptographic Primitive with a Risky Implementation. Lokalny atakujący z podwyższonymi uprawnieniami może potencjalnie wykorzystać tę lukę, prowadząc do ujawnienia poufnych informacji.

pub. 2024-06-28
Pokazano 20 z 22 podatności
Informacje
ID: CWE-1240
Typ: Base
Podatności: 22
MITRE CWE ↗
← Słownik CWE