CVEbaza.plSłownik CWECWE-320
Common Weakness Enumeration

CWE-320

CVE: 93
Podatności CVE z CWE-320 (93)
9.8
CVSS
CRITICAL
CVE-2016-10421

Podatność w oprogramowaniu układowym chipsetów Qualcomm Snapdragon Mobile i Snapdragon Wear powoduje, że materiał kryptograficzny (klucze) nie jest zawsze prawidłowo usuwany z pamięci. Stwarza to poważne ryzyko ujawnienia wrażliwych danych kryptograficznych atakującemu.

pub. 2018-04-18
9.8
CVSS
CRITICAL
CVE-2016-10467

Podatność w oprogramowaniu układowym Qualcomm Snapdragon polega na błędnym założeniu dotyczącym rozmiaru zakodowanej wiadomości RSA podczas weryfikacji dopełnienia PKCS#1 PSS. Błąd może prowadzić do naruszenia poufności, integralności i dostępności systemu.

pub. 2018-04-18
9.8
CVSS
CRITICAL
CVE-2018-0124

Podatność w Cisco Unified Communications Domain Manager umożliwia nieuwierzytelnionemu atakującemu zdalne ominięcie zabezpieczeń i wykonanie dowolnego kodu. Krytyczny poziom zagrożenia wynika z braku wymogu jakiegokolwiek uwierzytelnienia do przeprowadzenia ataku.

pub. 2018-02-22
9.8
CVSS
CRITICAL
CVE-2015-0936

Urządzenia Ceragon FibeAir IP-10 zawierają wbudowany domyślny publiczny klucz SSH w pliku authorized_keys użytkownika mateidu. Atakujący posiadający odpowiadający klucz prywatny może uzyskać nieautoryzowany dostęp SSH do urządzenia bez żadnego uwierzytelnienia własnego.

pub. 2017-06-01
9.8
CVSS
CRITICAL
CVE-2015-4166

Cloudera Key Trustee Server w wersjach przed 5.4.3 nie przechowuje kluczy szyfrowania w sposób synchroniczny, co może prowadzić do ich utraty. Utrata klucza szyfrowania może skutkować całkowitą niedostępnością zaszyfrowanych danych lub naruszeniem ich integralności.

pub. 2017-03-23
9.1
CVSS
CRITICAL
CVE-2024-36391

Podatność w Milesight DeviceHub wynika z nieprawidłowego zarządzania kluczami kryptograficznymi (CWE-320), co może pozwolić atakującemu na ominięcie uwierzytelnienia oraz przeprowadzenie ataku Man-In-The-Middle. Ocena CVSS 9.1 wskazuje na krytyczny charakter zagrożenia, możliwy do wykorzystania zdalnie bez żadnych uprawnień.

pub. 2024-06-02
9.1
CVSS
CRITICAL
CVE-2019-5672

Urządzenia NVIDIA Jetson TX1 i TX2 z systemem Linux for Tegra (L4T) przed wersją R28.3 zawierają preinstalowane, przykładowe klucze SSH, które nie są zastępowane unikalnymi kluczami po wygenerowaniu i wgraniu rootfs. Oznacza to, że wszystkie dotknięte urządzenia mogą posiadać identyczne klucze hosta SSH, co umożliwia atakującemu przeprowadzenie ataku man-in-the-middle lub uzyskanie nieautoryzowanego dostępu.

pub. 2019-04-11
8.8
CVSS
HIGH
CVE-2015-8542

An issue was discovered in Open-Xchange Guard before 2.2.0-rev8. The "getprivkeybyid" API call is used to download a PGP Private Key for a specific user after providing authentication credentials. Clients provide the "id" and "cid" parameter to specify the current user by its user- and context-ID. The "auth" parameter contains a hashed password string which gets created by the client by asking the user to enter his or her OX Guard password. This parameter is used as single point of authentication when accessing PGP Private Keys. In case a user has set the same password as another user, it is possible to download another user's PGP Private Key by iterating the "id" and "cid" parameters. This kind of attack would also be able by brute-forcing login credentials, but since the "id" and "cid" parameters are sequential they are much easier to predict than a user's login name. At the same time, there are some obvious insecure standard passwords that are widely used. A attacker could send the hashed representation of typically weak passwords and randomly fetch Private Key of matching accounts. The attack can be executed by both internal users and "guests" which use the external mail reader.

pub. 2016-12-15
8.3
CVSS
HIGH
CVE-2026-56254

W bibliotece @capgo/capacitor-updater przed wersją 12.128.2 schemat szyfrowania end-to-end dystrybuuje klucz prywatny do każdego urządzenia pobierającego aplikację, co całkowicie podważa bezpieczeństwo mechanizmu weryfikacji aktualizacji. Atakujący może podpisać fałszywą paczkę aktualizacji i skłonić urządzenia do jej instalacji.

pub. 2026-07-10
8.1
CVSS
HIGH
CVE-2015-0839

The hp-plugin utility in HP Linux Imaging and Printing (HPLIP) makes it easier for man-in-the-middle attackers to execute arbitrary code by leveraging use of a short GPG key id from a keyserver to verify print plugin downloads.

pub. 2017-08-02
7.8
CVSS
HIGH
CVE-2016-2880

IBM QRadar 7.2 stores the encryption key used to encrypt the service account password which can be obtained by a local user. IBM Reference #: 1997340.

pub. 2017-03-01
7.7
CVSS
HIGH
CVE-2023-21652

Cryptographic issue in HLOS as derived keys used to encrypt/decrypt information is present on stack after use.

pub. 2023-08-08
7.5
CVSS
HIGH
CVE-2021-26322

Persistent platform private key may not be protected with a random IV leading to a potential “two time pad attack”.

pub. 2021-11-16
7.5
CVSS
HIGH
CVE-2019-9894

A remotely triggerable memory overwrite in RSA key exchange in PuTTY before 0.71 can occur before host key verification.

pub. 2019-03-21
7.5
CVSS
HIGH
CVE-2017-13887

In macOS High Sierra before 10.13.2, a logic issue existed in APFS when deleting keys during hibernation. This was addressed with improved state management.

pub. 2019-01-11
7.5
CVSS
HIGH
CVE-2018-0732

During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server can send a very large prime value to the client. This will cause the client to spend an unreasonably long period of time generating a key for this prime resulting in a hang until the client has finished. This could be exploited in a Denial Of Service attack. Fixed in OpenSSL 1.1.0i-dev (Affected 1.1.0-1.1.0h). Fixed in OpenSSL 1.0.2p-dev (Affected 1.0.2-1.0.2o).

pub. 2018-06-12
7.5
CVSS
HIGH
CVE-2015-0153

D-Link DIR-815 devices with firmware before 2.07.B01 allow remote attackers to obtain sensitive information by leveraging cleartext storage of the wireless key.

pub. 2018-04-12
7.5
CVSS
HIGH
CVE-2018-9234

GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently valid certifications that occurred only with access to a signing subkey.

pub. 2018-04-04
7.5
CVSS
HIGH
CVE-2015-7503

Zend Framework before 2.4.9, zend-framework/zend-crypt 2.4.x before 2.4.9, and 2.5.x before 2.5.2 allows remote attackers to recover the RSA private key.

pub. 2017-10-10
7.5
CVSS
HIGH
CVE-2016-6879

The X509_Certificate::allowed_usage function in botan 1.11.x before 1.11.31 might allow attackers to have unspecified impact by leveraging a call with more than one Key_Usage set in the enum value.

pub. 2017-04-10
Pokazano 20 z 93 podatności
Informacje
ID: CWE-320
Podatności: 93
MITRE CWE ↗
← Słownik CWE