CVEbaza.plSłownik CWECWE-757
Common Weakness Enumeration

CWE-757

Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')

Kategoria: BaseCVE: 35
Opis

Protokół lub jego implementacja umożliwia interakcję między wieloma stronami i pozwala im negocjować, który algorytm powinien być używany jako mechanizm ochrony, taki jak szyfrowanie lub uwierzytelnianie, ale nie wybiera najsilniejszego dostępnego algorytmu dla obu stron. W wyniku tego możliwe jest wymuszenie użycia słabszego algorytmu, co obniża poziom bezpieczeństwa komunikacji.

Description (EN)

A protocol or its implementation supports interaction between multiple actors and allows those actors to negotiate which algorithm should be used as a protection mechanism such as encryption or authentication, but it does not select the strongest algorithm that is available to both parties.

Podatności CVE z CWE-757 (35)
9.8
CVSS
CRITICAL
CVE-2026-72889

Net::OAuth versions before 0.33 for Perl allow the sender to choose the signature algorithm in verify. verify resolves the signature method class from the signature_method parameter of the incoming message. signature_method is required on every request, so the algorithm used to check a signature is chosen by whoever sent it, and nothing lets the verifying party pin the method instead. When a message names HMAC-SHA1 or HMAC-SHA256, the key is derived from consumer_secret and token_secret rather than from the key the provider deployed. A provider deployed on RSA-SHA1 holds only the consumer public key, and RFC 5849 does not use consumer_secret for that method, so the required parameter is filled with a placeholder. A client that names HMAC-SHA1 instead has its signature checked against that placeholder, so a guessable one is enough to forge requests for any consumer key and token.

pub. 2026-08-19
9.8
CVSS
CRITICAL
CVE-2026-72887

Net::OAuth::Client versions before 0.32 for Perl allow the service provider to silently downgrade OAuth 1.0a to OAuth 1.0 in get_request_token. Passing a callback to the constructor selects OAuth 1.0a. get_request_token then revokes that choice when the request token response omits oauth_callback_confirmed, with no exception, no warning and no option to require 1.0a. The access token request is built from the OAuth 1.0 message class, which has no verifier parameter, so oauth_verifier is dropped from the request even when get_access_token was passed one. oauth_verifier is the binding that OAuth 1.0a added between the authorization step and the token exchange. An application that asked for 1.0a and gets 1.0 is open to OAuth 1.0 session fixation, where an attacker obtains a request token, has the victim authorize it, and then completes the exchange themselves, linking the victim's provider account to a session the attacker controls. No attacker action sets up the downgrade: a provider that does not confirm the callback is enough.

pub. 2026-08-16
9.1
CVSS
CRITICAL
CVE-2026-55953

The Erlang/OTP ssl TLS 1.2 (and earlier) and DTLS client does not verify that the cipher suite selected by the server in ServerHello was among the suites offered by the client in ClientHello. The client-side tls_handshake:hello/5 handler validates the negotiated protocol version and the downgrade sentinel but hands the server-chosen suite directly to ssl_handshake:handle_server_hello_extensions/9, which installs it without a membership check. The TLS 1.3 client path performs this check (per RFC 8446), so it is not affected. An on-path attacker between the client and the intended server can respond with a ServerHello selecting an anonymous key exchange suite such as TLS_DH_anon_* or TLS_ECDH_anon_* that the client never offered. Anonymous suites do not require the server to present a certificate, so the entire verify_peer and cacerts configuration is bypassed: the attacker completes the handshake with its own ephemeral parameters, no certificate is validated, no hostname is checked, and ssl:connect returns {ok, Socket}. All subsequent application traffic is readable and modifiable by the attacker. This issue affects OTP from OTP 17.0 before OTP 27.3.4.15, from OTP 28.0 before OTP 28.5.0.4, and from OTP 29.0 before OTP 29.0.4, corresponding to ssl from 5.3.4 before 11.2.12.11, from 11.3 before 11.6.0.4, and from 11.7 before 11.7.4. Whether OTP before OTP 17.0, corresponding to ssl before 5.3.4, is affected is unknown.

pub. 2026-07-27
9.1
CVSS
CRITICAL
CVE-2025-24154

Podatność typu out-of-bounds write w systemach Apple iOS, iPadOS oraz macOS umożliwia atakującemu zdalnie wywołanie nieoczekiwanego zakończenia systemu lub uszkodzenie pamięci jądra (kernel memory). Wysoki wynik CVSS 9.1 oraz brak wymagań dotyczących uwierzytelnienia czynią ją szczególnie niebezpieczną.

pub. 2025-01-27
9.1
CVSS
CRITICAL
CVE-2024-4995

Wapro ERP Desktop jest podatny na wymuszony downgrade protokołu MS SQL przez serwer, co skutkuje przesyłaniem danych w formie niezaszyfrowanej. Umożliwia to przechwycenie i modyfikację wrażliwych danych biznesowych przez atakującego.

pub. 2024-12-18
9.1
CVSS
CRITICAL
CVE-2024-38883

Podatność w oprogramowaniu Horizon Business Services Inc. Caterease umożliwia zdalnemu atakującemu przeprowadzenie ataku typu Drop Encryption Level, polegającego na wymuszeniu negocjacji słabszego algorytmu kryptograficznego. Zagrożenie jest krytyczne, ponieważ nie wymaga uwierzytelnienia ani interakcji użytkownika, a może prowadzić do ujawnienia i modyfikacji przesyłanych danych.

pub. 2024-08-02
9.1
CVSS
CRITICAL
CVE-2019-14887

W serwerze aplikacyjnym Wildfly, przy użyciu dostawcy zabezpieczeń OpenSSL, konfiguracja 'enabled-protocols' nie jest respektowana. Atakujący może wymusić obniżenie połączenia do słabszej wersji TLS, potencjalnie naruszając poufność przesyłanych danych.

pub. 2020-03-16
9.0
CVSS
CRITICAL
CVE-2026-18691

An issue in MongoDB Server's intra-cluster connection setup could allow a party with suitable network access to influence which authentication mechanism is used when one replica set member connects to another. Under certain conditions, this could cause the cluster's shared internal credential to be transmitted in a less-protected form, potentially allowing that credential to be recovered. If recovered, the credential could be used to authenticate as the internal superuser to nodes in the deployment.

pub. 2026-08-11
8.3
CVSS
HIGH
CVE-2024-8773

SIMPLE.ERP client is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unencrypted communication vulnerable to data interception and modification. This issue affect SIMPLE.ERP from 6.20 to 6.30. Only the 6.30 version received a patch 6.30@a03.9, which make it possible for an administrator to enforce encrypted communication. Versions 6.20 and 6.25 remain unpatched.

pub. 2025-03-24
8.2
CVSS
HIGH
CVE-2026-53712

Podatność w bibliotece Java com.ongres.scram (wersje przed 3.3) umożliwia atakującemu przeprowadzającemu atak TLS man-in-the-middle ciche obniżenie poziomu uwierzytelniania z SCRAM-SHA-256-PLUS (z channel binding) do SCRAM-SHA-256 (bez channel binding). Jest to groźne, ponieważ eliminuje ochronę przed przechwyceniem sesji uwierzytelnienia bez wiedzy klienta ani serwera.

pub. 2026-07-17
8.2
CVSS
HIGH
CVE-2026-54291

Podatność w sterowniku pgjdbc umożliwia ciche obniżenie poziomu uwierzytelnienia z SCRAM-SHA-256-PLUS (z channel binding) do zwykłego SCRAM-SHA-256, mimo że połączenie jest skonfigurowane z opcją channelBinding=require. Atakujący zdolny do przechwycenia połączenia TLS może w ten sposób pozbawić je ochrony przed atakami man-in-the-middle.

pub. 2026-07-06
8.1
CVSS
HIGH
CVE-2018-25029

The Z-Wave specification requires that S2 security can be downgraded to S0 or other less secure protocols, allowing an attacker within radio range during pairing to downgrade and then exploit a different vulnerability (CVE-2013-20003) to intercept and spoof traffic.

pub. 2022-02-04
7.7
CVSS
HIGH
CVE-2017-9269

In libzypp before August 2018 GPG keys attached to YUM repositories were not correctly pinned, allowing malicious repository mirrors to silently downgrade to unsigned repositories with potential malicious content.

pub. 2018-03-01
7.6
CVSS
HIGH
CVE-2025-10693

When SmartStart Inclusion fails during the onboarding of a Z-Wave PIR sensor, the sensor will join the network as a non-secure device. This vulnerability exists in Silicon Labs' Z-Wave PIR Sensor Reference design delivered as part of SiSDK v2025.6.0 and v2025.6.1.

pub. 2025-10-31
7.5
CVSS
HIGH
CVE-2026-32650

Anviz CrossChex Standard is vulnerable when an attacker manipulates the TDS7 PreLogin to disable encryption, causing database credentials to be sent in plaintext and enabling unauthorized database access.

pub. 2026-04-17
7.5
CVSS
HIGH
CVE-2024-23656

Dex is an identity service that uses OpenID Connect to drive authentication for other apps. Dex 2.37.0 serves HTTPS with insecure TLS 1.0 and TLS 1.1. `cmd/dex/serve.go` line 425 seemingly sets TLS 1.2 as minimum version, but the whole `tlsConfig` is ignored after `TLS cert reloader` was introduced in v2.37.0. Configured cipher suites are not respected either. This issue is fixed in Dex 2.38.0.

pub. 2024-01-25
7.3
CVSS
HIGH
CVE-2022-23000

The Western Digital My Cloud Web App [https://os5.mycloud.com/] uses a weak SSLContext when attempting to configure port forwarding rules. This was enabled to maintain compatibility with old or outdated home routers. By using an "SSL" context instead of "TLS" or specifying stronger validation, deprecated or insecure protocols are permitted. As a result, a local user with no privileges can exploit this vulnerability and jeopardize the integrity, confidentiality and authenticity of information transmitted. The scope of impact cannot extend to other components and no user input is required to exploit this vulnerability.

pub. 2022-07-25
6.9
CVSS
MEDIUM
CVE-2019-16791

In postfix-mta-sts-resolver before 0.5.1, All users can receive incorrect response from daemon under rare conditions, rendering downgrade of effective STS policy.

pub. 2020-01-22
6.6
CVSS
MEDIUM
CVE-2026-59293

Unless the application explicitly raises smbMinVersion, the jCIFS client will negotiate down to SMB1/CIFS, which lacks mandatory signing/encryption and is vulnerable to NTLM relay and content-tampering MITM. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12

pub. 2026-08-27
6.5
CVSS
MEDIUM
CVE-2026-2673

Serwer OpenSSL TLS 1.3 może nie wynegocjować oczekiwaną preferowaną grupę wymiany kluczy, gdy jego konfiguracja grupy wymiany kluczy zawiera domyślną grupę za pomocą słowa kluczowego 'DEFAULT'. W wyniku tego może dojść do użycia mniej preferowanej grupy wymiany kluczy, nawet jeśli bardziej preferowana grupa jest obsługiwana przez klienta i serwer, jeśli grupa nie była uwzględniona w początkowych przewidywanych keyshares klienta. Problem polega na utracie przez listę 'DEFAULT' struktury 'tuple', co powoduje, że serwer nie wysyła Hello Retry Request (HRR) nawet gdy bardziej preferowana grupa wymiany jest wspólnie obsługiwana, uniemożliwiając wynegocjowanie grup post-kwantowych takich jak 'X25519MLKEM768'.

pub. 2026-03-13
Pokazano 20 z 35 podatności
Informacje
ID: CWE-757
Typ: Base
Podatności: 35
MITRE CWE ↗
← Słownik CWE