Cryptographic Flaw in Enterprise in Google Chrome prior to 151.0.7922.72 allowed an attacker in a privileged network pos
Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.sig
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Before 2.6.0, node:crypto doesn't finalize cipher. The vulner
Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a library-level vulne
Versions of the package sjcl before 1.0.9 are vulnerable to Improper Verification of Cryptographic Signature due to miss
OpenClaw before 2026.3.28 contains a webhook replay vulnerability in Plivo V3 signature verification that canonicalizes
Issue summary: When an application drives an AES-OCB context through the public EVP_Cipher() one-shot interface, the app
Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.3.10, 0.4
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, node:crypto.checkPrime(candidate[, options][,
Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-
Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.
Missing cryptographic step in Windows CryptoAPI allows an authorized attacker to perform tampering locally.
Missing Cryptographic Step (CWE-325) vulnerability exists in certain FeliCa IC chips shipped in or before 2017. If the v
Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.
EAZ EazyFix 12.9 allows a Security Feature Bypass related to a "Missing Cryptographic Step" associated with "Secure Boot
An improper implementation of TLS certificate validation vulnerability found in NETGEAR's ReadyCloud client app which co
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to forge a GINA-encrypted email.
Issue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) mishandle the authentication of AAD
Issue summary: When using the low-level OCB API directly with AES-NI or<br>other hardware-accelerated code paths, inputs
Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the peer key is not properly check
The netty incubator codec.bhttp is a java language binary http parser. Prior to version 0.0.22.FInal, the codec-ohttp im
A Missing Required Cryptographic Step vulnerability has been identified in Moxa's embedded Linux firmware for industrial
Missing cryptographic step in Caliptra Core Firmware (aes_256_gcm_update module) results in an incorrect GCM authenticat
Multiple TP-Link Kasa smart home devices contain insufficient cryptographic protections in the local device communicatio
Frequently Asked Questions
What is CWE-325?
CWE-325 (CWE-325) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-325?
There are 25 CVE records associated with CWE-325 in our database. Of these, 1 are critical severity, 11 are high severity, and 7 are medium severity.
How can I protect against CWE-325 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-325 using AI-powered security agents.
Detect CWE-325 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-325 vulnerabilities across your infrastructure.
Get Started