In Charm 0.43, any single user can decrypt DAC-MACS or MA-ABE-YJ14 data.
Snudown is a reddit-specific fork of the Sundown Markdown parser used by GitHub, with Python integration added. In affec
Assuming a database breach, nonce reuse issues in GitLab 11.6+ allows an attacker to decrypt some of the database's encr
Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in Microchip Libraries for Applications 2018-11-26 All up to 201
Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in STM32 cryptographic firmware library software expansion for S
IBM Security Verify Bridge uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt hi
In Charm 0.43, any two users can collude to achieve the ability to decrypt YCT14 data.
The ElGamal implementation in Libgcrypt before 1.9.4 allows plaintext recovery because, during interaction between two c
The ElGamal implementation in Botan through 2.18.1, as used in Thunderbird and other products, allows plaintext recovery
The ElGamal implementation in Crypto++ through 8.5 allows plaintext recovery because, during interaction between two cry
There is a weak secure algorithm vulnerability in Huawei products. A weak secure algorithm is used in a module. Attacker
The use of a broken or risky cryptographic algorithm is an unnecessary risk that may result in the exposure of sensitive
Functions SDK for EdgeX is meant to provide all the plumbing necessary for developers to get started in processing/trans
In crypt.c of remote-login-service, the cryptographic algorithm used to cache usernames and passwords is insecure. An at
A flaw was found in libtpms in versions before 0.8.2. The commonly used integration of libtpms with OpenSSL contained a
Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to retrieve passwords in cleartext due to a w
In JetBrains Ktor before 1.4.2, weak cipher suites were enabled by default.
In RELIC before 2020-08-01, RSA PKCS#1 v1.5 signature forgery can occur because certain checks of the padding (and of th
iDrive RemotePC before 7.6.48 on Windows allows information disclosure. A man in the middle can recover a system's Perso
In JetBrains TeamCity before 2021.1, an insecure key generation mechanism for encrypted properties was used.
An Information Exposure vulnerability in Juniper Networks SRC Series devices configured for NETCONF over SSH permits the
Laravel is a web application framework. Laravel prior to versions 8.75.0, 7.30.6, and 6.20.42 contain a possible cross-s
Weak encryption in the Quick Pairing mode in the eWeLink mobile application (Android application V4.9.2 and earlier, iOS
Archer before 6.8 P2 (6.8.0.2) is affected by a path exposure vulnerability. A remote authenticated malicious attacker w
ntpkeygen can generate keys that ntpd fails to parse. NTPsec 1.2.0 allows ntpkeygen to generate keys with '#' characters
"HCL Traveler Companion is vulnerable to an iOS weak cryptographic process vulnerability via the included MobileIron App
OpenSSL 1.0.2 supports SSLv2. If a client attempts to negotiate SSLv2 with a server that is configured to support both S
The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn
The function mt_rand is used to generate session tokens, this function is cryptographically flawed due to its nature bei
In the IPv4 implementation in the Linux kernel before 5.12.4, net/ipv4/route.c has an information leak because the hash
The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn
GigaVUE-OS (GVOS) 5.4 - 5.9 uses a weak algorithm for a hash stored in internal database.
IBM Security Verify Information Queue 1.0.6 and 1.0.7 uses weaker than expected cryptographic algorithms that could allo
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660
An issue was discovered on Samsung mobile devices with N(7.0), O(8.0) (exynos7420 or Exynos 8890/8996 chipsets) software
A weak encryption vulnerability in Mitel MiVoice Connect Client before 214.100.1214.0 could allow an unauthenticated att
Bond JetSelect (all versions) has an issue in the Java class (ENCtool.jar) and corresponding password generation algorit
Authenticated and encrypted payload MMEs can be forged and remotely sent to any HPAV2 system using a jailbreak key recov
Protocol encryption can be easily broken for CodeMeter (All versions prior to 6.90 are affected, including Version 6.90
A ZTE product is impacted by the cryptographic issues vulnerability. The encryption algorithm is not properly used, so r
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R670
In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.20, and greater than or equal to 10.0.0 and less than 10.4
Algorithm downgrade vulnerability in QuickConnect in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-
Algorithm downgrade vulnerability in QuickConnect in Synology Router Manager (SRM) before 1.2.4-8081 allows man-in-the-m
A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9
VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module allow weak hashing algorithm and insecure permissions wh
Wrong public key usage from existing oem_keystore for hash generation in Snapdragon Auto, Snapdragon Consumer IOT, Snapd
A CWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists in Easergy Builder (Version 1.4.7.2 and
u'Keymaster attestation key and device IDs provisioning which is a one time process is incorrectly allowed to be re-prov
In GLPI before version 9.5.0, the encryption algorithm used is insecure. The security of the data encrypted relies on th
Frequently Asked Questions
What is CWE-327?
CWE-327 (CWE-327) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-327?
There are 799 CVE records associated with CWE-327 in our database. Of these, 60 are critical severity, 251 are high severity, and 293 are medium severity.
How can I protect against CWE-327 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-327 using AI-powered security agents.
Detect CWE-327 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-327 vulnerabilities across your infrastructure.
Get Started