Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati
The Semtech LR11xx LoRa transceivers implement secure boot functionality using digital signatures to authenticate firmwa
Insecure generation of credentials in the local SAT (Technical Support) access functionality of the Ingecon Sun EMS Boar
LibJWT is a C JSON Web Token Library. From 3.0.0 to 3.3.2, libjwt accepts an RSA JWK that does not contain an alg parame
Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.23 and 3.0.6,
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, the `hmacBase64()` functio
Padding oracle attack vulnerability in Oberon microsystem AG’s ocrypto library in all versions since 3.0.0 and prior to
Padding oracle attack vulnerability in Oberon microsystem AG’s Oberon PSA Crypto library in all versions since 1.0.0 and
Cwe-327 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Johnson Controls TL280 allows Cryptanalytic At
Due to reliance on a trivial substitution cipher, sent in cleartext, and the reliance on a default password when the use
Brocade SANnav OVA before SANnav 2.3.1b enables SHA1 deprecated setting for SSH for port 22.
An unauthenticated remote attacker could exploit the used, insecure TLS 1.0 and TLS 1.1 protocols to intercept and manip
A cryptanalytic break in Altcha Proof-of-Work obfuscation mode version 0.8.0 and later allows for remote visitors to rec
Inside Track / Entropy Derby is a research-grade horse-racing betting engine. Prior to commit 2d38d2f, the VDF-based tim
CyberGhostVPNSetup.exe (Windows installer) is signed using the weak cryptographic hash algorithm SHA-1, which is vulnera
The vulnerability, if exploited, could allow a miscreant with read access to Edge Project files or Edge Offline Cache f
The use of a broken or risky cryptographic algorithm was discovered in firmware version 3.60 of the Click Plus PLC. The
Use of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.67.2 allows local attackers to rep
During the initial setup of the device the user connects to an access point broadcast by the Sight Bulb Pro. During the
A “Use of a Broken or Risky Cryptographic Algorithm” vulnerability in the SSL/TLS component used in B&R Automation Runti
ECOVACS robot lawnmowers and vacuums use a deterministic symmetric key to decrypt firmware updates. An attacker can crea
An issue was discovered in AudioCodes Mediant Session Border Controller (SBC) before 7.40A.501.841. Due to the use of we
Emissary is a P2P based data-driven workflow engine. The ChecksumCalculator class within allows for hashing and checksum
The File Away plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the
A vulnerability has been identified in SIRIUS 3RK3 Modular Safety System (MSS) (All versions), SIRIUS Safety Relays 3SK2
Vulnerability in the cryptographic algorithm of AndSoft's e-TMS v25.03, which uses MD5 to encrypt passwords. MD5 is a cr
Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA/SaaS deployments) store user passwords u
Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an insecure hashing algorithm vulnerability. The product
The application uses an insecure hashing algorithm (MD5) to hash passwords. If an attacker obtained a copy of these hash
Weak Encryption Algorithm in StreamPark, The use of an AES cipher in ECB mode and a weak random number generator for enc
A cryptography vulnerability in Kentico Xperience allows attackers to potentially manipulate URL hash values through exi
Out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 (and potentially earlier unsupported versions) that are configu
Flock Safety Bravo Edge AI Compute Device BRAVO_00.00_local_20241017 ships with Secure Boot disabled. This allows an att
A vulnerability in the cryptographic logic used by HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authe
A vulnerability has been identified in RUGGEDCOM i800 (All versions), RUGGEDCOM i801 (All versions), RUGGEDCOM i802 (All
jose v6.0.10 was discovered to contain weak encryption. NOTE: this is disputed by a third party because the claim of "do
poco v1.14.1-release was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key
Missing Cryptographic Step vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise
A flaw has been found in Linksys E5600 1.1.0.26. The affected element is the function verify_gemtek_header of the file c
HCL SX v21 is affected by usage of a weak cryptographic algorithm. An attacker could exploit this weakness to gain acce
A service supports the use of a deprecated and unsafe TLS version. This could be exploited to expose sensitive informati
The VNC authentication mechanism bases on a challenge-response system where both server and client use the same password
DuckDB is a SQL database management system. DuckDB implemented block-based encryption of DB on the filesystem starting w
A vulnerability in the SSH server of TP-Link TL-WR820N v2.80 allows the use of a weak cryptographic algorithm, enabling
A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Au
In illumos illumos-gate 2024-02-15, an error occurs in the elliptic curve point addition algorithm that uses mixed Jacob
Broken or Risky Cryptographic Algorithm, Use of Password Hash With Insufficient Computational Effort, Use of Weak Hash,
IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 uses weaker than expected cryptographic algorithms
IBM Concert Software 1.0.0, 1.0.1, 1.0.2, 1.0.2.1, and 1.0.3 could allow a remote attacker to obtain sensitive informati
IBM Robotic Process Automation 21.0.0 through 21.0.7.19 and 23.0.0 through 23.0.19 could allow a remote attacker to obta
Frequently Asked Questions
What is CWE-327?
CWE-327 (CWE-327) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-327?
There are 799 CVE records associated with CWE-327 in our database. Of these, 60 are critical severity, 251 are high severity, and 293 are medium severity.
How can I protect against CWE-327 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-327 using AI-powered security agents.
Detect CWE-327 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-327 vulnerabilities across your infrastructure.
Get Started