IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 uses weaker than expected cryptographic algorithms that
IBM Maximo Application Suite - Manage Component 8.10, 8.11, and 9.0 uses weaker than expected cryptographic algorithms t
IBM Concert Software 1.0.0 through 1.0.1 could allow a remote attacker to obtain sensitive information, caused by the fa
IBM Cognos Controller 11.0.0 and 11.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker
IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.2 could provide weaker than expected security for outbo
A flaw was found in GnuTLS. The Minerva attack is a cryptographic vulnerability that exploits deterministic behavior in
IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security for outbound TLS connections ca
Use of a Broken or Risky Cryptographic Algorithm vulnerability in Mia Technology Inc. Mia-Med Health Aplication allows S
The server supports at least one cipher suite which is on the NCSC-NL list of cipher suites to be phased out, increasing
The device is observed to accept deprecated TLS protocols, increasing the risk of cryptographic weaknesses.
IBM i Access Client Solutions (ACS) 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.4 is vulnerable to NT LAN Manager (NTL
In modem, there is a possible information disclosure due to using risky cryptographic algorithm during connection establ
Dell Secure Connect Gateway (SCG) 5.0 Appliance - SRS, version(s) 5.24, contains a Use of a Broken or Risky Cryptographi
Gessler GmbH WEB-MASTER user account is stored using a weak hashing algorithm. The attacker can restore the passwords by
Windows Authentication Elevation of Privilege Vulnerability
An issue was discovered in Matrix libolm through 3.2.16. There is Ed25519 signature malleability due to lack of validati
Dell Key Trust Platform, v3.0.6 and prior, contains Use of a Cryptographic Primitive with a Risky Implementation vulnera
Vyper is a Pythonic Smart Contract Language for the EVM. There is an error in the stack management when compiling the `I
Dell Secure Connect Gateway, 5.18, contains an Inadequate Encryption Strength Vulnerability. An unauthenticated network
A vulnerability was found in Topdata Inner Rep Plus WebServer 2.01. It has been rated as problematic. Affected by this i
IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain sensitive information due to improper encryptio
IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain sensitive information due to improper encryptio
Weak algorithm used to sign RPM package. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux)
sftpgo is a full-featured and highly configurable event-driven file transfer solution. Server protocols: SFTP, HTTP/S, F
ESPTouch is a connection protocol for internet of things devices. In the ESPTouchV2 protocol, while there is an option t
Econolite EOS versions prior to 3.2.23 use a weak hash algorithm for encrypting privileged user credentials. A configura
HHVM 4.172.0 and all prior versions use TLS 1.0 for secure connections when handling tls:// URLs in the stream extension
SonicWall GMS and Analytics use outdated Tiny Encryption Algorithm (TEA) with a hardcoded key to encrypt sensitive data.
Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key g
CryptoES is a cryptography algorithms library compatible with ES6 and TypeScript. Prior to version 2.1.0, CryptoES PBKDF
crypto-js is a JavaScript library of crypto standards. Prior to version 4.2.0, crypto-js PBKDF2 is 1,000 times weaker th
An issue was discovered in bcoin-org bcoin version 2.2.0, allows remote attackers to obtain sensitive information via we
In btm_sec_encrypt_change of btm_sec.cc, there is a possible way to downgrade the link key type due to improperly used c
Vault Key Sealed With SHA1 PCRs The measured boot solution implemented in EVE OS leans on a PCR locking mechanism
OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). The AES GCM decryption ro
A Cryptographic Issue vulnerability has been found on IBERMATICA RPS, affecting version 2019. By firstly downloading the
Windows Kerberos Elevation of Privilege Vulnerability
Sliver from v1.5.x to v1.5.39 has an improper cryptographic implementation, which allows attackers to execute a man-in-t
there is a possible way to bypass cryptographic assurances due to a logic error in the code. This could lead to local es
A misconfiguration of RSA padding implemented in the PingID Adapter for PingFederate to support Offline MFA with PingID
TP-Link router TL-WR940N V6 3.19.1 Build 180119 uses a deprecated MD5 algorithm to hash the admin password used for basi
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 bu
IBM Runtime Environment, Java Technology Edition IBMJCEPlus and JSSE 8.0.7.0 through 8.0.7.11 components could expose se
Broadcom RAID Controller web interface is vulnerable has an insecure default TLS configuration that supports obsolete SH
Broadcom RAID Controller web interface is vulnerable has an insecure default TLS configuration that support obsolete and
A vulnerability has been identified in NPort 6000 Series, making the authentication mechanism vulnerable. This vulnerabi
An issue was discovered in blinksocks version 3.3.8, allows remote attackers to obtain sensitive information via weak en
Sympa before 6.2.62 relies on a cookie parameter for certain security objectives, but does not ensure that this paramete
SanDisk PrivateAccess versions prior to 6.4.9 support insecure TLS 1.0 and TLS 1.1 protocols which are susceptible to ma
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versio
Frequently Asked Questions
What is CWE-327?
CWE-327 (CWE-327) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-327?
There are 799 CVE records associated with CWE-327 in our database. Of these, 60 are critical severity, 251 are high severity, and 293 are medium severity.
How can I protect against CWE-327 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-327 using AI-powered security agents.
Detect CWE-327 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-327 vulnerabilities across your infrastructure.
Get Started