Passeo is an open source python password generator. Versions prior to 1.0.5 rely on the python `random` library for rand
SAP Customer Data Cloud (Gigya mobile app for Android) - version 7.4, uses insecure random number generator program whic
A flaw was found in github.com/satori/go.uuid in versions from commit 0ef6afb2f6cdd6cdaeee3885a95099c63f18fc8c to d91630
PolarSSL versions prior to v1.1 use the HAVEGE random number generation algorithm. At its heart, this uses timing inform
Eclipse TinyDTLS through 0.9-rc1 relies on the rand function in the C library, which makes it easier for remote attacker
In JetBrains YouTrack before 2021.2.16363, an insecure PRNG was used.
In NetBSD through 9.2, the IPv6 fragment ID generation algorithm employs a weak cryptographic PRNG.
In NetBSD through 9.2, the IPv6 Flow Label generation algorithm employs a weak cryptographic PRNG.
Vulnerability in the generation of session IDs in revive-adserver < 5.3.0, based on the cryptographically insecure uniqi
Use of cryptographically weak pseudo-random number generator (PRNG) in an API for the Intel(R) Security Library before v
showdoc is vulnerable to Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
It was found that various OpenID Providers (OPs) had TLS Server Certificates that used weak keys, as a result of the Deb
showdoc is vulnerable to Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
An issue was discovered in Joomla! 3.2.0 through 3.9.24. Usage of the insecure rand() function within the process of gen
BTCPay Server through 1.0.7.0 uses a weak method Next to produce pseudo-random values to generate a legacy API key.
A cryptographically weak pseudo-random number generator (PRNG) is used during authentication to the Palo Alto Networks P
The function mt_rand is used to generate session tokens, this function is cryptographically flawed due to its nature bei
In InfiniteWP Admin Panel before 3.1.12.3, resetPasswordSendMail generates a weak password-reset code, which makes it ea
AdRem NetCrunch 10.6.0.4587 has an Improper Session Handling vulnerability in the NetCrunch web client, which can lead t
NVIDIA DGX servers, all BMC firmware versions prior to 3.38.30, contain a vulnerability in the AMI BMC firmware in which
An issue was discovered in Rclone before 1.53.3. Due to the use of a weak random number generator, the password generato
An issue was discovered in Open Source Social Network (OSSN) through 5.3. A user-controlled file path with a weak crypto
A class generated by the Generator in JHipster before 6.3.0 and JHipster Kotlin through 1.1.0 produces code that uses an
The oauth2-provider plugin before 3.1.5 for WordPress has incorrect generation of random numbers.
Use of cryptographically weak PRNG in the password recovery token generation of Revive Adserver < v4.2.1 causes a potent
Multiple classes used within Apereo CAS before release 6.1.0-RC5 makes use of apache commons-lang3 RandomStringUtils for
An issue was discovered in Matrix Sydent before 1.0.3 and Synapse before 0.99.3.1. Random number generation is mishandle
A cryptographically weak pseudo-rando number generator is used in multiple security relevant contexts in Magento 2.1 pri
The miekg Go DNS package before 1.1.25, as used in CoreDNS before 1.6.6 and other products, improperly generates random
A cryptograhic flaw in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 could be abus
A casting error in Chicken before 4.8.0 on 64-bit platform caused the random number generator to return a constant value
Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1 uses cryptographically weak random number generator
The SAML identifier generated within SAML2Utils.java was found to make use of the apache commons-lang3 RandomStringUtils
Ratpack versions before 1.6.1 generate a session ID using a cryptographically weak PRNG in the JDK's ThreadLocalRandom.
It was discovered that QtPass before 1.2.1, when using the built-in password generator, generates possibly predictable a
Lightbend Akka 2.5.x before 2.5.16 allows message disclosure and modification because of an RNG error. A random number g
Pivotal CredHub Service Broker, versions prior to 1.1.0, uses a guessable form of random number generation in creating s
The _addguess function of a simplelottery smart contract implementation for 1000 Guess, an Ethereum gambling game, gener
The endCoinFlip function and throwSlammer function of the smart contract implementations for Cryptogs, an Ethereum game,
The maxRandom function of a smart contract implementation for All For One, an Ethereum gambling game, generates a random
The "PayWinner" function of a simplelottery smart contract implementation for The Ethereum Lottery, an Ethereum gambling
The fallback function of a simple lottery smart contract implementation for Lucky9io, an Ethereum gambling game, generat
In Snapdragon (Automobile, Mobile, Wear) in version MDM9206, MDM9607, MDM9640, MDM9650, MSM8996AU, QCA6574AU, QCA6584, S
In Snapdragon (Automobile, Mobile, Wear) in version IPQ8074, MDM9206, MDM9607, MDM9640, MDM9650, MSM8996AU, QCA4531, QCA
In Snapdragon (Automobile, Mobile, Wear) in version IPQ8074, MDM9206, MDM9607, MDM9640, MDM9650, MSM8996AU, QCA6574AU, S
The random() function of the smart contract implementation for CryptoSaga, an Ethereum game, generates a random value wi
A lottery smart contract implementation for Greedy 599, an Ethereum gambling game, generates a random value that is pred
A gambling smart contract implementation for RuletkaIo, an Ethereum gambling game, generates a random value that is pred
In Snapdragon (Automobile, Mobile, Wear) in version MDM9206, MDM9607, MDM9640, MDM9650, MSM8996AU, QCA6574AU, SD 210/SD
The randMod() function of the smart contract implementation for MyCryptoChamp, an Ethereum game, generates a random valu
Frequently Asked Questions
What is CWE-338?
CWE-338 (CWE-338) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-338?
There are 241 CVE records associated with CWE-338 in our database. Of these, 49 are critical severity, 77 are high severity, and 67 are medium severity.
How can I protect against CWE-338 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-338 using AI-powered security agents.
Detect CWE-338 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-338 vulnerabilities across your infrastructure.
Get Started