Threats Tagged 'cwe-325'
View all threats tagged with 'cwe-325'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-325'
Click on any threat for detailed analysis and mitigation recommendations
0 Crux Agent from 1.9.0 before 2.0.3 uses the full SKA bilocation key as the WireGuard preshared key. When a peering session negotiates use of SHA-512, the key produced is 64 bytes instead of the 32 bytes WireGuard requires. The agent does not validate this size; instead it attempts to use the `wg set` command to update the live tunnel, and write the invalid key to the WireGuard configuration file. The update fails, so the live tunnel keeps using its previous preshared key until the tunnel is shut down. The tunnel will fail to start when restarted. For a peer which has never successfully negotiated a 32-byte bilocation key in a Crux C2 organization which has the "Enforce SKA Use" setting turned off, no preshared key will be set for the tunnel. Therefore, an attacker who is able to intercept and store the peer's traffic, and has access (or will have access) to a cryptographically relevant quantum computer, will be able to decrypt the tunnel. Join the discussion | CVE Database V5 | 10/09/2026, 13:15:57 UTC Added: 10/09/2026, 13:34:09 UTC |
0 Missing cryptographic step in the DSTU 7624 CCM mode implementation (KCcmBlockCipher) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can observe encrypted messages of known or chosen content to forge ciphertexts with valid authentication tags, via messages encrypted without associated data. The cause is that the G1 block, which binds the nonce, the message length and the parameter flags into the CBC-MAC, was processed only when associated data was present. Without associated data the tag was a CBC-MAC of the plaintext alone, independent of the nonce. Only applications that use KCcmBlockCipher directly and supply no associated data are affected. Join the discussion | CVE Database V5 | 10/02/2026, 06:54:23 UTC Added: 10/02/2026, 14:55:30 UTC |
Dell Wyse Management Suite versions prior to 2605.0.3.683 contain a vulnerability due to a missing cryptographic step. This flaw could be exploited by a high privileged attacker with remote access to tamper with information. The vulnerability is identified as CWE-325 and has a high severity rating with a CVSS score of 8. No patch or remediation details are provided in the input data. Join the discussion | CVE Database V5 | 09/15/2026, 17:43:03 UTC Added: 09/15/2026, 18:02:13 UTC |
CVE-2026-25250 is a medium severity vulnerability in eazsolution EazyFix version 12.9. It involves a security feature bypass due to a missing cryptographic step related to disabling Secure Boot. The vulnerability has a CVSS score of 6.0 and impacts confidentiality and integrity but not availability. There is no official patch or remediation level provided by the vendor as of now. No known exploits are reported in the wild. Join the discussion | CVE Database V5 | 08/27/2026, 16:55:27 UTC Added: 08/27/2026, 20:24:14 UTC |
0 TP-Link Kasa smart home devices HS103P3 and HS103P4 v5 have insufficient cryptographic protections in their local communication protocol. This weakness allows an adjacent network attacker to intercept, replay, or forge control messages. Exploitation can lead to unauthorized control of the device, causing state changes, disruption, or denial of service. Join the discussion | CVE Database V5 | 08/26/2026, 17:47:54 UTC Added: 08/26/2026, 18:07:51 UTC |
0 Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally. Join the discussion | CVE Database V5 | 07/14/2026, 17:10:16 UTC Added: 07/14/2026, 17:49:57 UTC |
0 Missing cryptographic step in Windows CryptoAPI allows an authorized attacker to perform tampering locally. Join the discussion | CVE Database V5 | 07/14/2026, 17:05:06 UTC Added: 07/14/2026, 17:18:57 UTC |
0 This security update provides a functional equivalent of RHSA-2026:33514. The original Red Hat(R) advisory is available from the Red Hat web site at https://access.redhat.com/errata/RHSA-2026:33514. Join the discussion | GCVE Database | 06/30/2026, 00:00:00 UTC Added: 06/30/2026, 23:35:58 UTC |
Missing cryptographic step in Caliptra Core Firmware (aes_256_gcm_update module) results in an incorrect GCM authentication tag. When the streaming AES-256-GCM API is used with empty AAD, the hardware GHASH accumulator state is not saved after the first update call, causing the final tag to exclude the first batch of processed ciphertext. Ciphertext produced by that call may be modified without the tag reflecting the change. This issue affects Core Runtime Firmware: from 2.0.0 through 2.0.1, 2.1.0. Join the discussion | CVE Database V5 | 06/23/2026, 23:49:44 UTC Added: 06/24/2026, 00:24:13 UTC |
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, node:crypto.checkPrime(candidate[, options][, callback]) and crypto.checkPrimeSync(candidate[, options]) ran no Miller-Rabin rounds at all when the caller left options.checks at its default of 0. In that mode, the only test applied to the candidate was trial division by the primes up to 17,863. Any composite whose smallest prime factor exceeds that bound — for example the product of two primes just above it, such as 17,881 × 17,891 — was reported as true ("probably prime"). The same divergence affected the lower-level op_node_check_prime / op_node_check_prime_bytes paths that the polyfill calls into. This vulnerability is fixed in 2.8.1. Join the discussion | CVE Database V5 | 06/23/2026, 17:13:25 UTC Added: 06/23/2026, 17:39:59 UTC |
Showing 1 to 10 of 25 results