Threats Tagged 'cwe-327'
View all threats tagged with 'cwe-327'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-327'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-8470: CWE-327 Use of a Broken or Risky Cryptographic Algorithm in IBM Langflow OSSCVE-2026-8470 0 IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 use Python's non-cryptographic random module for generating Fernet encryption keys from user secrets under 32 characters. The deterministic Mersenne Twister PRNG produces identical keys for identical seeds, allowing attackers to reproduce encryption keys and decrypt stored API keys and authentication tokens. Join the discussion | CVE Database V5 | 08/05/2026, 18:11:52 UTC Added: 08/05/2026, 18:27:02 UTC |
CVE-2026-56609: CWE-327 Use of a Broken or Risky Cryptographic Algorithm in HCL Software HCL iControlCVE-2026-56609 0 HCL iControl version 3.2.0 uses weak SSL/TLS protocols, specifically TLS 1.0 and 1.1, which are outdated and lack modern security features. This weakness can expose sensitive data during transmission to known cryptographic attacks. The vulnerability is classified under CWE-327 for use of broken or risky cryptographic algorithms. The CVSS score is 4.8, indicating a medium severity level. Join the discussion | CVE Database V5 | 08/03/2026, 11:26:07 UTC Added: 08/03/2026, 12:48:47 UTC |
CVE-2026-65309: CWE-327 in ANDRITZ HIPASE-250CVE-2026-65309 0 ANDRITZ HIPASE-250 stores and transmits user passwords using a reversible format rather than a secure one-way hash. This vulnerability allows attackers who can access the credential store or intercept network traffic to recover all stored passwords. The issue affects unspecified versions of the product. No official patch or remediation guidance is currently available. The vulnerability has a high severity rating with a CVSS score of 7.5. Join the discussion | CVE Database V5 | 07/31/2026, 07:17:40 UTC Added: 07/31/2026, 07:37:52 UTC |
CVE-2026-56582: CWE-327: Use of a Broken or Risky Cryptographic Algorithm in HCLSoftware MyCloudCVE-2026-56582 0 HCL MyCloud was affected by the SSL/TLS LUCKY13 Vulnerability. An attacker may exploit this vulnerability to decrypt sensitive information through a TLS/SSL padding oracle attack. Join the discussion | CVE Database V5 | 07/21/2026, 17:38:24 UTC Added: 07/21/2026, 18:12:18 UTC |
CVE-2026-56454: CWE-327: Use of a Broken or Risky Cryptographic Algorithm in HCL Software DFXAnalyticsCVE-2026-56454 0 HCL DFXAnalytics is affected by a Deprecated Protocol vulnerability due to the use of TLS 1.0 and TLS 1.1. These legacy protocols contain numerous cryptographic design flaws that expose data to interception and decryption. To remediate this risk, the application must disable all support for TLS 1.0 and TLS 1.1, and exclusively enable support for secure protocols, specifically TLS 1.2 and TLS 1.3. Join the discussion | CVE Database V5 | 07/16/2026, 13:08:38 UTC Added: 07/16/2026, 13:18:08 UTC |
Showing 1 to 5 of 5 results