Threats Tagged 'cwe-327'
View all threats tagged with 'cwe-327'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-327'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2025-10237: CWE-327: Use of a Broken or Risky Cryptographic Algorithm in Lenovo X13 Gen 6 (Type 21RK, 21RL) Laptops (ThinkPad) BIOSCVE-2025-10237 0 A high-severity vulnerability (CVE-2025-10237) was identified in the BIOS of Lenovo ThinkPad X13 Gen 6 (Type 21RK, 21RL) laptops. The issue involves the use of a broken or risky cryptographic algorithm in the embedded controller firmware, which could allow a privileged local user to perform arbitrary reads or writes to privileged memory regions. This vulnerability was discovered during an internal security assessment. No patch or official remediation guidance has been provided yet. Join the discussion | CVE Database V5 | 06/10/2026, 14:10:56 UTC Added: 06/10/2026, 14:50:07 UTC |
CVE-2026-46395: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor in haxtheweb haxcms-nodejsCVE-2026-46395 0 HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, the `hmacBase64()` function in the HAXcms Node.js backend contains two critical cryptographic implementation errors that together allow any unauthenticated attacker to extract the system’s private signing key and forge arbitrary admin-level JSON Web Tokens (JWTs) allowing them to get full admin access with a single HTTP request. First, the function passes the literal string "0" as the HMAC signing key instead of the key parameter, making every HAXcms instance compute identical HMACs for the same input. Then, after computing the HMAC, the function concatenates the real key parameter which is "this.privateKey + this.salt", the system’s master signing secret is directly onto the output. The combined buffer is base64-encoded and returned as the token. Every base64url token produced has the same structure: 32 bytes HMAC keyed with "0" and N bytes of `privateKey+salt`. An attacker base64-decodes any token, discards the first 32 bytes, and reads the private key directly. The `/system/api/connectionSettings` endpoint is unauthenticated and returns multiple tokens generated by this function. A single GET request to this endpoint exposes the private key. The PHP backend implements this function correctly with the actual key and returns only the hash. The PHP version produces 44-character tokens whereas the broken Node.js version produces 139+ character tokens. Version 26.0.0 fixes the issue. Join the discussion | CVE Database V5 | 06/05/2026, 18:27:54 UTC Added: 06/05/2026, 19:03:38 UTC |
CVE-2024-3264: CWE-327 Use of a Broken or Risky Cryptographic Algorithm in Mia Technology Inc. Mia-Med Health AplicationCVE-2024-3264 0 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Mia Technology Inc. Mia-Med Health Aplication allows Signature Spoofing by Improper Validation. This issue affects Mia-Med Health Aplication: before 1.0.14. Join the discussion | CVE Database V5 | 06/24/2024, 12:45:13 UTC Added: 06/03/2026, 15:49:02 UTC |
CVE-2026-49323: CWE-1390 Weak Authentication in Indian Motorcycle (Polaris Inc.) Scout Bobber + TechCVE-2026-49323 0 Weak authentication between the Wireless Control Module (WCM) and the Engine Control Module (ECM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker with read access to the in-vehicle network to recover the per-vehicle ECM immobilizer secret by passively observing a single seed/key exchange. The WCM derives its response using a reversible, non-cryptographic operation rather than a cryptographic challenge-response, so the persistent immobilizer secret can be reconstructed from one captured exchange. With this secret the attacker can authenticate to the ECM independently of the WCM and start the engine, defeating the immobilizer. Specific protocol details have been withheld pending vendor remediation. Join the discussion | CVE Database V5 | 05/29/2026, 12:31:35 UTC Added: 05/29/2026, 12:48:35 UTC |
CVE-2026-49322: CWE-1390 Weak Authentication in Indian Motorcycle (Polaris Inc.) Scout Bobber + TechCVE-2026-49322 0 Weak authentication in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker with read access to the in-vehicle network to recover the user-set unlock PIN by passively observing a single PIN authentication exchange. The Infotainment Digital Round display computes its response using a non-cryptographic operation rather than a cryptographic challenge-response, so the PIN is mathematically derivable from one captured exchange, defeating the motorcycle's primary user-authentication control. Specific protocol details have been withheld pending vendor remediation. Join the discussion | CVE Database V5 | 05/29/2026, 07:29:55 UTC Added: 05/29/2026, 07:48:34 UTC |
CVE-2025-46371: CWE-327: Use of a Broken or Risky Cryptographic Algorithm in Dell PowerFlex Manager (Appliance)CVE-2025-46371 0 Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) a Use of a Broken or Risky Cryptographic Algorithm vulnerability in the ssh. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Protection mechanism bypass. Join the discussion | CVE Database V5 | 05/22/2026, 13:43:18 UTC Added: 05/22/2026, 14:29:48 UTC |
CVE-2026-44699: CWE-327: Use of a Broken or Risky Cryptographic Algorithm in benmcollins libjwtCVE-2026-44699 0 LibJWT is a C JSON Web Token Library. From 3.0.0 to 3.3.2, libjwt accepts an RSA JWK that does not contain an alg parameter as the verification key for an HS256/HS384/HS512 token. In the OpenSSL backend, this causes HMAC verification to run with a zero-length key, so an attacker can forge a valid JWT without knowing any secret or RSA private key. This is an algorithm-confusion authentication bypass. It affects applications that load RSA keys from JWKS where alg is omitted, which is valid JWK syntax and common in real deployments, and then choose the verification algorithm from the JWT header, for example in a kid lookup callback. This vulnerability is fixed in 3.3.3. Join the discussion | CVE Database V5 | 05/15/2026, 16:08:34 UTC Added: 05/15/2026, 16:36:40 UTC |
CVE-2026-8072: CWE-327: Use of a Broken or Risky Cryptographic Algorithm in Ingeteam Ingecon Sun EMS BoardCVE-2026-8072 0 CVE-2026-8072 is a critical vulnerability in the Ingecon Sun EMS Board related to the use of a weak cryptographic algorithm for generating local SAT access credentials. The insecure hashing scheme used for secret credentials can allow an attacker to escalate privileges. The vulnerability has a high CVSS 4. 0 score of 9. 2, indicating network attack vector with high impact on confidentiality, integrity, and availability. No official patch or remediation guidance is currently available from the vendor. There are no known exploits in the wild at this time. Join the discussion | CVE Database V5 | 05/12/2026, 09:57:02 UTC Added: 05/12/2026, 10:21:35 UTC |
CVE-2026-6411: CWE-327 in MAXHUB MAXHUB Pivot client applicationCVE-2026-6411 0 CVE-2026-6411 is a high-severity vulnerability in the MAXHUB Pivot client application versions prior to v1. 36. 2. It involves a hardcoded AES encryption key that allows attackers to decrypt encrypted tenant email addresses and related metadata. Additionally, attackers may cause a denial-of-service by enrolling multiple unauthorized devices into a tenant via MQTT, disrupting tenant operations. No official patch or remediation guidance is currently confirmed. Join the discussion | CVE Database V5 | 05/07/2026, 22:25:54 UTC Added: 05/07/2026, 22:36:24 UTC |
CVE-2026-5588: CWE-327 Use of a Broken or Risky Cryptographic Algorithm in Legion of the Bouncy Castle Inc. BC-JAVACVE-2026-5588 0 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpkix on all (pkix modules), Legion of the Bouncy Castle Inc. BCPKIX-FIPS bcpkix on All (pkix modules), Legion of the Bouncy Castle Inc. BCPIX-LTS bcpkix on All (pkix modules). This vulnerability is associated with program files JcaContentVerifierProviderBuilder.Java, JcaContentVerfierProviderBuilder.Java. This issue affects BC-JAVA: from 1.67 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84; BCPKIX-FIPS: from 2.0.6 before 2.0.11, from 2.1.7 before 2.1.11; BCPIX-LTS: from 2.73.7 before 2.73.11. Join the discussion | CVE Database V5 | 04/15/2026, 09:06:15 UTC Added: 04/15/2026, 09:31:59 UTC |
Showing 1 to 10 of 90 results