Threats Tagged 'cwe-327'
View all threats tagged with 'cwe-327'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-327'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-50268: CWE-256: Plaintext Storage of a Password in SteeltoeOSS Steeltoe.Configuration.EncryptionCVE-2026-50268 0 Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Configuration.Encryption 4.0.0 through 4.1.0, configuring `encrypt:rsa:algorithm=OAEP` does not enable OAEP encryption. Due to an incorrect BouncyCastle transformation string, the `OAEP` setting selects PKCS#1 v1.5, which is the same algorithm as the `DEFAULT` setting. Steeltoe.Configuration.Encryption version 4.2.0 patches the issue. Join the discussion | CVE Database V5 | 06/17/2026, 22:01:19 UTC Added: 06/17/2026, 22:35:08 UTC |
CVE-2026-40641: CWE-327: Use of a Broken or Risky Cryptographic Algorithm in Dell PowerFlexCVE-2026-40641 0 Dell PowerFlex Manager version 4.6.0.1 contains a vulnerability due to the use of a broken or risky cryptographic algorithm. This flaw could allow an unauthenticated remote attacker to cause information disclosure and information tampering. The vulnerability has a medium severity rating with a CVSS score of 4.8. No patch or official remediation guidance is currently provided by the vendor. There are no known exploits in the wild at this time. Join the discussion | CVE Database V5 | 06/17/2026, 14:19:09 UTC Added: 06/17/2026, 15:07:07 UTC |
CVE-2026-9261: CWE-327: Use of a Broken or Risky Cryptographic Algorithm in Canon Inc. EOS Network Setting Tool for WindowsCVE-2026-9261 0 Use of weak SSH cryptographic algorithms in Canon EOS Network Setting Tool Version 1.5.0 or earlier Join the discussion | CVE Database V5 | 06/15/2026, 23:39:23 UTC Added: 06/16/2026, 00:00:41 UTC |
CVE-2026-50086: CWE-327: Use of a Broken or Risky Cryptographic Algorithm in Aqara Aqara IAM/SSO GatewayCVE-2026-50086 0 The Aqara IAM/SSO Gateway has a critical vulnerability involving the use of a broken or risky cryptographic algorithm (AES round-trups) exposed without authentication. This vulnerability allows unauthenticated attackers to interact with the platform's signing key, leading to a high-severity impact on confidentiality, integrity, and availability. The issue is categorized under CWE-327 and CWE-306. No official patch or remediation guidance is currently available. Join the discussion | CVE Database V5 | 06/12/2026, 15:01:26 UTC Added: 06/12/2026, 15:39:37 UTC |
CVE-2026-40996: CWE-327: Use of a Broken or Risky Cryptographic Algorithm in Spring Spring Web ServicesCVE-2026-40996 0 Wss4jSecurityInterceptor defaulted allowRSA15KeyTransportAlgorithm to true, overriding Apache WSS4J's safer default for validation RequestData. Inbound WS-Security decryption could therefore accept RSA PKCS#1 v1.5 (rsa-1_5) encrypted key material unless operators explicitly reconfigured the flag. Affected versions: Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8. Join the discussion | CVE Database V5 | 06/11/2026, 05:04:05 UTC Added: 06/11/2026, 06:46:18 UTC |
CVE-2025-10237: CWE-327: Use of a Broken or Risky Cryptographic Algorithm in Lenovo X13 Gen 6 (Type 21RK, 21RL) Laptops (ThinkPad) BIOSCVE-2025-10237 0 During an internal security assessment, a potential vulnerability was discovered in some ThinkPad embedded controller firmware that could allow a privileged local user to perform arbitrary reads or writes to privileged memory regions. Join the discussion | CVE Database V5 | 06/10/2026, 14:10:56 UTC Added: 06/10/2026, 14:50:07 UTC |
CVE-2026-46395: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor in haxtheweb haxcms-nodejsCVE-2026-46395 0 HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, the `hmacBase64()` function in the HAXcms Node.js backend contains two critical cryptographic implementation errors that together allow any unauthenticated attacker to extract the system’s private signing key and forge arbitrary admin-level JSON Web Tokens (JWTs) allowing them to get full admin access with a single HTTP request. First, the function passes the literal string "0" as the HMAC signing key instead of the key parameter, making every HAXcms instance compute identical HMACs for the same input. Then, after computing the HMAC, the function concatenates the real key parameter which is "this.privateKey + this.salt", the system’s master signing secret is directly onto the output. The combined buffer is base64-encoded and returned as the token. Every base64url token produced has the same structure: 32 bytes HMAC keyed with "0" and N bytes of `privateKey+salt`. An attacker base64-decodes any token, discards the first 32 bytes, and reads the private key directly. The `/system/api/connectionSettings` endpoint is unauthenticated and returns multiple tokens generated by this function. A single GET request to this endpoint exposes the private key. The PHP backend implements this function correctly with the actual key and returns only the hash. The PHP version produces 44-character tokens whereas the broken Node.js version produces 139+ character tokens. Version 26.0.0 fixes the issue. Join the discussion | CVE Database V5 | 06/05/2026, 18:27:54 UTC Added: 06/05/2026, 19:03:38 UTC |
CVE-2024-3264: CWE-327 Use of a Broken or Risky Cryptographic Algorithm in Mia Technology Inc. Mia-Med Health AplicationCVE-2024-3264 0 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Mia Technology Inc. Mia-Med Health Aplication allows Signature Spoofing by Improper Validation. This issue affects Mia-Med Health Aplication: before 1.0.14. Join the discussion | CVE Database V5 | 06/24/2024, 12:45:13 UTC Added: 06/03/2026, 15:49:02 UTC |
CVE-2026-49323: CWE-1390 Weak Authentication in Indian Motorcycle (Polaris Inc.) Scout Bobber + TechCVE-2026-49323 0 Weak authentication between the Wireless Control Module (WCM) and the Engine Control Module (ECM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker with read access to the in-vehicle network to recover the per-vehicle ECM immobilizer secret by passively observing a single seed/key exchange. The WCM derives its response using a reversible, non-cryptographic operation rather than a cryptographic challenge-response, so the persistent immobilizer secret can be reconstructed from one captured exchange. With this secret the attacker can authenticate to the ECM independently of the WCM and start the engine, defeating the immobilizer. Specific protocol details have been withheld pending vendor remediation. Join the discussion | CVE Database V5 | 05/29/2026, 12:31:35 UTC Added: 05/29/2026, 12:48:35 UTC |
CVE-2026-49322: CWE-1390 Weak Authentication in Indian Motorcycle (Polaris Inc.) Scout Bobber + TechCVE-2026-49322 0 Weak authentication in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker with read access to the in-vehicle network to recover the user-set unlock PIN by passively observing a single PIN authentication exchange. The Infotainment Digital Round display computes its response using a non-cryptographic operation rather than a cryptographic challenge-response, so the PIN is mathematically derivable from one captured exchange, defeating the motorcycle's primary user-authentication control. Specific protocol details have been withheld pending vendor remediation. Join the discussion | CVE Database V5 | 05/29/2026, 07:29:55 UTC Added: 05/29/2026, 07:48:34 UTC |
Showing 1 to 10 of 10 results