Skip to main content

Threats Tagged 'cwe-330'

View all threats tagged with 'cwe-330'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-330

Threats Tagged 'cwe-330'

Click on any threat for detailed analysis and mitigation recommendations

OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 uses an administrator password-reset unlock-code design that lacks a per-device secret or other server-side cryptographic material. An attacker with physical-console access and access to the privileged password-reset workflow can forge a valid unlock code offline and use it to reset the administrator password. The underlying design has been present since at least firmware 2.2.3.4. Upgrade to version 3.5.4.

Join the discussion
0

Postiz generates security-sensitive credentials using `Math.random()` instead of a cryptographically secure source. The same helper is used for OAuth access tokens, authorization codes, client secrets, organization API keys, and PKCE verifiers, meaning these credentials depend entirely on V8’s deterministic xorshift128+ PRNG state. An unauthenticated OAuth dynamic client registration endpoint exposes freshly generated client credentials, giving attackers enough consecutive PRNG output to reconstruct that internal state. Once recovered, they can deterministically derive past and future values produced by the same generator, potentially compromising credentials belonging to other users and organizations.

Join the discussion

Bucket Squatting in Google Cloud Gemini Enterprise Agent Platform SDK for Python versions prior to 1.166.1 allows an attacker to achieve Remote Code Execution (RCE) and tenant-project token theft.

Join the discussion

OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). In versions 0.6.1 through 0.6.2.5, when cjose encrypts a JWE using an AES-CBC-HMAC content-encryption algorithm (`A128CBC-HS256`, `A192CBC-HS384`, or `A256CBC-HS512`) together with any key-management algorithm that generates a fresh content-encryption key (CEK), the CEK is all zero bytes instead of being randomly generated. The resulting JWE is therefore encrypted and authenticated under a fixed, publicly known key, so anyone who obtains the JWE can recover the plaintext and forge or modify the content. This is fixed in version 0.6.2.6 by `_cjose_jwe_set_cek_aes_cbc()` generating the CEK from `RAND_bytes`. A regression test asserts that the `encrypted_key` differs across two encryptions for each AES-CBC-HMAC variant. Until upgrading, for data encrypted with cjose, three options are available. Use an AES-GCM `enc` (`A128GCM` / `A192GCM` / `A256GCM`) instead of an AES-CBC-HMAC `enc`, use `alg=dir` with a caller-supplied CEK, or avoid using cjose for JWE encryption with the affected algorithm pair. These are mitigations for new ciphertexts only; data already encrypted under the zero key remains compromised and should be re-encrypted (and any secrets it contained rotated).

Join the discussion

IBM i versions 7.3, 7.4, 7.5, and 7.6 contain a vulnerability where predictable server seeds could allow a remote authenticated attacker to bypass security restrictions. This issue is due to the use of insufficiently random values in the system's security mechanisms. The vulnerability has a medium severity with a CVSS score of 5.4.

Join the discussion

The API Publisher component previously used a non-cryptographic pseudorandom number generator (PRNG) to create shared secrets for Webhook HMAC validation. This PRNG lacks sufficient entropy for security-sensitive operations, allowing a sophisticated attacker to predict future secrets. This enables malicious actors to forge event payloads with valid HMAC signatures, bypassing the API Gateway's authenticity verification. Successful exploitation could allow an attacker to predict shared secrets used for Webhook HMAC validation and forge event payloads with valid signatures. This may enable bypassing API Gateway authenticity checks, leading to unauthorized event injection, data manipulation, or downstream system compromise.

Join the discussion

CVE-2026-81852 is a vulnerability in ash-project's ash_admin component where a hardcoded, publicly known Content-Security-Policy (CSP) nonce is used. This nonce is a compile-time constant that is not rotated per request, allowing an attacker who can inject HTML on an admin page to reuse the known nonce to bypass CSP protections against inline scripts. The issue affects versions from 0.10.8 up to but not including 1.3.1. The vulnerability has a low severity score and no known exploits in the wild.

Join the discussion

CVE-2026-19485 is a critical vulnerability in Google Cloud Vertex AI Search for Commerce prior to 2026-04-27. It involves predictable resource names in the BigQuery Import Staging component, allowing an attacker who knows a victim's project number to gain read/write access to staged data and error logs. This vulnerability has been patched by Google, and no customer action is required. The vulnerability has a CVSS 4.0 score of 9.3, indicating high severity. It affects the cloud service hosted by Google Cloud Platform.

Join the discussion

Typebot.io versions up to and including 3.17.1 have a vulnerability in their passwordless email magic-link authentication. The 6-digit login code is generated insecurely with Math.random(), allowing brute force attacks due to a limited keyspace and no effective attempt limits or lockout. Attackers can guess valid codes within their 10-minute lifetime without consuming attempts, enabling account takeover. OAuth or SSO-only deployments without email providers are not affected. This issue is fixed in version 3.18.0.

Join the discussion

Combodo iTop versions prior to 3.2.3 use a weak 24-bit pseudo-random secret to protect inline images accessible without authentication. This insufficient entropy vulnerability allows potential attackers to predict or guess the secret, potentially exposing these images. The issue has been fixed in version 3.2.3.

Join the discussion

Showing 1 to 10 of 58 results

Filters:Tag: cwe-330
Page 1 of 6
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses