Skip to main content

Threats Tagged 'cwe-331'

View all threats tagged with 'cwe-331'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-331

Threats Tagged 'cwe-331'

Click on any threat for detailed analysis and mitigation recommendations

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insufficient Entropy in PRNG vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges.

Join the discussion

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A session identifier is generated using an algorithm with insufficient randomness, resulting in a token with low entropy that can be predicted or brute-forced within a feasible number of attempts. This could allow an unauthenticated remote attacker to derive valid session identifiers and bypass authentication.

Join the discussion

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A session identifier is generated using an algorithm with insufficient randomness, resulting in a token with low entropy that can be predicted or brute-forced within a feasible number of attempts. This could allow an unauthenticated remote attacker to derive valid session identifiers and bypass authentication.

Join the discussion

Combodo iTop versions prior to 3.2.3 use a weak 24-bit pseudo-random secret to protect inline images accessible without authentication. This insufficient entropy vulnerability allows potential attackers to predict or guess the secret, potentially exposing these images. The issue has been fixed in version 3.2.3.

Join the discussion

CVE-2026-4936 is a vulnerability in IBM PowerVM Hypervisor's Platform KeyStore (PKS) and virtual TPM firmware versions FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H2. The issue involves the use of persistent storage key seeds that produce an AES key with reduced cryptographic strength due to insufficient entropy. An attacker with high-level access to the service processor or Hardware Management Console (HMC) could potentially derive the encryption key and gain unauthorized access to protected data.

Join the discussion

CVE-2026-4937 is a medium severity vulnerability in IBM PowerVM Hypervisor versions FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H2. It involves insufficient entropy in certain hypervisor calls, which could allow a local attacker with administrative privileges to decrypt encrypted data. The vulnerability does not affect confidentiality, integrity, or availability beyond the described impact. No known exploits are reported in the wild, and no patch information is provided.

Join the discussion

crypto-js is a JavaScript library of crypto standards. Versions of crypto-js prior to 4.0.0 generate randomness in CryptoJS.lib.WordArray.random() using a custom variation of the Multiply-With-Carry pseudorandom number generator, seeded from Math.random(), instead of a cryptographically secure source. This generator was introduced in version 3.1.2-4 and remained present in nearly every 3.x release. Nominal requests for 128 or 256 bits of entropy through this function produce effective search spaces of approximately 2 to the 39th and 2 to the 47th possibilities, small enough to enumerate on commodity hardware. Downstream wallet applications that used CryptoJS.lib.WordArray.random() as the entropy source for BIP39 recovery phrases are affected, and an attacker who enumerates the reduced output space can recover the resulting private keys and control the associated funds. This issue is fixed in version 4.0.0.

Join the discussion

A cryptographic weakness exists in the Omada adoption protocol where session encryption keys used to protect communications between controllers and managed devices may be predictable due to insufficient entropy in session key generation. An attacker who successfully intercepts adoption-related communications may be able to recover session encryption keys and decrypt affected communications.

Join the discussion

IBM PowerVM Hypervisor FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 could allow an attacker with physical access to the Transparent Memory Encryption (TME) hardware to decrypt encrypted memory due to insufficient cryptographic entropy.

Join the discussion

A vulnerability in Sonatype Nexus Repository Manager's format-specific API key generation may allow a remote attacker to gain unauthorized access to repository operations as a targeted user. A format-specific API key realm (NuGet API Key, Docker Bearer Token, or npm Bearer Token) must be enabled and the targeted user must have an active API key for this vulnerability to be exploitable.

Join the discussion

Showing 1 to 10 of 49 results

Filters:Tag: cwe-331
Page 1 of 5
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses