CWE:
 

Tytuł
Data
Autor
Med.
Oracle Database Weak NNE Integrity Key Derivation
13.12.2021
Moritz Bechler
Med.
CyberArk Credential Provider Local Cache Decryption
04.09.2021
Klayton Monroe
Med.
CyberArk Credential Provider Race Condition / Authorization Bypass
04.09.2021
Klayton Monroe


Common Weakness Enumeration (CWE)

CVE
Szczegóły
Opis
2023-05-17
Waiting for details
CVE-2023-31135

Updating...
 

 
Dgraph is an open source distributed GraphQL database. Existing Dgraph audit logs are vulnerable to brute force attacks due to nonce collisions. The first 12 bytes come from a baseIv which is initialized when an audit log is created. The last 4 bytes come from the length of the log line being encrypted. This is problematic because two log lines will often have the same length, so due to these collisions we are reusing the same nonce many times. All audit logs generated by versions of Dgraph <v23.0.0 are affected. Attackers must have access to the system the logs are stored on. Dgraph users should upgrade to v23.0.0. Users unable to upgrade should store existing audit logs in a secure location and for extra security, encrypt using an external tool like `gpg`.

 
2023-05-15
Waiting for details
CVE-2022-4048

Updating...
 

 
Inadequate Encryption Strength in CODESYS Development System V3 versions prior to V3.5.18.40 allows an unauthenticated local attacker to access and manipulate code of the encrypted boot application.

 
2023-04-11
Waiting for details
CVE-2023-29054

Updating...
 

 
A vulnerability has been identified in SCALANCE X200-4P IRT (All versions < V5.5.2), SCALANCE X201-3P IRT (All versions < V5.5.2), SCALANCE X201-3P IRT PRO (All versions < V5.5.2), SCALANCE X202-2IRT (All versions < V5.5.2), SCALANCE X202-2IRT (All versions < V5.5.2), SCALANCE X202-2P IRT (All versions < V5.5.2), SCALANCE X202-2P IRT PRO (All versions < V5.5.2), SCALANCE X204IRT (All versions < V5.5.2), SCALANCE X204IRT (All versions < V5.5.2), SCALANCE X204IRT PRO (All versions < V5.5.2), SCALANCE XF201-3P IRT (All versions < V5.5.2), SCALANCE XF202-2P IRT (All versions < V5.5.2), SCALANCE XF204-2BA IRT (All versions < V5.5.2), SCALANCE XF204IRT (All versions < V5.5.2), SIPLUS NET SCALANCE X202-2P IRT (All versions < V5.5.2). The SSH server on affected devices is configured to offer weak ciphers by default. This could allow an unauthorized attacker in a man-in-the-middle position to read and modify any data passed over the connection between legitimate clients and the affected device.

 
2022-12-02
Waiting for details
CVE-2022-2640

Updating...
 

 

 
2022-10-11
Waiting for details
CVE-2022-41209

Updating...
 

 
SAP Customer Data Cloud (Gigya mobile app for Android) - version 7.4, uses encryption method which lacks proper diffusion and does not hide the patterns well. This can lead to information disclosure. In certain scenarios, application might also be susceptible to replay attacks.

 
2022-08-31
Waiting for details
CVE-2022-2758

Updating...
 

 

 
2022-07-08
Medium
CVE-2022-22464

Vendor: IBM
Software: Security ver...
 

 
IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 225081.

 
2022-05-06
Low
CVE-2022-28164

Vendor: Broadcom
Software: Sannav
 

 
Brocade SANnav before SANnav 2.2.0 application uses the Blowfish symmetric encryption algorithm for the storage of passwords. This could allow an authenticated attacker to decrypt stored account passwords.

 
2022-05-04
Medium
CVE-2021-32010

Vendor: Secomea
Software: Linkmanager
 

 
Inadequate Encryption Strength vulnerability in TLS stack of Secomea SiteManager, LinkManager, GateManager may facilitate man in the middle attacks. This issue affects: Secomea SiteManager All versions prior to 9.7. Secomea LinkManager versions prior to 9.7. Secomea GateManager versions prior to 9.7.

 
2022-05-03
Medium
CVE-2022-22368

Updating...
 

 
IBM Spectrum Scale 5.1.0 through 5.1.3.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 221012.

 

 


Copyright 2023, cxsecurity.com

 

Back to Top