Show filters
158 Total Results
Displaying 31-40 of 158
Sort by:
Attacker Value
Unknown

CVE-2021-34687

Disclosure Date: July 15, 2021 (last updated February 23, 2025)
iDrive RemotePC before 7.6.48 on Windows allows information disclosure. A man in the middle can recover a system's Personal Key when a client attempts to make a LAN connection. The Personal Key is transmitted over the network while only being encrypted via a substitution cipher.
Attacker Value
Unknown

CVE-2021-20497

Disclosure Date: July 13, 2021 (last updated February 23, 2025)
IBM Security Verify Access Docker 10.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 197969
Attacker Value
Unknown

CVE-2021-29794

Disclosure Date: July 09, 2021 (last updated February 23, 2025)
IBM Tivoli Netcool/Impact 7.1.0.20 and 7.1.0.21 uses an insecure SSH server configuration which enables weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 203556.
Attacker Value
Unknown

CVE-2021-20379

Disclosure Date: July 06, 2021 (last updated February 23, 2025)
IBM Guardium Data Encryption (GDE) 3.0.0.3 and 4.0.0.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 195711.
Attacker Value
Unknown

CVE-2021-20566

Disclosure Date: June 15, 2021 (last updated February 22, 2025)
IBM Resilient SOAR V38.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 199238.
Attacker Value
Unknown

CVE-2020-26515

Disclosure Date: June 08, 2021 (last updated February 22, 2025)
An insufficiently protected credentials issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. The remember-me cookie (CB_LOGIN) issued by the application contains the encrypted user's credentials. However, due to a bug in the application code, those credentials are encrypted using a NULL encryption key.
Attacker Value
Unknown

CVE-2021-22212

Disclosure Date: June 08, 2021 (last updated February 22, 2025)
ntpkeygen can generate keys that ntpd fails to parse. NTPsec 1.2.0 allows ntpkeygen to generate keys with '#' characters. ntpd then either pads, shortens the key, or fails to load these keys entirely, depending on the key type and the placement of the '#'. This results in the administrator not being able to use the keys as expected or the keys are shorter than expected and easier to brute-force, possibly resulting in MITM attacks between ntp clients and ntp servers. For short AES128 keys, ntpd generates a warning that it is padding them.
Attacker Value
Unknown

CVE-2021-22738

Disclosure Date: May 26, 2021 (last updated February 22, 2025)
Use of a Broken or Risky Cryptographic Algorithm vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior that could cause unauthorized access when credentials are discovered after a brute force attack.
Attacker Value
Unknown

CVE-2021-20419

Disclosure Date: May 21, 2021 (last updated February 22, 2025)
IBM Security Guardium 11.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 196280.
Attacker Value
Unknown

CVE-2021-27457

Disclosure Date: May 20, 2021 (last updated February 22, 2025)
A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected products utilize a weak encryption algorithm for storage of sensitive data, which may allow an attacker to more easily obtain credentials used for access.