目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CWE-327 使用已被攻破或存在风险的密码学算法 类漏洞列表 299

CWE-327 使用已被攻破或存在风险的密码学算法 类弱点 299 条 CVE 漏洞汇总,含 AI 中文分析。

CWE-327指使用已损坏或存在风险加密算法的漏洞。攻击者常利用弱算法(如MD5、DES)破解数据,窃取敏感信息或篡改内容。开发者应避免使用已知不安全的算法,优先采用AES、SHA-256等现代标准,并定期审查加密实现,确保密钥管理安全,以保障数据机密性与完整性。

MITRE CWE 官方描述
CWE:CWE-327 使用损坏或有风险的加密算法 (Use of a Broken or Risky Cryptographic Algorithm) 英文:The product uses a broken or risky cryptographic algorithm or protocol. 译文:该产品使用了损坏或有风险的加密算法或协议。 加密算法 (Cryptographic algorithms) 是用于对数据进行混淆以防止未经授权的实体进行观察或干预的方法。不安全的加密 (Insecure cryptography) 可能被利用来暴露敏感信息、以意外方式修改数据、伪造其他用户或设备的身份,或造成其他影响。生成一个安全的算法非常困难,即使是知名加密专家设计的高知名度算法也可能被破解。目前存在已知的技术可以破解或削弱各种类型的加密。因此,只有少数经过充分理解和广泛研究的算法应被大多数产品使用。使用非标准或已知不安全的算法是危险的,因为坚定的攻击者可能能够破解该算法,从而破坏受保护的数据。由于密码学 (Cryptography) 的发展非常迅速,即使某个算法曾经被认为很强,现在也可能被视为“不安全”。这可能是因为发现了新的攻击方法,或者因为计算能力的大幅提升使得该加密算法不再能提供最初认为的保护程度。出于多种原因,与软件实现相比,在硬件部署中管理这种弱点更具挑战性。首先,如果发现硬件实现的加密存在缺陷,在大多数情况下无法修复该缺陷,除非召回产品,因为硬件不像软件那样易于更换。其次,由于硬件产品预期会运行多年,攻击者的计算能力将随着时间的推移而不断增强。
常见影响 (3)
Confidentiality Read Application Data
The confidentiality of sensitive data may be compromised by the use of a broken or risky cryptographic algorithm.
Integrity Modify Application Data
The integrity of sensitive data may be compromised by the use of a broken or risky cryptographic algorithm.
Accountability, Non-Repudiation Hide Activities
If the cryptographic algorithm is used to ensure the identity of the source of the data (such as digital signatures), then a broken algorithm will compromise this scheme and the source of the data cannot be proven.
缓解措施 (5)
Architecture and Design When there is a need to store or transmit sensitive data, use strong, up-to-date cryptographic algorithms to encrypt that data. Select a well-vetted algorithm that is currently considered to be strong by experts in the field, and use well-tested implementations. As with all cryptographic mechanisms, the source code should be available for analysis. For example, US government systems require FIPS 1…
Architecture and Design Ensure that the design allows one cryptographic algorithm to be replaced with another in the next generation or version. Where possible, use wrappers to make the interfaces uniform. This will make it easier to upgrade to stronger algorithms. With hardware, design the product at the Intellectual Property (IP) level so that one cryptographic algorithm can be replaced with another in the next generat…
Effectiveness: Defense in Depth
Architecture and Design Carefully manage and protect cryptographic keys (see CWE-320). If the keys can be guessed or stolen, then the strength of the cryptography itself is irrelevant.
Architecture and Design Use a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid [REF-1482]. Industry-standard implementations will save development time and may be more likely to avoid errors that can occur during implementation of cryptographic algorithms. Consider the ESAPI Encryption feature.
Implementation, Architecture and Design When using industry-approved techniques, use them correctly. Don't cut corners by skipping resource-intensive steps (CWE-325). These steps are often essential for preventing common attacks.
代码示例 (2)
These code examples use the Data Encryption Standard (DES).
EVP_des_ecb();
Bad · C
Cipher des=Cipher.getInstance("DES..."); des.initEncrypt(key2);
Bad · Java
Suppose a chip manufacturer decides to implement a hashing scheme for verifying integrity property of certain bitstream, and it chooses to implement a SHA1 hardware accelerator for to implement the scheme.
The manufacturer chooses a SHA1 hardware accelerator for to implement the scheme because it already has a working SHA1 Intellectual Property (IP) that the manufacturer had created and used earlier, so this reuse of IP saves design cost.
Bad · Other
The manufacturer could have chosen a cryptographic solution that is recommended by the wide security community (including standard-setting bodies like NIST) and is not expected to be broken (or even better, weakened) within the reasonable life expectancy of the hardware product. In this case, the architects could have used SHA-2 or SHA-3, even if it meant that such choice would cost extra.
Good · Other
CVE ID 标题 CVSS 风险等级 Published
CVE-2026-18104 IBM Db2 Mirror for i 敏感信息泄露漏洞 — Db2 Mirror for i 3.3 Low 2026-09-24
CVE-2026-18153 IBM FTM 多个漏洞 — Financial Transaction Manager (FTM) for RedHat OpenShift 5.4 Medium 2026-09-22
CVE-2025-36084 IBM Concert 软件多个漏洞 — Concert 5.9 Medium 2026-09-22
CVE-2026-54147 http4k DigestAuthProvider算法及URI绑定漏洞 — http4k 6.5 Medium 2026-09-18
CVE-2025-33147 IBM Cognos Analytics 12.1.3 安全漏洞 — Cognos Analytics 5.9 Medium 2026-09-18
CVE-2024-56344 IBM Cognos Analytics 12.0.4/12.1.3 安全漏洞 — Cognos Analytics 5.9 Medium 2026-09-18
CVE-2026-81438 Dell OpenManage低于11.1.0.3弱加密算法漏洞 — Dell OpenManage Server Administrator Managed Node (Patch) for Windows 3.7 Low 2026-09-17
CVE-2025-36591 Dell ECS 3.8.1.x与ObjectScale 4.4.0前弱加密漏洞 — Elastic Cloud Storage (ECS) 4.4 Medium 2026-09-16
CVE-2026-15638 加密填充神谕漏洞 — Secret Server (On-Prem) 9.1 Critical 2026-09-15
CVE-2026-17467 IBM Cloud Pak for Data 系统漏洞 — Cloud Pak for Data System (Yosemite 1.0) 8.2 High 2026-09-14
CVE-2026-81822 AVEVA Pipeline Integrity Monitor 加密问题漏洞 — Pipeline Integrity Monitor 8.4 High 2026-09-08
CVE-2026-69382 Microsoft Exchange Server 加密问题漏洞 — Microsoft Exchange Server 2016 Cumulative Update 23 5.9 Medium 2026-09-08
CVE-2026-16693 IBM i 加密问题漏洞 — i 4.4 Medium 2026-09-04
CVE-2026-81859 IBM Cloud Pak for Business Automation 加密问题漏洞 — Cloud Pak for Business Automation 6.2 Medium 2026-09-04
CVE-2026-76133 Ebyte NA111-M 加密问题漏洞 — Ebyte NA111-M Firmware 9.8 Critical 2026-08-31
CVE-2026-39944 Ceph 加密问题漏洞 — ceph 8.8 High 2026-08-27
CVE-2025-30156 Ceph 加密问题漏洞 — ceph 8.9 High 2026-08-27
CVE-2026-77151 L1nSn0w Ech0 加密问题漏洞 — Ech0 3.7 Low 2026-08-20
CVE-2026-74888 jahlives openssl_encrypt 加密问题漏洞 — openssl_encrypt 7.5 High 2026-08-17
CVE-2026-48386 Adobe ColdFusion 2025 加密问题漏洞 — ColdFusion 2025 7.5 High 2026-08-11
CVE-2026-66407 Hellohas Robotics DEEBOT PRO M1 加密问题漏洞 — DEEBOT PRO M1 8.1 High 2026-08-10
CVE-2026-8470 IBM Langflow OSS 加密问题漏洞 — Langflow OSS 7.4 High 2026-08-05
CVE-2026-56609 HCL iControl 加密问题漏洞 — HCL iControl 4.8 Medium 2026-08-03
CVE-2026-67336 better-auth 加密问题漏洞 — better-auth 8.7 High 2026-08-01
CVE-2026-65309 ANDRITZ HIPASE-250 信任管理问题漏洞 — HIPASE-250 7.5 High 2026-07-31
CVE-2026-56582 HCL MyCloud 加密问题漏洞 — MyCloud 3.1 Low 2026-07-21
CVE-2026-63761 SurrealDB 加密问题漏洞 — surrealdb 4.3 Medium 2026-07-20
CVE-2026-56454 HCL DFXAnalytics 加密问题漏洞 — DFXAnalytics 5.9 Medium 2026-07-16
CVE-2026-54780 CoreWCF 加密问题漏洞 — CoreWCF 3.7 Low 2026-07-08
CVE-2026-57997 Strapi 加密问题漏洞 — strapi 4.8 Medium 2026-06-29

CWE-327(使用已被攻破或存在风险的密码学算法) 是常见的弱点类别,本平台收录该类弱点关联的 299 条 CVE 漏洞。