The lack of entropy available for, or used by, a Pseudo-Random Number Generator (PRNG) can be a stability and security threat.
Volume of CVEs assigned to CWE-332 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-9057CRITICAL aws/resource_aws_iam_user_login_profile.go in the HashiCorp Terraform Amazon Web Services (AWS) provider through v1.12.0 has an inappropriate PRNG algorithm and seeding, which make | Mar 27, 2018 | 9.8 | 30 | NO | NO |
CVE-2026-3290HIGH Timing limitations of the HRNG in RS9116 when power save mode is enabled results in predictable values | May 14, 2026 | 7.4 | 26 | NO | NO |
CVE-2016-10743HIGH hostapd before 2.6 does not prevent use of the low-quality PRNG that is reached by an os_random() function call. | Mar 23, 2019 | 7.5 | 26 | NO | NO |
CVE-2023-20107HIGH A vulnerability in the deterministic random bit generator (DRBG), also known as pseudorandom number generator (PRNG), in Cisco Adaptive Security Appliance (ASA) Software and Cisco | Mar 23, 2023 | 7.5 | 25 | NO | NO |
CVE-2017-18486HIGH Jitbit Helpdesk before 9.0.3 allows remote attackers to escalate privileges because of mishandling of the User/AutoLogin userHash parameter. By inspecting the token value provided | Aug 9, 2019 | 7.2 | 24 | NO | NO |
CVE-2019-1715HIGH A vulnerability in the Deterministic Random Bit Generator (DRBG), also known as Pseudorandom Number Generator (PRNG), used in Cisco Adaptive Security Appliance (ASA) Software and C | May 3, 2019 | 7.5 | 24 | NO | NO |
CVE-2017-9371MEDIUM In BlackBerry QNX Software Development Platform (SDP) 6.6.0 and 6.5.0 SP1 and earlier, a loss of integrity vulnerability in the default configuration of the QNX SDP could allow an | Nov 14, 2017 | 5.9 | 20 | NO | NO |
CVE-2014-9690HIGH Huawei home gateways WS318 with software V100R001C01B022 and earlier versions are affected by the PIN offline brute force cracking vulnerability of the WPS protocol because the ran | Apr 2, 2017 | 7.5 | 19 | NO | NO |
CVE-2016-9154HIGH Siemens Desigo PX Web modules PXA40-W0, PXA40-W1, PXA40-W2 for Desigo PX automation controllers PXC00-E.D, PXC50-E.D, PXC100-E.D, PXC200-E.D (All firmware versions < V6.00.046) and | Dec 23, 2016 | 7.5 | 19 | NO | NO |
CVE-2014-0016MEDIUM stunnel before 5.00, when using fork threading, does not properly update the state of the OpenSSL pseudo-random number generator (PRNG), which causes subsequent children with the s | Mar 24, 2014 | 4.3 | 19 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.