The number of possible random values is smaller than needed by the product, making it more susceptible to brute force attacks.
Volume of CVEs assigned to CWE-334 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-39979CRITICAL There is a vulnerability in MXsecurity versions prior to 1.0.1 that can be exploited to bypass authentication. A remote attacker might access the system if the web service authenti | Sep 2, 2023 | 9.8 | 28 | NO | NO |
CVE-2025-3895CRITICAL Token used for resetting passwords in MegaBIP software are generated using a small space of random values combined with a queryable value.
It allows an unauthenticated attacker wh | May 23, 2025 | 9.1 | 25 | NO | NO |
CVE-2021-21955HIGH An authentication bypass vulnerability exists in the get_aes_key_info_by_packetid() function of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h. Generic network sniffing | Dec 9, 2021 | 7.5 | 25 | NO | NO |
CVE-2024-6890HIGH Password reset tokens are generated using an insecure source of randomness. Attackers who know the username of the Journyx installation user can bruteforce the password reset and c | Aug 7, 2024 | 8.8 | 24 | NO | NO |
CVE-2020-7566HIGH A CWE-334: Small Space of Random Values vulnerability exists in Modicon M221 (all references, all versions) that could allow the attacker to break the encryption keys when the atta | Nov 19, 2020 | 7.3 | 24 | NO | NO |
CVE-2024-54017MEDIUM A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V11.0), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 6MD85 (CP300) (All versions >= V7.80 < V | May 12, 2026 | 5.3 | 23 | NO | NO |
CVE-2023-6951MEDIUM A Use of Weak Credentials vulnerability affecting the Wi-Fi network generated by a set of DJI drones could allow a remote attacker to derive the WPA2 PSK key and authenticate witho | Apr 2, 2024 | 6.6 | 22 | NO | NO |
CVE-2022-24402HIGH The TETRA TEA1 keystream generator implements a key register initialization function that compresses the 80-bit key to only 32 bits for usage during the keystream generation phase, | Oct 19, 2023 | 7.5 | 22 | NO | NO |
CVE-2022-22517HIGH An unauthenticated, remote attacker can disrupt existing communication channels between CODESYS products by guessing a valid channel ID and injecting packets. This results in the c | Apr 7, 2022 | 7.5 | 21 | NO | NO |
CVE-2022-20941MEDIUM A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to access sensitive inform | Nov 15, 2022 | 5.3 | 20 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.