CWE-1240Base

Use of a Cryptographic Primitive with a Risky Implementation

Draft in the CWE catalog · 22 CVEs mapped

22
CVEs mapped
6.1
Median CVSS
What it is

To fulfill the need for a cryptographic primitive, the product implements a cryptographic algorithm using a non-standard, unproven, or disallowed/non-compliant cryptographic implementation.

Recent examples
7.4cvss
CVE-2026-21751

CVE-2026-21751 - HIGH Severity Vulnerability

HCL Hive is affected by a cryptographic primitive with a risky implementation which could allow an attacker unauthorized lateral compromise or widespread credential leakage if a single internal component is breached.

HIGHno explanation yet
0%
epss
5.3cvss
CVE-2025-68833

CVE-2025-68833 - MEDIUM Severity Vulnerability

HCL Hive Keycloak IAM Instance is affected by insufficient granularity of access control which could allow an attacker unauthorized access to resources.

MEDIUMno explanation yet
0%
epss
5.5cvss
CVE-2026-50303

Windows Key Guard Security Feature Bypass Vulnerability

Use of a cryptographic primitive with a risky implementation in Windows Key Guard allows an authorized attacker to bypass a security feature locally.

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-1240
Abstraction
Base
Structure
Simple
Status
Draft
References (4)