CWE-331Base

Insufficient Entropy

Draft in the CWE catalog · 85 CVEs mapped

85
CVEs mapped
7.1
Median CVSS
What it is

The product uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.

Recent examples
7.5cvss
CVE-2026-27490

CVE-2026-27490 - HIGH Severity Vulnerability

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, inline images that are accessible without being authenticated are protected by a weak 24-bit pseudo-random secret. This issue has been fixed in version 3.2.3.

HIGHno explanation yet
0%
epss
5.3cvss
CVE-2026-4937

CVE-2026-4937 - MEDIUM Severity Vulnerability

IBM PowerVM Hypervisor FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H2 could allow a local attacker with administrative privileges to decrypt encrypted data due to certain hypervisor calls utilizing less entropy than requested.

MEDIUMno explanation yet
0%
epss
5.1cvss
CVE-2026-4936

CVE-2026-4936 - MEDIUM Severity Vulnerability

IBM PowerVM Hypervisor Platform KeyStore (PKS) and virtual TPM FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H2 use persistent storage key seeds that result in an AES key with reduced strength. An attacker with access to the service processor or HMC could exploit this weakness to derive the encryption key and access the data.

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-331
Abstraction
Base
Structure
Simple
Status
Draft