Cyber Posture

CWE · MITRE source

CWE-326Inadequate Encryption Strength

Abstraction: Class · CVEs in our corpus: 442

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

A weak encryption scheme can be subjected to brute force attacks that have a reasonable chance of succeeding using current attack methods and resources.

Last updated: 09 May 2026 03:25 UTC

NIST 800-53 r5 controls that address this weakness (5)AI

Control Title Family Why it addresses this CWE
SC-12Cryptographic Key Establishment and ManagementSCEstablishment procedures require selection and generation of keys with adequate length and strength for the chosen algorithm.
SC-13Cryptographic ProtectionSCSpecifies required cryptography types and parameters, preventing selection of inadequate encryption strength.
PM-15Security and Privacy Groups and AssociationsPMMaintaining currency with technologies and practices reduces selection of encryption mechanisms that provide inadequate strength.
RA-4Risk Assessment UpdateRAUpdated assessments identify when previously adequate encryption strength no longer meets current attack capabilities or compliance drivers.
SI-2Flaw RemediationSIPrompt patching corrects inadequate encryption strength when vendors release updates that increase key sizes or algorithm security.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2017-1000486 KEV9.69.80.93642018-01-03
CVE-2017-11317 KEV9.59.80.91972017-08-23
CVE-2018-15811 KEV9.17.50.93002019-07-03
CVE-2018-18325 KEV9.17.50.92962019-07-03
CVE-2014-02246.97.40.89692014-06-05
CVE-2013-25666.65.90.90762013-03-15
CVE-2017-142622.98.10.21022017-09-11
CVE-2024-523172.66.50.21072024-11-18
CVE-2024-368232.27.50.11822024-06-06
CVE-2018-208102.19.80.01542019-06-28
CVE-2024-523182.16.10.15472024-11-18
CVE-2016-58042.09.80.00182016-07-15
CVE-2017-80762.09.80.00422017-04-23
CVE-2017-78882.09.80.00162017-05-10
CVE-2017-79032.09.80.00232017-06-30
CVE-2017-79052.09.80.00202017-06-30
CVE-2017-76732.09.80.00402017-07-17
CVE-2014-99752.09.80.00032017-08-18
CVE-2015-05752.09.80.00062017-08-18
CVE-2018-72422.09.80.00252018-04-18
CVE-2018-151242.09.80.00352018-08-13
CVE-2018-04482.09.80.01082018-10-05
CVE-2019-109072.09.80.00162019-04-07
CVE-2019-158052.09.80.00232019-08-29
CVE-2019-158062.09.80.00232019-08-29