Cyber Resilience

CWE · MITRE source

CWE-326Inadequate Encryption Strength

Abstraction: Class · CVEs in our corpus: 461

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

A weak encryption scheme can be subjected to brute force attacks that have a reasonable chance of succeeding using current attack methods and resources.

Last updated: 20 August 2026 13:14 UTC

Cumulative inbound coverage

How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.

Collective: mostly · 6 mapping(s) from 5 framework(s): CAPEC 2 (partial) · STIG oracle linux 9 1 (mostly) · STIG rhel 8 1 (mostly) · STIG rhel 9 1 (partial) · STIG windows server 2016 1 (partial)

See the full cumulative-coverage rollup →

OWASP Top 10 for Web (2025)

This weakness contributes to A04:2025 Cryptographic Failures.

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • SC-12 Cryptographic Key Establishment and Management
  • SC-13 Cryptographic Protection
  • PM-15 Security and Privacy Groups and Associations
  • RA-4 Risk Assessment Update
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)
  • 14 hardening rules · 7 OS baselines
Validate
Prove the fix (OWASP ASVS)
  • V11.4.2
  • V14.1.2
  • V14.2.4

NIST 800-53 r5 controls that address this weakness (5)AI-assisted

Control Title Family Why it addresses this CWE
SC-12Cryptographic Key Establishment and ManagementSCEstablishment procedures require selection and generation of keys with adequate length and strength for the chosen algorithm.
SC-13Cryptographic ProtectionSCSpecifies required cryptography types and parameters, preventing selection of inadequate encryption strength.
PM-15Security and Privacy Groups and AssociationsPMMaintaining currency with technologies and practices reduces selection of encryption mechanisms that provide inadequate strength.
RA-4Risk Assessment UpdateRAUpdated assessments identify when previously adequate encryption strength no longer meets current attack capabilities or compliance drivers.
SI-2Flaw RemediationSIPrompt patching corrects inadequate encryption strength when vendors release updates that increase key sizes or algorithm security.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2017-11317 KEV 9.99.80.83482017-08-23
CVE-2017-1000486 KEV 9.99.80.94102018-01-03
CVE-2018-15811 KEV 8.57.50.74052019-07-03
CVE-2018-18325 KEV 8.57.50.74052019-07-03
CVE-2014-0224 8.37.40.95332014-06-05
CVE-2017-7903 7.89.80.02762017-06-30
CVE-2020-6966 7.810.00.02222020-01-24
CVE-2018-7242 7.79.80.01952018-04-18
CVE-2018-0448 7.79.80.02142018-10-05
CVE-2011-4121 7.79.80.02532019-11-26
CVE-2013-2166 7.79.80.02152019-12-10
CVE-2017-7905 7.69.80.01282017-06-30
CVE-2017-7673 7.69.80.01652017-07-17
CVE-2018-20810 7.69.80.01772019-06-28
CVE-2013-7287 7.69.80.01432020-02-13
CVE-2016-5804 7.59.80.01122016-07-15
CVE-2017-8076 7.59.80.00902017-04-23
CVE-2017-7888 7.59.80.01072017-05-10
CVE-2018-15124 7.59.80.01072018-08-13
CVE-2019-10907 7.59.80.00922019-04-07
CVE-2019-15805 7.59.80.01192019-08-29
CVE-2019-15806 7.59.80.01192019-08-29
CVE-2019-16649 7.510.00.00922019-09-21
CVE-2020-10275 7.59.80.00962020-06-24
CVE-2021-42216 7.59.80.01162021-12-15