CWE-334: Small Space of Random Values
The number of possible random values is smaller than needed by the product, making it more susceptible to brute force attacks.
14 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-3895 — Low token entropy in MegaBIP
- CVE-2026-71851 — crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain
- CVE-2024-54017 — A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V11.0), SIPROTEC 5 6MD85 (CP200) (All ve
- CVE-2024-51720 — Vulnerabilities in SecuSUITE Server Components Impact SecuSUITE
- CVE-2024-52616 — Avahi: avahi wide-area dns predictable transaction ids
Recently published
- CVE-2026-71851 — crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain
- CVE-2024-54017 — A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V11.0), SIPROTEC 5 6MD85 (CP200) (All ve
- CVE-2025-3895 — Low token entropy in MegaBIP
- CVE-2024-52616 — Avahi: avahi wide-area dns predictable transaction ids
- CVE-2024-51720 — Vulnerabilities in SecuSUITE Server Components Impact SecuSUITE
More specific weaknesses
- CWE-6 — J2EE Misconfiguration: Insufficient Session-ID Length