Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CWE-320 (密钥管理错误) — Vulnerability Class 13

13 vulnerabilities classified as CWE-320 (密钥管理错误). AI Chinese analysis included.

This page aggregates vulnerability data specifically related to the Key Exposure after Initial TLS Connection weakness, classified under CWE-320. It collects security issues affecting various vendors and products where cryptographic keys remain accessible or improperly managed following the establishment of Transport Layer Security connections. The database covers historical records from the early 2000s through the present, capturing a wide spectrum of implementations across different industries. By centralizing these entries, the platform allows security professionals to track a specific vendor's advisories as they release patches for this distinct class of flaws. Researchers can utilize this resource to understand the broader patterns and recurring mistakes associated with CWE-320, facilitating better risk assessment and mitigation strategies. Additionally, users can look up a particular product's vulnerability history to see past instances of key exposure and evaluate the effectiveness of past remediation efforts. The collection includes details on affected software versions, disclosure dates, and potential impact scopes, providing a comprehensive view of how this weakness manifests in real-world environments. This structured approach helps organizations identify gaps in their cryptographic key management practices and prioritize fixes for exposures that could lead to data interception or unauthorized access. The content is strictly technical, focusing on factual reporting of known issues without speculative commentary.

CVE IDTitleCVSSSeverityPublished
CVE-2026-56254 capacitor-updater - End-to-End Encryption Bypass via Private Key Distribution — capacitor-updater 7.0 High2026-07-10
CVE-2026-32897 OpenClaw < 2026.2.22 - Authentication Token Reuse in Owner ID Prompt Hashing Fallback — OpenClaw 3.7 Low2026-03-21
CVE-2024-40593 Fortinet多款产品 加密问题漏洞 — FortiAnalyzer 5.9 Medium2025-12-11
CVE-2025-2220 Odyssey CMS reCAPTCHA odyssey_contact_form.php key management — CMS 3.3 Low2025-03-12
CVE-2024-36391 MileSight DeviceHub - CWE-320: Key Management Errors — DeviceHub 9.1 Critical2024-06-02
CVE-2023-21652 Key Management Errors in HLOS — Snapdragon 7.7 High2023-08-08
CVE-2023-21626 Improper Authentication in HLOS. — Snapdragon 7.1 High2023-08-08
CVE-2021-26322 AMD Secure Processor 安全特征问题漏洞 — 1st Gen AMD EPYC™ 7.5 -2021-11-16
CVE-2019-12621 Cisco HyperFlex Static SSL Key Vulnerability — Cisco HyperFlex HX-Series 7.4 -2019-08-21
CVE-2019-1586 Cisco Application Policy Infrastructure Controller Recoverable Encryption Key Vulnerability — Cisco Application Policy Infrastructure Controller (APIC) 4.6 -2019-05-03
CVE-2018-15397 Cisco Adaptive Security Appliance IPsec VPN Denial of Service Vulnerability — Cisco Adaptive Security Appliance (ASA) Software 5.9 -2018-10-05
CVE-2018-0124 Cisco Unified Communications Domain Manager 加密问题漏洞 — Cisco Unified Communications Domain Manager 9.8 -2018-02-22
CVE-2014-2361 OleumTech WIO Family Key Management Errors — WIO DH2 Wireless Gateway 5.7 -2014-07-24

Vulnerabilities classified as CWE-320 (密钥管理错误) represent 13 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.