The software stores or transmits sensitive data using an
encryption scheme that is theoretically sound, but is not strong enough for the
level of protection required.
Extended Description
A weak encryption scheme can be subjected to brute force attacks that have
a reasonable chance of succeeding using current attack methods and
resources.
Time of Introduction
Architecture and Design
Applicable Platforms
Languages
All
Common Consequences
Scope
Effect
Confidentiality
An attacker may be able to decrypt the data using brute force
attacks.