Weaknesses of type CWE-311
312 resultsAusência de criptografia de dados sensíveis
Quando dados sensíveis (senhas, tokens, PII, chaves) são transmitidos ou armazenados sem criptografia, qualquer pessoa com acesso à rede ou ao disco consegue lê-los diretamente. O risco é grave porque expõe informações críticas a interceptação ou roubo.
Example
Uma aplicação web envia credenciais de usuário em HTTP plano em vez de HTTPS, ou salva senhas em um arquivo de texto sem criptografar. Um atacante na mesma rede (ou com acesso ao servidor) captura as credenciais facilmente.
How to mitigate
Use HTTPS/TLS para toda transmissão de dados sensíveis, criptografe dados em repouso com algoritmos fortes (AES-256), implemente gestão segura de chaves e nunca armazene ou transmita dados sensíveis em claro. Revise logs e backups também.
CVE-2022-22386MEDIUMIBM Security Verify Privilege information disclosureEPSS 0.5%CVE-2022-22377MEDIUMIBM Security Verify Privilege information disclosureEPSS 0.5%CVE-2017-3219—Acronis True Image up to and including version 2017 Build 8053 performs software updates using HTTP. Downloaded updates are only verified usEPSS 0.5%CVE-2022-26390MEDIUMUnencrypted internal storage of security credentialsEPSS 0.5%CVE-2017-9632—A Missing Encryption of Sensitive Data issue was discovered in PDQ Manufacturing LaserWash G5 and G5 S Series all versions, LaserWash M5, alEPSS 0.5%CVE-2022-3781MEDIUMDashlane password and Keepass Server password in My Account Settings are not encrypted in the database in Devolutions Remote Desktop ManageEPSS 0.5%CVE-2025-69969CRITICALA lack of authentication and authorization mechanisms in the Bluetooth Low Energy (BLE) communication protocol of SRK Powertech Pvt Ltd PebbEPSS 0.5%CVE-2023-37858MEDIUMPHOENIX CONTACT: Use of Hard-coded Credentials in WP 6xxx Web panelsEPSS 0.5%CVE-2022-39014—Under certain conditions SAP BusinessObjects Business Intelligence Platform Central Management Console (CMC) - version 430, allows an attackEPSS 0.5%CVE-2021-39090MEDIUMIBM Cloud Pak for Security information disclosureEPSS 0.4%CVE-2023-39954LOWuser_oidc app stores client secret unencrypted in databaseEPSS 0.4%CVE-2023-22948MEDIUMAn issue was discovered in TigerGraph Enterprise Free Edition 3.x. There is unsecured read access to an SSH private key. Any code that runs EPSS 0.4%CVE-2023-33228MEDIUMSolarWinds Network Configuration Manager Sensitive Information Disclosure VulnerabilityEPSS 0.4%CVE-2021-28496MEDIUMIn Arista's EOS software affected releases, the shared secret profiles sensitive configuration might be leaked when displaying output over eAPI or other JSON outputs to authenticated users on the device.EPSS 0.4%CVE-2021-41302HIGHECOA BAS controller - Missing Encryption of Sensitive DataEPSS 0.4%CVE-2022-33161MEDIUMIBM Security Directory Server information disclosureEPSS 0.4%CVE-2023-4384LOWMaximaTech Portal Executivo Cookie missing encryptionEPSS 0.4%CVE-2021-40366—A vulnerability has been identified in Climatix POL909 (AWB module) (All versions < V11.42), Climatix POL909 (AWM module) (All versions < V1EPSS 0.4%CVE-2020-9057—Z-Wave devices based on Silicon Labs 100, 200, and 300 series chipsets do not support encryption, allowing an attacker within radio range toEPSS 0.4%CVE-2021-22932—An issue has been identified in the CTX269106 mitigation tool for Citrix ShareFile storage zones controller which causes the ShareFile file EPSS 0.4%