Weaknesses of type CWE-311
312 resultsAusência de criptografia de dados sensíveis
Quando dados sensíveis (senhas, tokens, PII, chaves) são transmitidos ou armazenados sem criptografia, qualquer pessoa com acesso à rede ou ao disco consegue lê-los diretamente. O risco é grave porque expõe informações críticas a interceptação ou roubo.
Example
Uma aplicação web envia credenciais de usuário em HTTP plano em vez de HTTPS, ou salva senhas em um arquivo de texto sem criptografar. Um atacante na mesma rede (ou com acesso ao servidor) captura as credenciais facilmente.
How to mitigate
Use HTTPS/TLS para toda transmissão de dados sensíveis, criptografe dados em repouso com algoritmos fortes (AES-256), implemente gestão segura de chaves e nunca armazene ou transmita dados sensíveis em claro. Revise logs e backups também.
CVE-2022-47715MEDIUMIn Last Yard 22.09.8-1, the cookie can be stolen via via unencrypted traffic.EPSS 0.4%CVE-2023-33849LOWIBM CICS TX information disclosureEPSS 0.4%CVE-2021-27783MEDIUMHCL BigFix Mobile / Modern Client Management is vulnerable to sensitive information exposureEPSS 0.4%CVE-2025-65098HIGHTypebot Vulnerable to Credential Theft via Client-Side Script Execution and API Authorization BypassEPSS 0.3%CVE-2017-3218—Samsung Magician 5.0 fails to validate TLS certificates for HTTPS software update traffic. Prior to version 5.0, Samsung Magician uses HTTP EPSS 0.3%CVE-2018-8849MEDIUMMedtronic N'Vision Clinician Programmer Missing Encryption of Sensitive DataEPSS 0.3%CVE-2023-30523MEDIUMJenkins Report Portal Plugin 0.5 and earlier stores ReportPortal access tokens unencrypted in job config.xml files on the Jenkins controllerEPSS 0.3%CVE-2024-29151CRITICALRocket.Chat.Audit through 5ad78e8 depends on filecachetools, which does not exist in PyPI.EPSS 0.3%CVE-2023-35888MEDIUMIBM Security Verify Governance information disclosureEPSS 0.3%CVE-2018-18984MEDIUMMedtronic 9790, 2090 CareLink, and 29901 Encore Programmers Missing Encryption of Sensitive DataEPSS 0.3%CVE-2022-38658HIGHHCL BigFix Server Automation (SA) is affected by a security vulnerability around Notification Service EPSS 0.3%CVE-2022-30237HIGHA CWE-311: Missing Encryption of Sensitive Data vulnerability exists that could allow authentication credentials to be recovered when an attEPSS 0.3%CVE-2021-32001MEDIUMK3s/RKE2 bootstrap data is encrypted with empty string if user does not supply a tokenEPSS 0.3%CVE-2020-9058—Z-Wave devices based on Silicon Labs 500 series chipsets using CRC-16 encapsulation, including but likely not limited to the Linear LB60Z-1 EPSS 0.3%CVE-2024-42495HIGHHughes Network Systems WL3000 Missing Encryption of Sensitive DataEPSS 0.3%CVE-2023-38699CRITICALMindsDB 'Call to requests with verify=False disabling SSL certificate checks, security issue.' issueEPSS 0.3%CVE-2024-7396HIGHPlaintext CommunicationEPSS 0.3%CVE-2024-20515MEDIUMCisco Identity Services Engine Information Disclosure VulnerabilityEPSS 0.3%CVE-2014-2379—Sensys Networks Traffic Sensor Missing Encryption of Sensitive DataEPSS 0.3%CVE-2017-14012—Boston Scientific ZOOM LATITUDE PRM Model 3120 does not encrypt PHI at rest. CVSS v3 base score: 4.6; CVSS vector string: AV:P/AC:L/PR:N/UI:EPSS 0.3%