Weaknesses of type CWE-311
312 resultsAusência de criptografia de dados sensíveis
Quando dados sensíveis (senhas, tokens, PII, chaves) são transmitidos ou armazenados sem criptografia, qualquer pessoa com acesso à rede ou ao disco consegue lê-los diretamente. O risco é grave porque expõe informações críticas a interceptação ou roubo.
Example
Uma aplicação web envia credenciais de usuário em HTTP plano em vez de HTTPS, ou salva senhas em um arquivo de texto sem criptografar. Um atacante na mesma rede (ou com acesso ao servidor) captura as credenciais facilmente.
How to mitigate
Use HTTPS/TLS para toda transmissão de dados sensíveis, criptografe dados em repouso com algoritmos fortes (AES-256), implemente gestão segura de chaves e nunca armazene ou transmita dados sensíveis em claro. Revise logs e backups também.
CVE-2026-54784HIGHCoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentialityEPSS 0.3%CVE-2024-5731MEDIUMA vulnerability in the IPS Manager, Central Manager, and Local Manager communication workflow allows an attacker to control the destination EPSS 0.3%CVE-2022-31085MEDIUMMissing Encryption of Sensitive Data in ldap-account-managerEPSS 0.3%CVE-2024-28249MEDIUMCilium has possible unencrypted traffic between nodes when using IPsec and L7 policiesEPSS 0.3%CVE-2024-41124MEDIUMPuncia Cleartext Transmission of Sensitive Information via HTTP urls in `API_URLS`EPSS 0.3%CVE-2025-63579HIGHUnauthorized use of Kyocera printers, allows all information stored in the Kyocera address book to be exported. The security measure that enEPSS 0.3%CVE-2025-24008HIGHA vulnerability has been identified in SIRIUS 3RK3 Modular Safety System (MSS) (All versions), SIRIUS Safety Relays 3SK2 (All versions). TheEPSS 0.3%CVE-2024-38325MEDIUMIBM Storage Defender information disclosureEPSS 0.3%CVE-2017-12716—Abbott Laboratories Accent and Anthem pacemakers manufactured prior to Aug 28, 2017 transmit unencrypted patient information via RF communicEPSS 0.2%CVE-2025-64147MEDIUMJenkins Curseforge Publisher Plugin 1.0 does not mask API Keys displayed on the job configuration form, increasing the potential for attackeEPSS 0.2%CVE-2023-37405MEDIUMIBM Cloud Pak System information disclosureEPSS 0.2%CVE-2025-59325HIGHCPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to encrypt the initramfs contents, allowing for the offline recovery of secretsEPSS 0.2%CVE-2019-18254—BIOTRONIK CardioMessenger II, The affected products do not encrypt sensitive information while at rest. An attacker with physical access to EPSS 0.2%CVE-2025-36062MEDIUMIBM Cognos Analytics Mobile (iOS) information disclosureEPSS 0.2%CVE-2022-35860MEDIUMMissing AES encryption in Corsair K63 Wireless 3.1.3 allows physically proximate attackers to inject and sniff keystrokes via 2.4 GHz radio EPSS 0.2%CVE-2025-53663MEDIUMJenkins IBM Cloud DevOps Plugin 2.0.16 and earlier stores SonarQube authentication tokens unencrypted in job config.xml files on the JenkinsEPSS 0.2%CVE-2024-27106MEDIUMVulnerable data in transit in GE HealthCare EchoPAC productsEPSS 0.2%CVE-2025-53668MEDIUMJenkins VAddy Plugin 1.2.8 and earlier stores Vaddy API Auth Keys unencrypted in job config.xml files on the Jenkins controller, where they EPSS 0.2%CVE-2025-53666MEDIUMJenkins Dead Man's Snitch Plugin 0.1 stores Dead Man's Snitch tokens unencrypted in job config.xml files on the Jenkins controller, where thEPSS 0.2%CVE-2025-29314HIGHInsecure Shiro cookie configurations in OpenDaylight Service Function Chaining (SFC) Subproject SFC Sodium-SR4 and below allow attackers to EPSS 0.2%