Weaknesses of type CWE-311
312 resultsAusência de criptografia de dados sensíveis
Quando dados sensíveis (senhas, tokens, PII, chaves) são transmitidos ou armazenados sem criptografia, qualquer pessoa com acesso à rede ou ao disco consegue lê-los diretamente. O risco é grave porque expõe informações críticas a interceptação ou roubo.
Example
Uma aplicação web envia credenciais de usuário em HTTP plano em vez de HTTPS, ou salva senhas em um arquivo de texto sem criptografar. Um atacante na mesma rede (ou com acesso ao servidor) captura as credenciais facilmente.
How to mitigate
Use HTTPS/TLS para toda transmissão de dados sensíveis, criptografe dados em repouso com algoritmos fortes (AES-256), implemente gestão segura de chaves e nunca armazene ou transmita dados sensíveis em claro. Revise logs e backups também.
CVE-2023-52948MEDIUMMissing encryption of sensitive data vulnerability in settings functionality in Synology Active Backup for Business Agent before 2.7.0-3221 EPSS 0.1%CVE-2023-52950MEDIUMMissing encryption of sensitive data vulnerability in login component in Synology Active Backup for Business Agent before 2.7.0-3221 allows EPSS 0.1%CVE-2024-41982MEDIUMA vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Audit (All versions >=EPSS 0.1%CVE-2025-10227MEDIUMLack of Encryption in Object Archive in AxxonSoft Axxon One (C-Werk) before 2.0.8EPSS 0.1%CVE-2025-40680MEDIUMEncryption of sensitive data in CapillaryScope missingEPSS 0.1%CVE-2025-36751CRITICALMissing encryption on Local Configuration Interface or Cloud Endpoint Communication - Growatt MIC3300TL-X and ShineLan-XEPSS 0.1%CVE-2025-15548MEDIUMMissing Application-Layer Encryption in Web Interface Endpoints on TP-Link VX800vEPSS 0.1%CVE-2026-21079HIGHMissing encryption of sensitive data in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to intercept transmitted data.EPSS 0.1%CVE-2026-77812CRITICALCleartext Exposure of DJI Drone Wi-Fi Credentials via BLEEPSS 0.1%CVE-2026-92756MEDIUMCombining encryption settings may disable encryptionEPSS 0.1%CVE-2026-92757MEDIUMMalformed connection string may disable field level encryptionEPSS 0.1%CVE-2025-15065HIGHData Exposure in Kings Information & Network KESS EnterpriseEPSS 0.1%