Weaknesses of type CWE-311

312 results

Ausência de criptografia de dados sensíveis

Quando dados sensíveis (senhas, tokens, PII, chaves) são transmitidos ou armazenados sem criptografia, qualquer pessoa com acesso à rede ou ao disco consegue lê-los diretamente. O risco é grave porque expõe informações críticas a interceptação ou roubo.

Example

Uma aplicação web envia credenciais de usuário em HTTP plano em vez de HTTPS, ou salva senhas em um arquivo de texto sem criptografar. Um atacante na mesma rede (ou com acesso ao servidor) captura as credenciais facilmente.

How to mitigate

Use HTTPS/TLS para toda transmissão de dados sensíveis, criptografe dados em repouso com algoritmos fortes (AES-256), implemente gestão segura de chaves e nunca armazene ou transmita dados sensíveis em claro. Revise logs e backups também.

CVE-2016-10578—unicode loads unicode data downloaded from unicode.org into nodejs. Unicode before 9.0.0 downloads binary resources over HTTP, which leaves EPSS 0.6%CVE-2019-13922—A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). An attacker with administrative privileges caEPSS 0.6%CVE-2024-35061HIGHNASA AIT-Core v2.5.2 was discovered to use unencrypted channels to exchange data over the network, allowing attackers to execute a man-in-thEPSS 0.6%CVE-2016-10630—install-g-test downloads resources over HTTP, which leaves it vulnerable to MITM attacks.EPSS 0.5%CVE-2016-10654—sfml downloads resources over HTTP, which leaves it vulnerable to MITM attacks.EPSS 0.5%CVE-2016-10619—pennyworth is a natural language templating engine. pennyworth downloads data resources over HTTP, which leaves it vulnerable to MITM attackEPSS 0.5%CVE-2016-10616—openframe-image is an Openframe extension which adds support for images via fbi. openframe-image downloads data resources over HTTP, which lEPSS 0.5%CVE-2016-10610—unicode-json is a unicode lookup table. unicode-json before 2.0.0 downloads data resources over HTTP, which leaves it vulnerable to MITM attEPSS 0.5%CVE-2016-10652—prebuild-lwip is a module for comprehensive, fast, and simple image processing and manipulation. prebuild-lwip downloads resources over HTTPEPSS 0.5%CVE-2016-10673—ipip-coffee queries geolocation information from IP ipip-coffee downloads geolocation resources over HTTP, which leaves it vulnerable to MITEPSS 0.5%CVE-2016-10552—igniteui 0.0.5 and earlier downloads JavaScript and CSS resources over insecure protocol.EPSS 0.5%CVE-2016-10597—cobalt-cli downloads resources over HTTP, which leaves it vulnerable to MITM attacks.EPSS 0.5%CVE-2023-38688HIGHtwitch-tui's connection is not encryptedEPSS 0.5%CVE-2020-10039—A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). An attackEPSS 0.5%CVE-2016-10613—bionode-sra is a Node.js wrapper for SRA Toolkit. bionode-sra downloads data resources over HTTP, which leaves it vulnerable to MITM attacksEPSS 0.5%CVE-2023-42019MEDIUMIBM InfoSphere Information Server information disclosureEPSS 0.5%CVE-2020-28216—A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Easergy T300 (firmware 2.7 and older), that would allow an attacker EPSS 0.5%CVE-2022-22405MEDIUMIBM Aspera Faspex information disclosureEPSS 0.5%CVE-2020-35168MEDIUMDell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable TimEPSS 0.5%CVE-2021-21963HIGHAn information disclosure vulnerability exists in the Web Server functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A speciallEPSS 0.5%