Fallos del tipo CWE-311
312 resultadosAusência de criptografia para dados sensíveis
A aplicação processa ou armazena dados sensíveis (senhas, tokens, dados financeiros, PII) sem aplicar criptografia. Isso expõe as informações a quem tiver acesso ao meio de transmissão ou armazenamento, permitindo roubo ou vazamento direto.
Ejemplo
Um servidor que salva tokens de autenticação em um arquivo de log em texto plano, ou uma API que trafega CPF e dados bancários via HTTP simples em vez de HTTPS. Um atacante monitora a rede ou acessa o servidor e recupera os dados.
Cómo mitigar
Sempre use HTTPS/TLS para transmissão de dados sensíveis, criptografe dados em repouso usando algoritmos reconhecidos (AES-256), e aplique criptografia end-to-end onde possível. Nunca deixe senhas ou tokens em logs ou cache sem proteção.
CVE-2022-22386MEDIUMIBM Security Verify Privilege information disclosureEPSS 0.5%CVE-2022-22377MEDIUMIBM Security Verify Privilege information disclosureEPSS 0.5%CVE-2022-26390MEDIUMUnencrypted internal storage of security credentialsEPSS 0.5%CVE-2017-3219—Acronis True Image up to and including version 2017 Build 8053 performs software updates using HTTP. Downloaded updates are only verified usEPSS 0.5%CVE-2017-9632—A Missing Encryption of Sensitive Data issue was discovered in PDQ Manufacturing LaserWash G5 and G5 S Series all versions, LaserWash M5, alEPSS 0.5%CVE-2022-3781MEDIUMDashlane password and Keepass Server password in My Account Settings are not encrypted in the database in Devolutions Remote Desktop ManageEPSS 0.5%CVE-2025-69969CRITICALA lack of authentication and authorization mechanisms in the Bluetooth Low Energy (BLE) communication protocol of SRK Powertech Pvt Ltd PebbEPSS 0.5%CVE-2023-37858MEDIUMPHOENIX CONTACT: Use of Hard-coded Credentials in WP 6xxx Web panelsEPSS 0.5%CVE-2022-39014—Under certain conditions SAP BusinessObjects Business Intelligence Platform Central Management Console (CMC) - version 430, allows an attackEPSS 0.5%CVE-2021-39090MEDIUMIBM Cloud Pak for Security information disclosureEPSS 0.4%CVE-2023-39954LOWuser_oidc app stores client secret unencrypted in databaseEPSS 0.4%CVE-2023-22948MEDIUMAn issue was discovered in TigerGraph Enterprise Free Edition 3.x. There is unsecured read access to an SSH private key. Any code that runs EPSS 0.4%CVE-2023-33228MEDIUMSolarWinds Network Configuration Manager Sensitive Information Disclosure VulnerabilityEPSS 0.4%CVE-2021-28496MEDIUMIn Arista's EOS software affected releases, the shared secret profiles sensitive configuration might be leaked when displaying output over eAPI or other JSON outputs to authenticated users on the device.EPSS 0.4%CVE-2021-41302HIGHECOA BAS controller - Missing Encryption of Sensitive DataEPSS 0.4%CVE-2022-33161MEDIUMIBM Security Directory Server information disclosureEPSS 0.4%CVE-2023-4384LOWMaximaTech Portal Executivo Cookie missing encryptionEPSS 0.4%CVE-2021-40366—A vulnerability has been identified in Climatix POL909 (AWB module) (All versions < V11.42), Climatix POL909 (AWM module) (All versions < V1EPSS 0.4%CVE-2020-9057—Z-Wave devices based on Silicon Labs 100, 200, and 300 series chipsets do not support encryption, allowing an attacker within radio range toEPSS 0.4%CVE-2021-22932—An issue has been identified in the CTX269106 mitigation tool for Citrix ShareFile storage zones controller which causes the ShareFile file EPSS 0.4%