Fallos del tipo CWE-311

312 resultados

Ausência de criptografia para dados sensíveis

A aplicação processa ou armazena dados sensíveis (senhas, tokens, dados financeiros, PII) sem aplicar criptografia. Isso expõe as informações a quem tiver acesso ao meio de transmissão ou armazenamento, permitindo roubo ou vazamento direto.

Ejemplo

Um servidor que salva tokens de autenticação em um arquivo de log em texto plano, ou uma API que trafega CPF e dados bancários via HTTP simples em vez de HTTPS. Um atacante monitora a rede ou acessa o servidor e recupera os dados.

Cómo mitigar

Sempre use HTTPS/TLS para transmissão de dados sensíveis, criptografe dados em repouso usando algoritmos reconhecidos (AES-256), e aplique criptografia end-to-end onde possível. Nunca deixe senhas ou tokens em logs ou cache sem proteção.

CVE-2022-47715MEDIUMIn Last Yard 22.09.8-1, the cookie can be stolen via via unencrypted traffic.EPSS 0.4%CVE-2023-33849LOWIBM CICS TX information disclosureEPSS 0.4%CVE-2021-27783MEDIUMHCL BigFix Mobile / Modern Client Management is vulnerable to sensitive information exposureEPSS 0.4%CVE-2025-65098HIGHTypebot Vulnerable to Credential Theft via Client-Side Script Execution and API Authorization BypassEPSS 0.3%CVE-2017-3218Samsung Magician 5.0 fails to validate TLS certificates for HTTPS software update traffic. Prior to version 5.0, Samsung Magician uses HTTP EPSS 0.3%CVE-2018-8849MEDIUMMedtronic N'Vision Clinician Programmer Missing Encryption of Sensitive DataEPSS 0.3%CVE-2023-30523MEDIUMJenkins Report Portal Plugin 0.5 and earlier stores ReportPortal access tokens unencrypted in job config.xml files on the Jenkins controllerEPSS 0.3%CVE-2024-29151CRITICALRocket.Chat.Audit through 5ad78e8 depends on filecachetools, which does not exist in PyPI.EPSS 0.3%CVE-2018-18984MEDIUMMedtronic 9790, 2090 CareLink, and 29901 Encore Programmers Missing Encryption of Sensitive DataEPSS 0.3%CVE-2023-35888MEDIUMIBM Security Verify Governance information disclosureEPSS 0.3%CVE-2022-38658HIGHHCL BigFix Server Automation (SA) is affected by a security vulnerability around Notification Service EPSS 0.3%CVE-2022-30237HIGHA CWE-311: Missing Encryption of Sensitive Data vulnerability exists that could allow authentication credentials to be recovered when an attEPSS 0.3%CVE-2021-32001MEDIUMK3s/RKE2 bootstrap data is encrypted with empty string if user does not supply a tokenEPSS 0.3%CVE-2020-9058Z-Wave devices based on Silicon Labs 500 series chipsets using CRC-16 encapsulation, including but likely not limited to the Linear LB60Z-1 EPSS 0.3%CVE-2024-42495HIGHHughes Network Systems WL3000 Missing Encryption of Sensitive DataEPSS 0.3%CVE-2023-38699CRITICALMindsDB 'Call to requests with verify=False disabling SSL certificate checks, security issue.' issueEPSS 0.3%CVE-2024-7396HIGHPlaintext CommunicationEPSS 0.3%CVE-2024-20515MEDIUMCisco Identity Services Engine Information Disclosure VulnerabilityEPSS 0.3%CVE-2014-2379Sensys Networks Traffic Sensor Missing Encryption of Sensitive DataEPSS 0.3%CVE-2017-14012Boston Scientific ZOOM LATITUDE PRM Model 3120 does not encrypt PHI at rest. CVSS v3 base score: 4.6; CVSS vector string: AV:P/AC:L/PR:N/UI:EPSS 0.3%