Fallos del tipo CWE-311
312 resultadosAusência de criptografia para dados sensíveis
A aplicação processa ou armazena dados sensíveis (senhas, tokens, dados financeiros, PII) sem aplicar criptografia. Isso expõe as informações a quem tiver acesso ao meio de transmissão ou armazenamento, permitindo roubo ou vazamento direto.
Ejemplo
Um servidor que salva tokens de autenticação em um arquivo de log em texto plano, ou uma API que trafega CPF e dados bancários via HTTP simples em vez de HTTPS. Um atacante monitora a rede ou acessa o servidor e recupera os dados.
Cómo mitigar
Sempre use HTTPS/TLS para transmissão de dados sensíveis, criptografe dados em repouso usando algoritmos reconhecidos (AES-256), e aplique criptografia end-to-end onde possível. Nunca deixe senhas ou tokens em logs ou cache sem proteção.
CVE-2023-52948MEDIUMMissing encryption of sensitive data vulnerability in settings functionality in Synology Active Backup for Business Agent before 2.7.0-3221 EPSS 0.1%CVE-2023-52950MEDIUMMissing encryption of sensitive data vulnerability in login component in Synology Active Backup for Business Agent before 2.7.0-3221 allows EPSS 0.1%CVE-2024-41982MEDIUMA vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Audit (All versions >=EPSS 0.1%CVE-2025-10227MEDIUMLack of Encryption in Object Archive in AxxonSoft Axxon One (C-Werk) before 2.0.8EPSS 0.1%CVE-2025-40680MEDIUMEncryption of sensitive data in CapillaryScope missingEPSS 0.1%CVE-2025-36751CRITICALMissing encryption on Local Configuration Interface or Cloud Endpoint Communication - Growatt MIC3300TL-X and ShineLan-XEPSS 0.1%CVE-2025-15548MEDIUMMissing Application-Layer Encryption in Web Interface Endpoints on TP-Link VX800vEPSS 0.1%CVE-2026-21079HIGHMissing encryption of sensitive data in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to intercept transmitted data.EPSS 0.1%CVE-2026-77812CRITICALCleartext Exposure of DJI Drone Wi-Fi Credentials via BLEEPSS 0.1%CVE-2026-92756MEDIUMCombining encryption settings may disable encryptionEPSS 0.1%CVE-2026-92757MEDIUMMalformed connection string may disable field level encryptionEPSS 0.1%CVE-2025-15065HIGHData Exposure in Kings Information & Network KESS EnterpriseEPSS 0.1%