Fallos del tipo CWE-311
312 resultadosAusência de criptografia para dados sensíveis
A aplicação processa ou armazena dados sensíveis (senhas, tokens, dados financeiros, PII) sem aplicar criptografia. Isso expõe as informações a quem tiver acesso ao meio de transmissão ou armazenamento, permitindo roubo ou vazamento direto.
Ejemplo
Um servidor que salva tokens de autenticação em um arquivo de log em texto plano, ou uma API que trafega CPF e dados bancários via HTTP simples em vez de HTTPS. Um atacante monitora a rede ou acessa o servidor e recupera os dados.
Cómo mitigar
Sempre use HTTPS/TLS para transmissão de dados sensíveis, criptografe dados em repouso usando algoritmos reconhecidos (AES-256), e aplique criptografia end-to-end onde possível. Nunca deixe senhas ou tokens em logs ou cache sem proteção.
CVE-2016-10578—unicode loads unicode data downloaded from unicode.org into nodejs. Unicode before 9.0.0 downloads binary resources over HTTP, which leaves EPSS 0.6%CVE-2019-13922—A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). An attacker with administrative privileges caEPSS 0.6%CVE-2024-35061HIGHNASA AIT-Core v2.5.2 was discovered to use unencrypted channels to exchange data over the network, allowing attackers to execute a man-in-thEPSS 0.6%CVE-2016-10630—install-g-test downloads resources over HTTP, which leaves it vulnerable to MITM attacks.EPSS 0.5%CVE-2016-10652—prebuild-lwip is a module for comprehensive, fast, and simple image processing and manipulation. prebuild-lwip downloads resources over HTTPEPSS 0.5%CVE-2016-10610—unicode-json is a unicode lookup table. unicode-json before 2.0.0 downloads data resources over HTTP, which leaves it vulnerable to MITM attEPSS 0.5%CVE-2016-10654—sfml downloads resources over HTTP, which leaves it vulnerable to MITM attacks.EPSS 0.5%CVE-2016-10673—ipip-coffee queries geolocation information from IP ipip-coffee downloads geolocation resources over HTTP, which leaves it vulnerable to MITEPSS 0.5%CVE-2016-10616—openframe-image is an Openframe extension which adds support for images via fbi. openframe-image downloads data resources over HTTP, which lEPSS 0.5%CVE-2016-10619—pennyworth is a natural language templating engine. pennyworth downloads data resources over HTTP, which leaves it vulnerable to MITM attackEPSS 0.5%CVE-2016-10552—igniteui 0.0.5 and earlier downloads JavaScript and CSS resources over insecure protocol.EPSS 0.5%CVE-2016-10597—cobalt-cli downloads resources over HTTP, which leaves it vulnerable to MITM attacks.EPSS 0.5%CVE-2023-38688HIGHtwitch-tui's connection is not encryptedEPSS 0.5%CVE-2020-10039—A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). An attackEPSS 0.5%CVE-2016-10613—bionode-sra is a Node.js wrapper for SRA Toolkit. bionode-sra downloads data resources over HTTP, which leaves it vulnerable to MITM attacksEPSS 0.5%CVE-2023-42019MEDIUMIBM InfoSphere Information Server information disclosureEPSS 0.5%CVE-2020-28216—A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Easergy T300 (firmware 2.7 and older), that would allow an attacker EPSS 0.5%CVE-2022-22405MEDIUMIBM Aspera Faspex information disclosureEPSS 0.5%CVE-2020-35168MEDIUMDell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable TimEPSS 0.5%CVE-2021-21963HIGHAn information disclosure vulnerability exists in the Web Server functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A speciallEPSS 0.5%