Falhas do tipo CWE-311

312 resultados

Falta de criptografia de dados sensíveis

A aplicação transmite ou armazena dados sensíveis (senhas, tokens, dados pessoais, números de cartão) em texto plano, sem criptografia. Um atacante que intercepte a comunicação ou acesse o armazenamento consegue ler essas informações diretamente, comprometendo confidencialidade e segurança do usuário.

Exemplo

Um aplicativo mobile envia credenciais de login via HTTP em vez de HTTPS, ou salva senhas em um arquivo de configuração sem criptografia. Um atacante na mesma rede Wi-Fi ou com acesso ao dispositivo rouba as credenciais facilmente.

Como mitigar

Use HTTPS/TLS para toda comunicação de dados sensíveis, criptografe dados em repouso com algoritmos fortes (AES-256), e nunca armazene senhas em texto plano — use hash com salt (bcrypt, argon2). Aplique essas práticas no design, não como remendo.

CVE-2022-47715MEDIUMIn Last Yard 22.09.8-1, the cookie can be stolen via via unencrypted traffic.EPSS 0.4%CVE-2023-33849LOWIBM CICS TX information disclosureEPSS 0.4%CVE-2021-27783MEDIUMHCL BigFix Mobile / Modern Client Management is vulnerable to sensitive information exposureEPSS 0.4%CVE-2025-65098HIGHTypebot Vulnerable to Credential Theft via Client-Side Script Execution and API Authorization BypassEPSS 0.3%CVE-2017-3218Samsung Magician 5.0 fails to validate TLS certificates for HTTPS software update traffic. Prior to version 5.0, Samsung Magician uses HTTP EPSS 0.3%CVE-2018-8849MEDIUMMedtronic N'Vision Clinician Programmer Missing Encryption of Sensitive DataEPSS 0.3%CVE-2023-30523MEDIUMJenkins Report Portal Plugin 0.5 and earlier stores ReportPortal access tokens unencrypted in job config.xml files on the Jenkins controllerEPSS 0.3%CVE-2024-29151CRITICALRocket.Chat.Audit through 5ad78e8 depends on filecachetools, which does not exist in PyPI.EPSS 0.3%CVE-2018-18984MEDIUMMedtronic 9790, 2090 CareLink, and 29901 Encore Programmers Missing Encryption of Sensitive DataEPSS 0.3%CVE-2023-35888MEDIUMIBM Security Verify Governance information disclosureEPSS 0.3%CVE-2022-38658HIGHHCL BigFix Server Automation (SA) is affected by a security vulnerability around Notification Service EPSS 0.3%CVE-2022-30237HIGHA CWE-311: Missing Encryption of Sensitive Data vulnerability exists that could allow authentication credentials to be recovered when an attEPSS 0.3%CVE-2021-32001MEDIUMK3s/RKE2 bootstrap data is encrypted with empty string if user does not supply a tokenEPSS 0.3%CVE-2020-9058Z-Wave devices based on Silicon Labs 500 series chipsets using CRC-16 encapsulation, including but likely not limited to the Linear LB60Z-1 EPSS 0.3%CVE-2024-42495HIGHHughes Network Systems WL3000 Missing Encryption of Sensitive DataEPSS 0.3%CVE-2023-38699CRITICALMindsDB 'Call to requests with verify=False disabling SSL certificate checks, security issue.' issueEPSS 0.3%CVE-2024-7396HIGHPlaintext CommunicationEPSS 0.3%CVE-2024-20515MEDIUMCisco Identity Services Engine Information Disclosure VulnerabilityEPSS 0.3%CVE-2014-2379Sensys Networks Traffic Sensor Missing Encryption of Sensitive DataEPSS 0.3%CVE-2017-14012Boston Scientific ZOOM LATITUDE PRM Model 3120 does not encrypt PHI at rest. CVSS v3 base score: 4.6; CVSS vector string: AV:P/AC:L/PR:N/UI:EPSS 0.3%