Falhas do tipo CWE-311

312 resultados

Falta de criptografia de dados sensíveis

A aplicação transmite ou armazena dados sensíveis (senhas, tokens, dados pessoais, números de cartão) em texto plano, sem criptografia. Um atacante que intercepte a comunicação ou acesse o armazenamento consegue ler essas informações diretamente, comprometendo confidencialidade e segurança do usuário.

Exemplo

Um aplicativo mobile envia credenciais de login via HTTP em vez de HTTPS, ou salva senhas em um arquivo de configuração sem criptografia. Um atacante na mesma rede Wi-Fi ou com acesso ao dispositivo rouba as credenciais facilmente.

Como mitigar

Use HTTPS/TLS para toda comunicação de dados sensíveis, criptografe dados em repouso com algoritmos fortes (AES-256), e nunca armazene senhas em texto plano — use hash com salt (bcrypt, argon2). Aplique essas práticas no design, não como remendo.

CVE-2026-54784HIGHCoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentialityEPSS 0.3%CVE-2024-5731MEDIUMA vulnerability in the IPS Manager, Central Manager, and Local Manager communication workflow allows an attacker to control the destination EPSS 0.3%CVE-2022-31085MEDIUMMissing Encryption of Sensitive Data in ldap-account-managerEPSS 0.3%CVE-2024-28249MEDIUMCilium has possible unencrypted traffic between nodes when using IPsec and L7 policiesEPSS 0.3%CVE-2024-41124MEDIUMPuncia Cleartext Transmission of Sensitive Information via HTTP urls in `API_URLS`EPSS 0.3%CVE-2025-63579HIGHUnauthorized use of Kyocera printers, allows all information stored in the Kyocera address book to be exported. The security measure that enEPSS 0.3%CVE-2025-24008HIGHA vulnerability has been identified in SIRIUS 3RK3 Modular Safety System (MSS) (All versions), SIRIUS Safety Relays 3SK2 (All versions). TheEPSS 0.3%CVE-2024-38325MEDIUMIBM Storage Defender information disclosureEPSS 0.3%CVE-2017-12716Abbott Laboratories Accent and Anthem pacemakers manufactured prior to Aug 28, 2017 transmit unencrypted patient information via RF communicEPSS 0.2%CVE-2025-64147MEDIUMJenkins Curseforge Publisher Plugin 1.0 does not mask API Keys displayed on the job configuration form, increasing the potential for attackeEPSS 0.2%CVE-2023-37405MEDIUMIBM Cloud Pak System information disclosureEPSS 0.2%CVE-2025-59325HIGHCPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to encrypt the initramfs contents, allowing for the offline recovery of secretsEPSS 0.2%CVE-2019-18254BIOTRONIK CardioMessenger II, The affected products do not encrypt sensitive information while at rest. An attacker with physical access to EPSS 0.2%CVE-2025-36062MEDIUMIBM Cognos Analytics Mobile (iOS) information disclosureEPSS 0.2%CVE-2022-35860MEDIUMMissing AES encryption in Corsair K63 Wireless 3.1.3 allows physically proximate attackers to inject and sniff keystrokes via 2.4 GHz radio EPSS 0.2%CVE-2025-53663MEDIUMJenkins IBM Cloud DevOps Plugin 2.0.16 and earlier stores SonarQube authentication tokens unencrypted in job config.xml files on the JenkinsEPSS 0.2%CVE-2024-27106MEDIUMVulnerable data in transit in GE HealthCare EchoPAC productsEPSS 0.2%CVE-2025-53668MEDIUMJenkins VAddy Plugin 1.2.8 and earlier stores Vaddy API Auth Keys unencrypted in job config.xml files on the Jenkins controller, where they EPSS 0.2%CVE-2025-53666MEDIUMJenkins Dead Man's Snitch Plugin 0.1 stores Dead Man's Snitch tokens unencrypted in job config.xml files on the Jenkins controller, where thEPSS 0.2%CVE-2025-53659MEDIUMJenkins QMetry Test Management Plugin 1.13 and earlier stores Qmetry Automation API Keys unencrypted in job config.xml files on the Jenkins EPSS 0.2%