Falhas do tipo CWE-311

312 resultados

Falta de criptografia de dados sensíveis

A aplicação transmite ou armazena dados sensíveis (senhas, tokens, dados pessoais, números de cartão) em texto plano, sem criptografia. Um atacante que intercepte a comunicação ou acesse o armazenamento consegue ler essas informações diretamente, comprometendo confidencialidade e segurança do usuário.

Exemplo

Um aplicativo mobile envia credenciais de login via HTTP em vez de HTTPS, ou salva senhas em um arquivo de configuração sem criptografia. Um atacante na mesma rede Wi-Fi ou com acesso ao dispositivo rouba as credenciais facilmente.

Como mitigar

Use HTTPS/TLS para toda comunicação de dados sensíveis, criptografe dados em repouso com algoritmos fortes (AES-256), e nunca armazene senhas em texto plano — use hash com salt (bcrypt, argon2). Aplique essas práticas no design, não como remendo.

CVE-2025-45768HIGHpyjwt v2.10.1 was discovered to contain weak encryption. NOTE: this is disputed by the Supplier because the key length is chosen by the applEPSS 0.2%CVE-2014-6274HIGHS3 and Glacier remotes creds embedded in the git repo were not encryptedEPSS 0.2%CVE-2025-32875MEDIUMAn issue was discovered in the COROS application through 3.8.12 for Android. Bluetooth pairing and bonding is neither initiated nor enforcedEPSS 0.2%CVE-2023-40251MEDIUMMissing Encryption of Sensitive Data vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.0, Genians Genian NAC Suite V5.0, GeniaEPSS 0.2%CVE-2026-32891CRITICALAnchorr Privilege Escalation: Jellyseerr User → Anchorr Admin via Stored XSSEPSS 0.2%CVE-2025-64145MEDIUMJenkins ByteGuard Build Actions Plugin 1.0 does not mask API tokens displayed on the job configuration form, increasing the potential for atEPSS 0.2%CVE-2025-64146MEDIUMJenkins Curseforge Publisher Plugin 1.0 stores API Keys unencrypted in job config.xml files on the Jenkins controller where they can be viewEPSS 0.2%CVE-2025-64144MEDIUMJenkins ByteGuard Build Actions Plugin 1.0 stores API tokens unencrypted in job config.xml files on the Jenkins controller where they can beEPSS 0.2%CVE-2023-38267MEDIUMIBM Security Access Manager Appliance information disclosureEPSS 0.1%CVE-2025-8763MEDIUMRuijie EG306MG strongSwan strongswan.conf missing encryptionEPSS 0.1%CVE-2026-55568MEDIUMGuzzle: Silent HTTPS-Proxy Downgrade to CleartextEPSS 0.1%CVE-2024-56439HIGHAccess control vulnerability in the identity authentication module Impact: Successful exploitation of this vulnerability may affect service EPSS 0.1%CVE-2023-50129MEDIUMMissing encryption in the NFC tags of the Flient Smart Door Lock v1.0 allows attackers to create a cloned tag via brief physical proximity tEPSS 0.1%CVE-2025-59410MEDIUMDragonfly tiny file download uses hard coded HTTP protocolEPSS 0.1%CVE-2025-13453MEDIUMA potential vulnerability was reported in some ThinkPlus USB drives that could allow a user with physical access to read data stored on the EPSS 0.1%CVE-2025-65825MEDIUMThe firmware on the basestation of the Meatmeet is not encrypted. An adversary with physical access to the Meatmeet device can disassemble tEPSS 0.1%CVE-2025-47274LOWToolHive stores secrets in the state store with no encryptionEPSS 0.1%CVE-2022-38194MEDIUMPortal for ArcGIS system properties are not properly encrypted (10.8.1 only)EPSS 0.1%CVE-2026-81681CRITICALopenssl_encrypt before 1.4.9 False Encryption via Cleartext StorageEPSS 0.1%CVE-2025-43274MEDIUMA privacy issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.6. A sandboxed process may be able toEPSS 0.1%