Falhas do tipo CWE-311

312 resultados

Falta de criptografia de dados sensíveis

A aplicação transmite ou armazena dados sensíveis (senhas, tokens, dados pessoais, números de cartão) em texto plano, sem criptografia. Um atacante que intercepte a comunicação ou acesse o armazenamento consegue ler essas informações diretamente, comprometendo confidencialidade e segurança do usuário.

Exemplo

Um aplicativo mobile envia credenciais de login via HTTP em vez de HTTPS, ou salva senhas em um arquivo de configuração sem criptografia. Um atacante na mesma rede Wi-Fi ou com acesso ao dispositivo rouba as credenciais facilmente.

Como mitigar

Use HTTPS/TLS para toda comunicação de dados sensíveis, criptografe dados em repouso com algoritmos fortes (AES-256), e nunca armazene senhas em texto plano — use hash com salt (bcrypt, argon2). Aplique essas práticas no design, não como remendo.

CVE-2023-33833LOWIBM Security Verify Information Queue information disclosureEPSS 0.1%CVE-2026-19891MEDIUMTRENDnet TEW-WLC100 IKE Phase 1 Aggressive Mode racoon.conf missing encryptionEPSS 0.1%CVE-2024-41980LOWA vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Audit (All versions >=EPSS 0.1%CVE-2026-34992HIGHMissing Encryption of Sensitive Data in antrea.io/antreaEPSS 0.1%CVE-2026-84676MEDIUMJenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier stores tokens unencrypted in job config.xml files on the Jenkins controller whEPSS 0.1%CVE-2025-48981HIGHAn insecure implementation of the proprietary protocol DNET in Product CGM MEDICO allows attackers within the intranet to eavesdrop and maniEPSS 0.1%CVE-2025-48862HIGHAmbiguous wording in the web interface of the ctrlX OS setup mechanism could lead the user to believe that the backup file is encrypted whenEPSS 0.1%CVE-2022-41627MEDIUM The physical IoT device of the AliveCor's KardiaMobile, a smartphone-based personal electrocardiogram (EKG) has no encryption for its data-EPSS 0.1%CVE-2021-22782Missing Encryption of Sensitive Data vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versEPSS 0.1%CVE-2026-20157HIGHCisco RoomOS Security Hardening Release - Missing Encryption VulnerabilitiesEPSS 0.1%CVE-2024-25027MEDIUMIBM Security Verify Access Container information disclosureEPSS 0.1%CVE-2023-23371MEDIUMQVPN Device ClientEPSS 0.1%CVE-2025-33020MEDIUMIBM Engineering Systems Design Rhapsody information disclosureEPSS 0.1%CVE-2025-31977MEDIUMA cryptographic weakness has been identified in the HCL BigFix Service Management (SM)EPSS 0.1%CVE-2024-38283MEDIUMMissing Encryption of Sensitive Data in Motorola Solutions Vigilant Fixed LPR Coms Box (BCAV1F2-C600)EPSS 0.1%CVE-2023-50126MEDIUMMissing encryption in the RFID tags of the Hozard alarm system (Alarmsysteem) v1.0 allow attackers to create a cloned tag via brief physicalEPSS 0.1%CVE-2024-7142MEDIUMOn Arista CloudVision Appliance (CVA) affected releases running on appliances that support hardware disk encryption (DCA-350E-CV only), the disk encryption might not be successfully performed. This results in the disks remaining unsecured and data on themEPSS 0.1%CVE-2024-38302MEDIUMDell Data Lakehouse, version(s) 1.0.0.0, contain(s) a Missing Encryption of Sensitive Data vulnerability in the DDAE (Starburst). A low privEPSS 0.1%CVE-2025-13053HIGHA missing encryption of sensitive data vulnerability was found in the UPS settings of ADMEPSS 0.1%CVE-2025-1243LOWField in api-go proxy not transformed before version 1.44.1EPSS 0.1%