VYPR

CWE-311

Missing Encryption of Sensitive Data

ClassDraftLikelihood: High

Description

The product does not encrypt sensitive or critical information before storage or transmission.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-157 · CAPEC-158 · CAPEC-204 · CAPEC-31 · CAPEC-37 · CAPEC-383 · CAPEC-384 · CAPEC-385 · CAPEC-386 · CAPEC-387 · CAPEC-388 · CAPEC-477 · CAPEC-609 · CAPEC-65

CVEs mapped to this weakness (522)

page 1 of 27
  • CVE-2026-27944CriMar 5, 2026
    risk 0.65cvss 9.8epss 0.22

    Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.3, the /api/backup endpoint is accessible without authentication and discloses the encryption keys required to decrypt the backup in the X-Backup-Security response header. This allows an…

  • CVE-2023-6339CriJan 2, 2024
    risk 0.65cvss 10.0epss 0.00

    Google Nest WiFi Pro root code-execution & user-data compromise

  • CVE-2023-4420CriAug 24, 2023
    risk 0.64cvss 9.8epss 0.00

    A remote unprivileged attacker can intercept the communication via e.g. Man-In-The-Middle, due to the absence of Transport Layer Security (TLS) in the SICK LMS5xx. This lack of encryption in the communication channel can lead to the unauthorized disclosure of sensitive…

  • CVE-2023-0750CriApr 6, 2023
    risk 0.64cvss 9.8epss 0.00

    Yellobrik PEC-1864 implements authentication checks via javascript in the frontend interface.  When the device can be accessed over the network an attacker could bypass authentication. This would allow an attacker to : - Change the password, resulting in a DOS of the users…

  • CVE-2020-15331CriSep 29, 2022
    risk 0.64cvss 9.8epss 0.01

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded OAUTH_SECRET_KEY in /opt/axess/etc/default/axess.

  • CVE-2019-14480CriDec 16, 2020
    risk 0.64cvss 9.8epss 0.01

    AdRem NetCrunch 10.6.0.4587 has an Improper Session Handling vulnerability in the NetCrunch web client, which can lead to an authentication bypass or escalation of privileges.

  • CVE-2019-3431CriDec 23, 2019
    risk 0.64cvss 9.8epss 0.00

    All versions up to V4.01.01.02 of ZTE ZXCLOUD GoldenData VAP product have encryption problems vulnerability. Attackers could sniff unencrypted account and password through the network for front-end system access.

  • CVE-2019-12924CriJul 8, 2019
    risk 0.64cvss 9.8epss 0.01

    MailEnable Enterprise Premium 10.23 was vulnerable to XML External Entity Injection (XXE) attacks that could be exploited by an unauthenticated user. It was possible for an attacker to use a vulnerability in the configuration of the XML processor to read any file on the host…

  • CVE-2018-10698CriJun 7, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered on Moxa AWK-3121 1.14 devices. The device enables an unencrypted TELNET service by default. This allows an attacker who has been able to gain an MITM position to easily sniff the traffic between the device and the user. Also an attacker can easily connect…

  • CVE-2019-11523CriJun 6, 2019
    risk 0.64cvss 9.8epss 0.01

    Anviz Global M3 Outdoor RFID Access Control executes any command received from any source. No authentication/encryption is done. Attackers can fully interact with the device: for example, send the "open door" command, download the users list (which includes RFID codes and…

  • CVE-2019-11367CriJun 3, 2019
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in AUO Solar Data Recorder before 1.3.0. The web portal uses HTTP Basic Authentication and provides the account and password in the WWW-Authenticate attribute. By using this account and password, anyone can login successfully.

  • CVE-2019-6526CriApr 15, 2019
    risk 0.64cvss 9.8epss 0.01

    Moxa IKS-G6824A series Versions 4.5 and prior, EDS-405A series Version 3.8 and prior, EDS-408A series Version 3.8 and prior, and EDS-510A series Version 3.8 and prior use plaintext transmission of sensitive data, which may allow an attacker to capture sensitive data such as an…

  • CVE-2018-10612CriJan 29, 2019
    risk 0.64cvss 9.8epss 0.01

    In 3S-Smart Software Solutions GmbH CODESYS Control V3 products prior to version 3.5.14.0, user access management and communication encryption is not enabled by default, which could allow an attacker access to the device and sensitive information, including user credentials.

  • CVE-2018-16879CriJan 3, 2019
    risk 0.64cvss 9.8epss 0.01

    Ansible Tower before version 3.3.3 does not set a secure channel as it is using the default insecure configuration channel settings for messaging celery workers from RabbitMQ. This could lead in data leak of sensitive information such as passwords as well as denial of service…

  • CVE-2018-20100CriJan 2, 2019
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered on August Connect devices. Insecure data transfer between the August app and August Connect during configuration allows attackers to discover home Wi-Fi credentials. This data transfer uses an unencrypted access point for these credentials, and passes…

  • CVE-2018-17915CriOct 10, 2018
    risk 0.64cvss 9.8epss 0.01

    All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server do not encrypt all device communication. This includes the XMeye service and firmware update communication. This could allow an attacker to eavesdrop on video feeds, steal XMeye login credentials, or…

  • CVE-2017-3198CriJul 9, 2018
    risk 0.64cvss 9.8epss 0.02

    GIGABYTE BRIX UEFI firmware does not cryptographically validate images prior to updating the system firmware. Additionally, the firmware updates are served over HTTP. An attacker can make arbitrary modifications to firmware images without being detected.

  • CVE-2018-7498CriMar 28, 2018
    risk 0.64cvss 9.8epss 0.01

    In Philips Alice 6 System version R8.0.2 or prior, the lack of proper data encryption passes up the guarantees of confidentiality, integrity, and accountability that properly implemented encryption conveys.

  • CVE-2017-9632CriAug 7, 2017
    risk 0.64cvss 9.8epss 0.00

    A Missing Encryption of Sensitive Data issue was discovered in PDQ Manufacturing LaserWash G5 and G5 S Series all versions, LaserWash M5, all versions, LaserWash 360 and 360 Plus, all versions, LaserWash AutoXpress and AutoExpress Plus, all versions, LaserJet, all versions,…

  • CVE-2017-9854CriAug 5, 2017
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in SMA Solar Technology products. By sniffing for specific packets on the localhost, plaintext passwords can be obtained as they are typed into Sunny Explorer by the user. These passwords can then be used to compromise the overall device. NOTE: the vendor…