VYPR

CWE-311

Missing Encryption of Sensitive Data

ClassDraftLikelihood: High

Description

The product does not encrypt sensitive or critical information before storage or transmission.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-157 · CAPEC-158 · CAPEC-204 · CAPEC-31 · CAPEC-37 · CAPEC-383 · CAPEC-384 · CAPEC-385 · CAPEC-386 · CAPEC-387 · CAPEC-388 · CAPEC-477 · CAPEC-609 · CAPEC-65

CVEs mapped to this weakness (522)

page 11 of 27
  • CVE-2019-1003064HigApr 4, 2019
    risk 0.50cvss 8.8epss 0.01

    Jenkins aws-device-farm Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.

  • CVE-2019-1003063HigApr 4, 2019
    risk 0.50cvss 8.8epss 0.01

    Jenkins Amazon SNS Build Notifier Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.

  • CVE-2019-1003061HigApr 4, 2019
    risk 0.50cvss 8.8epss 0.01

    Jenkins jenkins-cloudformation-plugin Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.

  • CVE-2026-20157HigJul 15, 2026
    risk 0.49cvss 7.5epss 0.00

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered…

  • CVE-2014-6274HigJun 26, 2025
    risk 0.49cvss 7.5epss 0.00

    git-annex had a bug in the S3 and Glacier remotes where if embedcreds=yes was set, and the remote used encryption=pubkey or encryption=hybrid, the embedded AWS credentials were stored in the git repository in (effectively) plaintext, not encrypted as they were supposed to be.…

  • CVE-2024-56439HigJan 8, 2025
    risk 0.49cvss 7.5epss 0.00

    Access control vulnerability in the identity authentication module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2024-42657HigAug 19, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the lack of encryption during login process

  • CVE-2024-40620HigAug 14, 2024
    risk 0.49cvss 7.5epss 0.00

    CVE-2024-40620 IMPACT A vulnerability exists in the affected product due to lack of encryption of sensitive information. The vulnerability results in data being sent between the Console and the Dashboard without encryption, which can be seen in the logs of proxy servers,…

  • CVE-2023-44098HigNov 8, 2023
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of missing encryption in the card management module. Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-31825HigJul 13, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue found in Inageya v.13.4.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp Inageya function.

  • CVE-2023-31822HigJul 13, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue found in Entetsu Store v.13.4.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp Entetsu Store function.

  • CVE-2023-31820HigJul 13, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue found in Shizutetsu Store v.13.6.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp function.

  • CVE-2023-31819HigJul 13, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue found in KEISEI STORE Co, Ltd. LIVRE KEISEI v.13.6.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp function.

  • CVE-2023-37192HigJul 7, 2023
    risk 0.49cvss 7.5epss 0.01

    Memory management and protection issues in Bitcoin Core v22 allows attackers to modify the stored sending address within the app's memory, potentially allowing them to redirect Bitcoin transactions to wallets of their own choosing.

  • CVE-2023-34258HigMay 31, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in BMC Patrol before 22.1.00. The agent's configuration can be remotely queried. This configuration contains the Patrol account password, encrypted with a default AES key. This account can then be used to achieve remote code execution.

  • CVE-2023-32290HigMay 7, 2023
    risk 0.49cvss 7.5epss 0.00

    The myMail app through 14.30 for iOS sends cleartext credentials in a situation where STARTTLS is expected by a server.

  • CVE-2022-21940HigFeb 9, 2023
    risk 0.49cvss 7.5epss 0.00

    Sensitive Cookie in HTTPS Session Without 'Secure' Attribute vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 prior to 14.2.3 and version 15 prior to 15.0.3 could allow access to the cookie.

  • CVE-2020-15340HigSep 29, 2022
    risk 0.49cvss 7.5epss 0.01

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded opt/axess/AXAssets/default_axess/axess/TR69/Handlers/turbolink/sshkeys/id_rsa SSH key.

  • CVE-2022-26281HigApr 5, 2022
    risk 0.49cvss 7.5epss 0.01

    BigAnt Server v5.6.06 was discovered to contain an incorrect access control issue.

  • CVE-2022-23116HigJan 12, 2022
    risk 0.49cvss 7.5epss 0.01

    Jenkins Conjur Secrets Plugin 1.0.9 and earlier implements functionality that allows attackers able to control agent processes to decrypt secrets stored in Jenkins obtained through another method.