VYPR

CWE-311

Missing Encryption of Sensitive Data

ClassDraftLikelihood: High

Description

The product does not encrypt sensitive or critical information before storage or transmission.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-157 · CAPEC-158 · CAPEC-204 · CAPEC-31 · CAPEC-37 · CAPEC-383 · CAPEC-384 · CAPEC-385 · CAPEC-386 · CAPEC-387 · CAPEC-388 · CAPEC-477 · CAPEC-609 · CAPEC-65

CVEs mapped to this weakness (522)

page 12 of 27
  • CVE-2021-37189HigDec 10, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered on Digi TransPort Gateway devices through 5.2.13.4. They do not set the Secure attribute for sensitive cookies in HTTPS sessions, which could cause the user agent to send those cookies in cleartext over an HTTP session.

  • CVE-2021-37050HigDec 8, 2021
    risk 0.49cvss 7.5epss 0.00

    There is a Missing sensitive data encryption vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2021-22932HigAug 16, 2021
    risk 0.49cvss 7.5epss 0.00

    An issue has been identified in the CTX269106 mitigation tool for Citrix ShareFile storage zones controller which causes the ShareFile file encryption option to become disabled if it had previously been enabled. Customers are only affected by this issue if they previously…

  • CVE-2021-33900HigJul 26, 2021
    risk 0.49cvss 7.5epss 0.01

    While investigating DIRSTUDIO-1219 it was noticed that configured StartTLS encryption was not applied when any SASL authentication mechanism (DIGEST-MD5, GSSAPI) was used. While investigating DIRSTUDIO-1220 it was noticed that any configured SASL confidentiality layer was not…

  • CVE-2020-26732HigJan 14, 2021
    risk 0.49cvss 7.5epss 0.02

    SKYWORTH GN542VF Hardware Version 2.0 and Software Version 2.0.0.16 does not set the Secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session.

  • CVE-2018-19944HigDec 31, 2020
    risk 0.49cvss 7.5epss 0.01

    A cleartext transmission of sensitive information vulnerability has been reported to affect certain QTS devices. If exploited, this vulnerability allows a remote attacker to gain access to sensitive information. QNAP have already fixed this vulnerability in the following…

  • CVE-2020-25842HigDec 31, 2020
    risk 0.49cvss 7.5epss 0.01

    The encryption function of NHIServiSignAdapter fail to verify the file path input by users. Remote attacker can access arbitrary files through the flaw without privilege.

  • CVE-2020-35587HigDec 23, 2020
    risk 0.49cvss 7.5epss 0.01

    In Solstice Pod before 3.0.3, the firmware can easily be decompiled/disassembled. The decompiled/disassembled files contain non-obfuscated code. NOTE: it is unclear whether lack of obfuscation is directly associated with a negative impact, or instead only facilitates an attack…

  • CVE-2020-27055HigDec 15, 2020
    risk 0.49cvss 7.5epss 0.01

    In isSubmittable and showWarningMessagesIfAppropriate of WifiConfigController.java and WifiConfigController2.java, there is a possible insecure WiFi configuration due to improper input validation. This could lead to remote information disclosure with no additional execution…

  • CVE-2020-28217HigDec 11, 2020
    risk 0.49cvss 7.5epss 0.01

    A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Easergy T300 (firmware 2.7 and older), that would allow an attacker to read network traffic over HTTP protocol.

  • CVE-2020-28216HigDec 11, 2020
    risk 0.49cvss 7.5epss 0.01

    A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Easergy T300 (firmware 2.7 and older), that would allow an attacker to read network traffic over HTTP protocol.

  • CVE-2020-9774HigOct 27, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue existed with Siri Suggestions access to encrypted data. The issue was fixed by limiting access to encrypted data. This issue is fixed in macOS Catalina 10.15.3, Security Update 2020-001 Mojave, Security Update 2020-001 High Sierra. Encrypted data may be inappropriately…

  • CVE-2020-15771HigSep 18, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Gradle Enterprise 2018.2 and Gradle Enterprise Build Cache Node 4.1. Cross-site transmission of cookie containing CSRF token allows remote attacker to bypass CSRF mitigation.

  • CVE-2020-10273HigJun 24, 2020
    risk 0.49cvss 7.5epss 0.01

    MiR controllers across firmware versions 2.8.1.1 and before do not encrypt or protect in any way the intellectual property artifacts installed in the robots. This flaw allows attackers with access to the robot or the robot network (while in combination with other flaws) to…

  • CVE-2020-10267HigApr 6, 2020
    risk 0.49cvss 7.5epss 0.01

    Universal Robots control box CB 3.1 across firmware versions (tested on 1.12.1, 1.12, 1.11 and 1.10) does not encrypt or protect in any way the intellectual property artifacts installed from the UR+ platform of hardware and software components (URCaps). These files (*.urcaps)…

  • CVE-2019-15653HigMar 19, 2020
    risk 0.49cvss 7.5epss 0.01

    Comba AP2600-I devices through A02,0202N00PD2 are prone to password disclosure via an insecure authentication mechanism. The HTML source code of the login page contains values that allow obtaining the username and password. The username are password values are a double md5 of…

  • CVE-2019-19739HigDec 30, 2019
    risk 0.49cvss 7.5epss 0.01

    MFScripts YetiShare 3.5.2 through 4.5.3 does not set the Secure flag on session cookies, allowing the cookie to be sent over cleartext channels.

  • CVE-2019-18980HigNov 14, 2019
    risk 0.49cvss 7.5epss 0.00

    On Signify Philips Taolight Smart Wi-Fi Wiz Connected LED Bulb 9290022656 devices, an unprotected API lets remote users control the bulb's operation. Anyone can turn the bulb on or off, or change its color or brightness remotely. There is no authentication or encryption to use…

  • CVE-2019-10084HigNov 5, 2019
    risk 0.49cvss 7.5epss 0.01

    In Apache Impala 2.7.0 to 3.2.0, an authenticated user with access to the IDs of active Impala queries or sessions can interact with those sessions or queries via a specially-constructed request and thereby potentially bypass authorization and audit mechanisms. Session and query…

  • CVE-2019-13419HigAug 13, 2019
    risk 0.49cvss 7.5epss 0.01

    Search Guard versions before 23.1 had an issue that for aggregations clear text values of anonymised fields were leaked.