VYPR

CWE-311

Missing Encryption of Sensitive Data

ClassDraftLikelihood: High

Description

The product does not encrypt sensitive or critical information before storage or transmission.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-157 · CAPEC-158 · CAPEC-204 · CAPEC-31 · CAPEC-37 · CAPEC-383 · CAPEC-384 · CAPEC-385 · CAPEC-386 · CAPEC-387 · CAPEC-388 · CAPEC-477 · CAPEC-609 · CAPEC-65

CVEs mapped to this weakness (522)

page 13 of 27
  • CVE-2019-13418HigAug 12, 2019
    risk 0.49cvss 7.5epss 0.01

    Search Guard versions before 24.0 had an issue that values of string arrays in documents are not properly anonymized.

  • CVE-2019-6169HigJun 26, 2019
    risk 0.49cvss 7.5epss 0.01

    A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow unencrypted downloads over FTP.

  • CVE-2019-6518HigMar 5, 2019
    risk 0.49cvss 7.5epss 0.01

    Moxa IKS and EDS store plaintext passwords, which may allow sensitive information to be read by someone with access to the device.

  • CVE-2018-1340HigFeb 7, 2019
    risk 0.49cvss 7.5epss 0.02

    Prior to 1.0.0, Apache Guacamole used a cookie for client-side storage of the user's session token. This cookie lacked the "secure" flag, which could allow an attacker eavesdropping on the network to intercept the user's session token if unencrypted HTTP requests are made to the…

  • CVE-2018-14608HigJul 26, 2018
    risk 0.49cvss 7.5epss 0.01

    Thomson Reuters UltraTax CS 2017 on Windows has a password protection option; however, the level of protection might be inconsistent with some customers' expectations because the data is directly accessible in cleartext. Specifically, it stores customer data in unique…

  • CVE-2018-14607HigJul 26, 2018
    risk 0.49cvss 7.5epss 0.01

    Thomson Reuters UltraTax CS 2017 on Windows, in a client/server configuration, transfers customer records and bank account numbers in cleartext over SMBv2, which allows attackers to (1) obtain sensitive information by sniffing the network or (2) conduct man-in-the-middle (MITM)…

  • CVE-2018-5162HigJun 11, 2018
    risk 0.49cvss 7.5epss 0.02

    Plaintext of decrypted emails can leak through the src attribute of remote images, or links. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.

  • CVE-2016-10608HigJun 1, 2018
    risk 0.49cvss 7.5epss 0.02

    robot-js is a module for native system automation for node.js. robot-js downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled…

  • CVE-2016-10598HigJun 1, 2018
    risk 0.49cvss 7.5epss 0.01

    arrayfire-js is a module for ArrayFire for the Node.js platform. arrayfire-js downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker…

  • CVE-2017-17763HigDec 19, 2017
    risk 0.49cvss 7.5epss 0.01

    SuperBeam through 4.1.3, when using the LAN or WiFi Direct Share feature, does not use HTTPS or any integrity-protection mechanism for file transfer, which makes it easier for remote attackers to send crafted files, as demonstrated by APK injection.

  • CVE-2017-15581HigOct 27, 2017
    risk 0.49cvss 7.5epss 0.01

    In the "Diary with lock" (aka WriteDiary) application 4.72 for Android, neither HTTPS nor other encryption is used for transmitting data, despite the documentation that the product is intended for "a personal journal of ... secrets and feelings," which allows remote attackers to…

  • CVE-2017-15609HigOct 19, 2017
    risk 0.49cvss 7.5epss 0.01

    Octopus before 3.17.7 allows attackers to obtain sensitive cleartext information by reading a variable JSON file in certain situations involving Offline Drop Targets.

  • CVE-2017-12817HigAug 25, 2017
    risk 0.49cvss 7.5epss 0.01

    In Kaspersky Internet Security for Android 11.12.4.1622, some of the application trace files were not encrypted.

  • CVE-2017-7729HigJul 11, 2017
    risk 0.49cvss 7.5epss 0.01

    On iSmartAlarm cube devices, there is Incorrect Access Control because a "new key" is transmitted in cleartext.

  • CVE-2017-9604HigJun 13, 2017
    risk 0.49cvss 7.5epss 0.01

    KDE kmail before 5.5.2 and messagelib before 5.5.2, as distributed in KDE Applications before 17.04.2, do not ensure that a plugin's sign/encrypt action occurs during use of the Send Later feature, which allows remote attackers to obtain sensitive information by sniffing the…

  • CVE-2007-4961HigSep 18, 2007
    risk 0.49cvss 7.5epss 0.01

    The login_to_simulator method in Linden Lab Second Life, as used by the secondlife:// protocol handler and possibly other Second Life login mechanisms, sends an MD5 hash in cleartext in the passwd field, which allows remote attackers to login to an account by sniffing the…

  • CVE-2021-27764HigMay 6, 2022
    risk 0.48cvss 7.4epss 0.01

    Cookie without HTTPONLY flag set. NUMBER cookie(s) was set without Secure or HTTPOnly flags. The images show the cookie with the missing flag. (WebUI)

  • CVE-2021-40366HigNov 9, 2021
    risk 0.48cvss 7.4epss 0.00

    A vulnerability has been identified in Climatix POL909 (AWB module) (All versions < V11.42), Climatix POL909 (AWM module) (All versions < V11.34). The web server of affected devices transmits data without TLS encryption. This could allow an unauthenticated remote attacker in a…

  • CVE-2011-3355HigNov 25, 2019
    risk 0.48cvss 7.3epss 0.01

    evolution-data-server3 3.0.3 through 3.2.1 used insecure (non-SSL) connection when attempting to store sent email messages into the Sent folder, when the Sent folder was located on the remote server. An attacker could use this flaw to obtain login credentials of the victim.

  • CVE-2018-5481HigJan 7, 2019
    risk 0.48cvss 7.4epss 0.01

    OnCommand Unified Manager for 7-Mode (core package) prior to 5.2.4 uses cookies that lack the secure attribute in certain circumstances making it vulnerable to impersonation via man-in-the-middle (MITM) attacks.