VYPR

CWE-311

Missing Encryption of Sensitive Data

ClassDraftLikelihood: High

Description

The product does not encrypt sensitive or critical information before storage or transmission.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-157 · CAPEC-158 · CAPEC-204 · CAPEC-31 · CAPEC-37 · CAPEC-383 · CAPEC-384 · CAPEC-385 · CAPEC-386 · CAPEC-387 · CAPEC-388 · CAPEC-477 · CAPEC-609 · CAPEC-65

CVEs mapped to this weakness (522)

page 14 of 27
  • CVE-2016-10552HigMay 31, 2018
    risk 0.48cvss 7.4epss 0.01

    igniteui 0.0.5 and earlier downloads JavaScript and CSS resources over insecure protocol.

  • CVE-2017-15397HigFeb 7, 2018
    risk 0.48cvss 7.4epss 0.00

    Inappropriate implementation in ChromeVox in Google Chrome OS prior to 62.0.3202.74 allowed a remote attacker in a privileged network position to observe or tamper with certain cleartext HTTP requests by leveraging that position.

  • CVE-2024-35061HigMay 21, 2024
    risk 0.47cvss 7.3epss 0.01

    NASA AIT-Core v2.5.2 was discovered to use unencrypted channels to exchange data over the network, allowing attackers to execute a man-in-the-middle attack. When chained with CVE-2024-35059, the CVE in subject leads to an unauthenticated, fully remote code execution.

  • CVE-2021-41302HigSep 30, 2021
    risk 0.47cvss 7.3epss 0.00

    ECOA BAS controller stores sensitive data (backup exports) in clear-text, thus the unauthenticated attacker can remotely query user password and obtain user’s privilege.

  • CVE-2018-20465HigDec 25, 2018
    risk 0.47cvss 7.2epss 0.02

    Craft CMS through 3.0.34 allows remote authenticated administrators to read sensitive information via server-side template injection, as demonstrated by a {% string for craft.app.config.DB.user and craft.app.config.DB.password in the URI Format of the Site Settings, which causes…

  • CVE-2026-21079HigAug 10, 2026
    risk 0.46cvss epss 0.00

    Missing encryption of sensitive data in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to intercept transmitted data.

  • CVE-2025-48862HigAug 14, 2025
    risk 0.46cvss 7.1epss 0.00

    Ambiguous wording in the web interface of the ctrlX OS setup mechanism could lead the user to believe that the backup file is encrypted when a password is set. However, only the private key - if available in the backup - is encrypted, while the backup file itself remains…

  • CVE-2025-45768HigJul 31, 2025
    risk 0.46cvss 7.0epss 0.00

    pyjwt v2.10.1 was discovered to contain weak encryption. NOTE: this is disputed by the Supplier because the key length is chosen by the application that uses the library (admittedly, library users may benefit from a minimum value and a mechanism for opting in to strict…

  • CVE-2024-7396HigAug 5, 2024
    risk 0.46cvss epss 0.00

    Missing encryption of sensitive data in Korenix JetPort 5601v3 allows Eavesdropping.This issue affects JetPort 5601v3: through 1.2.

  • CVE-2023-33037HigJan 2, 2024
    risk 0.46cvss 7.1epss 0.00

    Cryptographic issue in Automotive while unwrapping the key secs2d and verifying with RPMB data.

  • CVE-2020-10124HigAug 21, 2020
    risk 0.46cvss 7.1epss 0.01

    NCR SelfServ ATMs running APTRA XFS 05.01.00 do not encrypt, authenticate, or verify the integrity of messages between the BNA and the host computer, which could allow an attacker with physical access to the internal components of the ATM to execute arbitrary code, including…

  • CVE-2019-10103HigJul 3, 2019
    risk 0.46cvss 8.1epss 0.01

    JetBrains IntelliJ IDEA projects created using the Kotlin (JS Client/JVM Server) IDE Template were resolving Gradle artifacts using an http connection, potentially allowing an MITM attack. This issue, which was fixed in Kotlin plugin version 1.3.30, is similar to CVE-2019-10101.

  • CVE-2019-11404HigApr 22, 2019
    risk 0.46cvss 8.1epss 0.01

    arrow-kt Arrow before 0.9.0 resolved Gradle build artifacts (for compiling and building the published JARs) over HTTP instead of HTTPS. Any of these dependent artifacts could have been maliciously compromised by an MITM attack.

  • CVE-2016-10665HigJun 4, 2018
    risk 0.46cvss 8.1epss 0.02

    herbivore is a packet sniffing and crafting library. Built on libtins herbivore 0.0.3 and below download binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with…

  • CVE-2016-10638HigJun 4, 2018
    risk 0.46cvss 8.1epss 0.02

    js-given is a JavaScript frontend to jgiven. js-given downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker…

  • CVE-2016-10626HigJun 1, 2018
    risk 0.46cvss 8.1epss 0.02

    mystem3 is a NodeJS wrapper for the Yandex MyStem 3. mystem3 downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the…

  • CVE-2016-10625HigJun 1, 2018
    risk 0.46cvss 8.1epss 0.02

    headless-browser-lite is a minimal npm installer for phantomjs and slimerjs with no external dependencies. headless-browser-lite downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping…

  • CVE-2016-10588HigJun 1, 2018
    risk 0.46cvss 8.1epss 0.02

    nw is an installer for nw.js. nw downloads zipped resources over HTTP, It may be possible to cause remote code execution (RCE) by swapping out the requested zip file with an attacker controlled binary if the attacker is on the network or positioned in between the user and the…

  • CVE-2016-10582HigJun 1, 2018
    risk 0.46cvss 8.1epss 0.02

    closurecompiler is a Closure Compiler for node.js. closurecompiler downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if…

  • CVE-2016-10579HigJun 1, 2018
    risk 0.46cvss 8.1epss 0.01

    Chromedriver is an NPM wrapper for selenium ChromeDriver. Chromedriver before 2.26.1 downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker…