VYPR

CWE-311

Missing Encryption of Sensitive Data

ClassDraftLikelihood: High

Description

The product does not encrypt sensitive or critical information before storage or transmission.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-157 · CAPEC-158 · CAPEC-204 · CAPEC-31 · CAPEC-37 · CAPEC-383 · CAPEC-384 · CAPEC-385 · CAPEC-386 · CAPEC-387 · CAPEC-388 · CAPEC-477 · CAPEC-609 · CAPEC-65

CVEs mapped to this weakness (530)

page 19 of 27
  • CVE-2022-22401MedSep 8, 2023
    risk 0.38cvss 5.9epss 0.01

    IBM Aspera Faspex 5.0.5 could allow a remote attacker to gather or persuade a naive user to supply sensitive information. IBM X-Force ID: 222567.

  • CVE-2022-22405MedSep 8, 2023
    risk 0.38cvss 5.9epss 0.01

    IBM Aspera Faspex 5.0.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM…

  • CVE-2021-21963MedFeb 4, 2022
    risk 0.38cvss 5.9epss 0.00

    An information disclosure vulnerability exists in the Web Server functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A specially-crafted man-in-the-middle attack can lead to a disclosure of sensitive information. An attacker can perform a man-in-the-middle attack to…

  • CVE-2020-4126MedDec 1, 2020
    risk 0.38cvss 5.9epss 0.01

    HCL iNotes is susceptible to a sensitive cookie exposure vulnerability. This can allow an unauthenticated remote attacker to capture the cookie by intercepting its transmission within an http session. Fixes are available in HCL Domino and iNotes versions 10.0.1 FP6 and 11.0.1…

  • CVE-2020-27651MedOct 29, 2020
    risk 0.38cvss 5.8epss 0.01

    Synology Router Manager (SRM) before 1.2.4-8081 does not set the Secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session.

  • CVE-2020-27650MedOct 29, 2020
    risk 0.38cvss 5.8epss 0.01

    Synology DiskStation Manager (DSM) before 6.2.3-25426-2 does not set the Secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session.

  • CVE-2019-18833MedDec 17, 2019
    risk 0.38cvss 5.9epss 0.00

    Barco ClickShare Button R9861500D01 devices before 1.9.0 allow Information exposure (issue 2 of 2).. The encryption key of the media content which is shared between a ClickShare Button and a ClickShare Base Unit is randomly generated for each new session and communicated over a…

  • CVE-2017-16041MedJun 4, 2018
    risk 0.38cvss 5.9epss 0.01

    ikst versions before 1.1.2 download resources over HTTP, which leaves it vulnerable to MITM attacks.

  • CVE-2016-10630MedJun 1, 2018
    risk 0.38cvss 5.9epss 0.01

    install-g-test downloads resources over HTTP, which leaves it vulnerable to MITM attacks.

  • CVE-2016-10613MedJun 1, 2018
    risk 0.38cvss 5.9epss 0.01

    bionode-sra is a Node.js wrapper for SRA Toolkit. bionode-sra downloads data resources over HTTP, which leaves it vulnerable to MITM attacks.

  • CVE-2016-10597MedJun 1, 2018
    risk 0.38cvss 5.9epss 0.01

    cobalt-cli downloads resources over HTTP, which leaves it vulnerable to MITM attacks.

  • CVE-2017-9045MedMay 18, 2017
    risk 0.38cvss 5.9epss 0.00

    The Google I/O 2017 application before 5.1.4 for Android downloads multiple .json files from http://storage.googleapis.com without SSL, which makes it easier for man-in-the-middle attackers to spoof Feed and Schedule data by creating a modified blocks_v4.json file.

  • CVE-2017-6297MedFeb 27, 2017
    risk 0.38cvss 5.9epss 0.01

    The L2TP Client in MikroTik RouterOS versions 6.38.3 and 6.37.4 does not enable IPsec encryption after a reboot, which allows man-in-the-middle attackers to view transmitted data unencrypted and gain access to networks on the L2TP server by monitoring the packets for the…

  • CVE-2025-32875MedJun 20, 2025
    risk 0.37cvss 5.7epss 0.00

    An issue was discovered in the COROS application through 3.8.12 for Android. Bluetooth pairing and bonding is neither initiated nor enforced by the application itself. Also, the watch does not enforce pairing and bonding. As a result, any data transmitted via BLE remains…

  • CVE-2024-27106MedMay 14, 2024
    risk 0.37cvss 5.7epss 0.00

    Vulnerable data in transit in GE HealthCare EchoPAC products

  • CVE-2023-28841MedApr 4, 2023
    risk 0.37cvss 6.8epss 0.01

    Moby is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon component (`dockerd`), which is developed as moby/moby is commonly referred to as…

  • CVE-2021-28496MedOct 21, 2021
    risk 0.37cvss 5.7epss 0.00

    On systems running Arista EOS and CloudEOS with the affected release version, when using shared secret profiles the password configured for use by BiDirectional Forwarding Detection (BFD) will be leaked when displaying output over eAPI or other JSON outputs to other…

  • CVE-2020-7567MedNov 19, 2020
    risk 0.37cvss 5.7epss 0.00

    A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Modicon M221 (all references, all versions) that could allow the attacker to find the password hash when the attacker has captured the traffic between EcoStruxure Machine - Basic software and Modicon M221…

  • CVE-2017-5042MedApr 24, 2017
    risk 0.37cvss 5.7epss 0.00

    Cast in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android sent cookies to sites discovered via SSDP, which allowed an attacker on the local network segment to initiate connections to arbitrary URLs and observe any plaintext cookies…

  • CVE-2026-92757MedSep 17, 2026
    risk 0.36cvss 5.5epss 0.00

    Applications built on MongoDB Entity Framework Core Provider which place a database name in the connection string may inadvertently disable field level encryption.