CWE-311
Missing Encryption of Sensitive Data
Description
The product does not encrypt sensitive or critical information before storage or transmission.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-157 · CAPEC-158 · CAPEC-204 · CAPEC-31 · CAPEC-37 · CAPEC-383 · CAPEC-384 · CAPEC-385 · CAPEC-386 · CAPEC-387 · CAPEC-388 · CAPEC-477 · CAPEC-609 · CAPEC-65
CVEs mapped to this weakness (522)
page 19 of 27| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-4126 | Med | 0.38 | 5.9 | 0.01 | Dec 1, 2020 | HCL iNotes is susceptible to a sensitive cookie exposure vulnerability. This can allow an unauthenticated remote attacker to capture the cookie by intercepting its transmission within an http session. Fixes are available in HCL Domino and iNotes versions 10.0.1 FP6 and 11.0.1… | ||
| CVE-2020-27651 | Med | 0.38 | 5.8 | 0.01 | Oct 29, 2020 | Synology Router Manager (SRM) before 1.2.4-8081 does not set the Secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session. | ||
| CVE-2020-27650 | Med | 0.38 | 5.8 | 0.01 | Oct 29, 2020 | Synology DiskStation Manager (DSM) before 6.2.3-25426-2 does not set the Secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session. | ||
| CVE-2019-18833 | Med | 0.38 | 5.9 | 0.00 | Dec 17, 2019 | Barco ClickShare Button R9861500D01 devices before 1.9.0 allow Information exposure (issue 2 of 2).. The encryption key of the media content which is shared between a ClickShare Button and a ClickShare Base Unit is randomly generated for each new session and communicated over a… | ||
| CVE-2017-16041 | Med | 0.38 | 5.9 | 0.01 | Jun 4, 2018 | ikst versions before 1.1.2 download resources over HTTP, which leaves it vulnerable to MITM attacks. | ||
| CVE-2016-10630 | Med | 0.38 | 5.9 | 0.01 | Jun 1, 2018 | install-g-test downloads resources over HTTP, which leaves it vulnerable to MITM attacks. | ||
| CVE-2016-10613 | Med | 0.38 | 5.9 | 0.01 | Jun 1, 2018 | bionode-sra is a Node.js wrapper for SRA Toolkit. bionode-sra downloads data resources over HTTP, which leaves it vulnerable to MITM attacks. | ||
| CVE-2016-10597 | Med | 0.38 | 5.9 | 0.01 | Jun 1, 2018 | cobalt-cli downloads resources over HTTP, which leaves it vulnerable to MITM attacks. | ||
| CVE-2017-9045 | Med | 0.38 | 5.9 | 0.00 | May 18, 2017 | The Google I/O 2017 application before 5.1.4 for Android downloads multiple .json files from http://storage.googleapis.com without SSL, which makes it easier for man-in-the-middle attackers to spoof Feed and Schedule data by creating a modified blocks_v4.json file. | ||
| CVE-2017-6297 | Med | 0.38 | 5.9 | 0.01 | Feb 27, 2017 | The L2TP Client in MikroTik RouterOS versions 6.83.3 and 6.37.4 does not enable IPsec encryption after a reboot, which allows man-in-the-middle attackers to view transmitted data unencrypted and gain access to networks on the L2TP server by monitoring the packets for the… | ||
| CVE-2025-32875 | Med | 0.37 | 5.7 | 0.00 | Jun 20, 2025 | An issue was discovered in the COROS application through 3.8.12 for Android. Bluetooth pairing and bonding is neither initiated nor enforced by the application itself. Also, the watch does not enforce pairing and bonding. As a result, any data transmitted via BLE remains… | ||
| CVE-2024-27106 | Med | 0.37 | 5.7 | 0.00 | May 14, 2024 | Vulnerable data in transit in GE HealthCare EchoPAC products | ||
| CVE-2023-28841 | Med | 0.37 | 6.8 | 0.01 | Apr 4, 2023 | Moby is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon component (`dockerd`), which is developed as moby/moby is commonly referred to as… | ||
| CVE-2021-28496 | Med | 0.37 | 5.7 | 0.00 | Oct 21, 2021 | On systems running Arista EOS and CloudEOS with the affected release version, when using shared secret profiles the password configured for use by BiDirectional Forwarding Detection (BFD) will be leaked when displaying output over eAPI or other JSON outputs to other… | ||
| CVE-2020-7567 | Med | 0.37 | 5.7 | 0.00 | Nov 19, 2020 | A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Modicon M221 (all references, all versions) that could allow the attacker to find the password hash when the attacker has captured the traffic between EcoStruxure Machine - Basic software and Modicon M221… | ||
| CVE-2017-5042 | Med | 0.37 | 5.7 | 0.00 | Apr 24, 2017 | Cast in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android sent cookies to sites discovered via SSDP, which allowed an attacker on the local network segment to initiate connections to arbitrary URLs and observe any plaintext cookies… | ||
| CVE-2025-31728 | Med | 0.36 | 5.5 | 0.00 | Apr 2, 2025 | Jenkins AsakusaSatellite Plugin 0.1.1 and earlier does not mask AsakusaSatellite API keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them. | ||
| CVE-2024-20503 | Med | 0.36 | 5.5 | 0.00 | Sep 4, 2024 | A vulnerability in Cisco Duo Epic for Hyperdrive could allow an authenticated, local attacker to view sensitive information in cleartext on an affected system. This vulnerability is due to improper storage of an unencrypted registry key. A low-privileged attacker could… | ||
| CVE-2021-22782 | Med | 0.36 | 5.5 | 0.00 | Jul 14, 2021 | Missing Encryption of Sensitive Data vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Process Expert (all versions, including all versions of EcoStruxure Hybrid DCS), and SCADAPack… | ||
| CVE-2012-5474 | Med | 0.36 | 5.5 | 0.00 | Dec 30, 2019 | The file /etc/openstack-dashboard/local_settings within Red Hat OpenStack Platform 2.0 and RHOS Essex Release (python-django-horizon package before 2012.1.1) is world readable and exposes the secret key value. |
- risk 0.38cvss 5.9epss 0.01
HCL iNotes is susceptible to a sensitive cookie exposure vulnerability. This can allow an unauthenticated remote attacker to capture the cookie by intercepting its transmission within an http session. Fixes are available in HCL Domino and iNotes versions 10.0.1 FP6 and 11.0.1…
- risk 0.38cvss 5.8epss 0.01
Synology Router Manager (SRM) before 1.2.4-8081 does not set the Secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session.
- risk 0.38cvss 5.8epss 0.01
Synology DiskStation Manager (DSM) before 6.2.3-25426-2 does not set the Secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session.
- risk 0.38cvss 5.9epss 0.00
Barco ClickShare Button R9861500D01 devices before 1.9.0 allow Information exposure (issue 2 of 2).. The encryption key of the media content which is shared between a ClickShare Button and a ClickShare Base Unit is randomly generated for each new session and communicated over a…
- risk 0.38cvss 5.9epss 0.01
ikst versions before 1.1.2 download resources over HTTP, which leaves it vulnerable to MITM attacks.
- risk 0.38cvss 5.9epss 0.01
install-g-test downloads resources over HTTP, which leaves it vulnerable to MITM attacks.
- risk 0.38cvss 5.9epss 0.01
bionode-sra is a Node.js wrapper for SRA Toolkit. bionode-sra downloads data resources over HTTP, which leaves it vulnerable to MITM attacks.
- risk 0.38cvss 5.9epss 0.01
cobalt-cli downloads resources over HTTP, which leaves it vulnerable to MITM attacks.
- risk 0.38cvss 5.9epss 0.00
The Google I/O 2017 application before 5.1.4 for Android downloads multiple .json files from http://storage.googleapis.com without SSL, which makes it easier for man-in-the-middle attackers to spoof Feed and Schedule data by creating a modified blocks_v4.json file.
- risk 0.38cvss 5.9epss 0.01
The L2TP Client in MikroTik RouterOS versions 6.83.3 and 6.37.4 does not enable IPsec encryption after a reboot, which allows man-in-the-middle attackers to view transmitted data unencrypted and gain access to networks on the L2TP server by monitoring the packets for the…
- risk 0.37cvss 5.7epss 0.00
An issue was discovered in the COROS application through 3.8.12 for Android. Bluetooth pairing and bonding is neither initiated nor enforced by the application itself. Also, the watch does not enforce pairing and bonding. As a result, any data transmitted via BLE remains…
- risk 0.37cvss 5.7epss 0.00
Vulnerable data in transit in GE HealthCare EchoPAC products
- risk 0.37cvss 6.8epss 0.01
Moby is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon component (`dockerd`), which is developed as moby/moby is commonly referred to as…
- risk 0.37cvss 5.7epss 0.00
On systems running Arista EOS and CloudEOS with the affected release version, when using shared secret profiles the password configured for use by BiDirectional Forwarding Detection (BFD) will be leaked when displaying output over eAPI or other JSON outputs to other…
- risk 0.37cvss 5.7epss 0.00
A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Modicon M221 (all references, all versions) that could allow the attacker to find the password hash when the attacker has captured the traffic between EcoStruxure Machine - Basic software and Modicon M221…
- risk 0.37cvss 5.7epss 0.00
Cast in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android sent cookies to sites discovered via SSDP, which allowed an attacker on the local network segment to initiate connections to arbitrary URLs and observe any plaintext cookies…
- risk 0.36cvss 5.5epss 0.00
Jenkins AsakusaSatellite Plugin 0.1.1 and earlier does not mask AsakusaSatellite API keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.
- risk 0.36cvss 5.5epss 0.00
A vulnerability in Cisco Duo Epic for Hyperdrive could allow an authenticated, local attacker to view sensitive information in cleartext on an affected system. This vulnerability is due to improper storage of an unencrypted registry key. A low-privileged attacker could…
- risk 0.36cvss 5.5epss 0.00
Missing Encryption of Sensitive Data vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Process Expert (all versions, including all versions of EcoStruxure Hybrid DCS), and SCADAPack…
- risk 0.36cvss 5.5epss 0.00
The file /etc/openstack-dashboard/local_settings within Red Hat OpenStack Platform 2.0 and RHOS Essex Release (python-django-horizon package before 2012.1.1) is world readable and exposes the secret key value.