VYPR

CWE-311

Missing Encryption of Sensitive Data

ClassDraftLikelihood: High

Description

The product does not encrypt sensitive or critical information before storage or transmission.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-157 · CAPEC-158 · CAPEC-204 · CAPEC-31 · CAPEC-37 · CAPEC-383 · CAPEC-384 · CAPEC-385 · CAPEC-386 · CAPEC-387 · CAPEC-388 · CAPEC-477 · CAPEC-609 · CAPEC-65

CVEs mapped to this weakness (522)

page 19 of 27
  • CVE-2020-4126MedDec 1, 2020
    risk 0.38cvss 5.9epss 0.01

    HCL iNotes is susceptible to a sensitive cookie exposure vulnerability. This can allow an unauthenticated remote attacker to capture the cookie by intercepting its transmission within an http session. Fixes are available in HCL Domino and iNotes versions 10.0.1 FP6 and 11.0.1…

  • CVE-2020-27651MedOct 29, 2020
    risk 0.38cvss 5.8epss 0.01

    Synology Router Manager (SRM) before 1.2.4-8081 does not set the Secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session.

  • CVE-2020-27650MedOct 29, 2020
    risk 0.38cvss 5.8epss 0.01

    Synology DiskStation Manager (DSM) before 6.2.3-25426-2 does not set the Secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session.

  • CVE-2019-18833MedDec 17, 2019
    risk 0.38cvss 5.9epss 0.00

    Barco ClickShare Button R9861500D01 devices before 1.9.0 allow Information exposure (issue 2 of 2).. The encryption key of the media content which is shared between a ClickShare Button and a ClickShare Base Unit is randomly generated for each new session and communicated over a…

  • CVE-2017-16041MedJun 4, 2018
    risk 0.38cvss 5.9epss 0.01

    ikst versions before 1.1.2 download resources over HTTP, which leaves it vulnerable to MITM attacks.

  • CVE-2016-10630MedJun 1, 2018
    risk 0.38cvss 5.9epss 0.01

    install-g-test downloads resources over HTTP, which leaves it vulnerable to MITM attacks.

  • CVE-2016-10613MedJun 1, 2018
    risk 0.38cvss 5.9epss 0.01

    bionode-sra is a Node.js wrapper for SRA Toolkit. bionode-sra downloads data resources over HTTP, which leaves it vulnerable to MITM attacks.

  • CVE-2016-10597MedJun 1, 2018
    risk 0.38cvss 5.9epss 0.01

    cobalt-cli downloads resources over HTTP, which leaves it vulnerable to MITM attacks.

  • CVE-2017-9045MedMay 18, 2017
    risk 0.38cvss 5.9epss 0.00

    The Google I/O 2017 application before 5.1.4 for Android downloads multiple .json files from http://storage.googleapis.com without SSL, which makes it easier for man-in-the-middle attackers to spoof Feed and Schedule data by creating a modified blocks_v4.json file.

  • CVE-2017-6297MedFeb 27, 2017
    risk 0.38cvss 5.9epss 0.01

    The L2TP Client in MikroTik RouterOS versions 6.83.3 and 6.37.4 does not enable IPsec encryption after a reboot, which allows man-in-the-middle attackers to view transmitted data unencrypted and gain access to networks on the L2TP server by monitoring the packets for the…

  • CVE-2025-32875MedJun 20, 2025
    risk 0.37cvss 5.7epss 0.00

    An issue was discovered in the COROS application through 3.8.12 for Android. Bluetooth pairing and bonding is neither initiated nor enforced by the application itself. Also, the watch does not enforce pairing and bonding. As a result, any data transmitted via BLE remains…

  • CVE-2024-27106MedMay 14, 2024
    risk 0.37cvss 5.7epss 0.00

    Vulnerable data in transit in GE HealthCare EchoPAC products

  • CVE-2023-28841MedApr 4, 2023
    risk 0.37cvss 6.8epss 0.01

    Moby is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon component (`dockerd`), which is developed as moby/moby is commonly referred to as…

  • CVE-2021-28496MedOct 21, 2021
    risk 0.37cvss 5.7epss 0.00

    On systems running Arista EOS and CloudEOS with the affected release version, when using shared secret profiles the password configured for use by BiDirectional Forwarding Detection (BFD) will be leaked when displaying output over eAPI or other JSON outputs to other…

  • CVE-2020-7567MedNov 19, 2020
    risk 0.37cvss 5.7epss 0.00

    A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Modicon M221 (all references, all versions) that could allow the attacker to find the password hash when the attacker has captured the traffic between EcoStruxure Machine - Basic software and Modicon M221…

  • CVE-2017-5042MedApr 24, 2017
    risk 0.37cvss 5.7epss 0.00

    Cast in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android sent cookies to sites discovered via SSDP, which allowed an attacker on the local network segment to initiate connections to arbitrary URLs and observe any plaintext cookies…

  • CVE-2025-31728MedApr 2, 2025
    risk 0.36cvss 5.5epss 0.00

    Jenkins AsakusaSatellite Plugin 0.1.1 and earlier does not mask AsakusaSatellite API keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.

  • CVE-2024-20503MedSep 4, 2024
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in Cisco Duo Epic for Hyperdrive could allow an authenticated, local attacker to view sensitive information in cleartext on an affected system. This vulnerability is due to improper storage of an unencrypted registry key. A low-privileged attacker could…

  • CVE-2021-22782MedJul 14, 2021
    risk 0.36cvss 5.5epss 0.00

    Missing Encryption of Sensitive Data vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Process Expert (all versions, including all versions of EcoStruxure Hybrid DCS), and SCADAPack…

  • CVE-2012-5474MedDec 30, 2019
    risk 0.36cvss 5.5epss 0.00

    The file /etc/openstack-dashboard/local_settings within Red Hat OpenStack Platform 2.0 and RHOS Essex Release (python-django-horizon package before 2012.1.1) is world readable and exposes the secret key value.