VYPR

CWE-311

Missing Encryption of Sensitive Data

ClassDraftLikelihood: High

Description

The product does not encrypt sensitive or critical information before storage or transmission.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-157 · CAPEC-158 · CAPEC-204 · CAPEC-31 · CAPEC-37 · CAPEC-383 · CAPEC-384 · CAPEC-385 · CAPEC-386 · CAPEC-387 · CAPEC-388 · CAPEC-477 · CAPEC-609 · CAPEC-65

CVEs mapped to this weakness (530)

page 21 of 27
  • CVE-2019-9681MedSep 17, 2019
    risk 0.35cvss 5.3epss 0.01

    Online upgrade information in some firmware packages of Dahua products is not encrypted. Attackers can obtain this information by analyzing firmware packages by specific means. Affected products include: IPC-HDW1X2X,IPC-HFW1X2X,IPC-HDW2X2X,IPC-HFW2X2X,IPC-HDW4X2X,IPC-HFW4X2X,IPC-…

  • CVE-2019-1692MedMay 3, 2019
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) Software could allow an unauthenticated, remote attacker to access sensitive system usage information. The vulnerability is due to a lack of proper data protection…

  • CVE-2019-1003089MedApr 4, 2019
    risk 0.35cvss 6.5epss 0.01

    Jenkins Upload to pgyer Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.

  • CVE-2018-17563MedApr 1, 2019
    risk 0.35cvss 5.3epss 0.01

    A Malformed Input String to /cgi-bin/api-get_line_status on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to dump the device's configuration in cleartext.

  • CVE-2018-5482MedMar 4, 2019
    risk 0.35cvss 5.3epss 0.01

    NetApp SnapCenter Server prior to 4.1 does not set the secure flag for a sensitive cookie in an HTTPS session which can allow the transmission of the cookie in plain text over an unencrypted channel.

  • CVE-2018-6976MedSep 11, 2018
    risk 0.35cvss 5.3epss 0.01

    The VMware Content Locker for iOS prior to 4.14 contains a data protection vulnerability in the SQLite database. This vulnerability relates to unencrypted filenames and associated metadata in SQLite database for the Content Locker.

  • CVE-2025-31977MedAug 28, 2025
    risk 0.34cvss 5.3epss 0.00

    HCL BigFix SM is affected by cryptographic weakness due to weak or outdated encryption algorithms.  An attacker with network access could exploit this weakness to decrypt or manipulate encrypted communications under certain conditions.

  • CVE-2023-52950MedSep 26, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing encryption of sensitive data vulnerability in login component in Synology Active Backup for Business Agent before 2.7.0-3221 allows adjacent man-in-the-middle attackers to obtain user credential via unspecified vectors.

  • CVE-2024-41124MedJul 19, 2024
    risk 0.34cvss 6.3epss 0.00

    Puncia is the Official CLI utility for Subdomain Center & Exploit Observer. `API_URLS` is utilizing HTTP instead of HTTPS for communication that can lead to issues like Eavesdropping, Data Tampering, Unauthorized Data Access & MITM Attacks. This issue has been addressed in…

  • CVE-2023-49927MedJun 5, 2024
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, Exynos 990, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 9110, Exynos W920, Exynos Modem 5123, Exynos Modem 5300. The baseband…

  • CVE-2022-22386MedOct 17, 2023
    risk 0.34cvss 5.3epss 0.00

    IBM Security Verify Privilege On-Premises 11.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the…

  • CVE-2022-22377MedOct 17, 2023
    risk 0.34cvss 5.3epss 0.00

    IBM Security Verify Privilege On-Premises 11.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the…

  • CVE-2022-33161MedOct 14, 2023
    risk 0.34cvss 5.3epss 0.00

    IBM Security Directory Server 6.4.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle…

  • CVE-2023-23371MedOct 6, 2023
    risk 0.34cvss 5.2epss 0.00

    A cleartext transmission of sensitive information vulnerability has been reported to affect QVPN Device Client. If exploited, the vulnerability could allow local authenticated administrators to read sensitive data via unspecified vectors. We have already fixed the vulnerability…

  • CVE-2023-40251MedAug 17, 2023
    risk 0.34cvss 5.2epss 0.00

    Missing Encryption of Sensitive Data vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.0, Genians Genian NAC Suite V5.0, Genians Genian ZTNA allows Man in the Middle Attack.This issue affects Genian NAC V4.0: from V4.0.0 through V4.0.155; Genian NAC V5.0: from…

  • CVE-2023-21404MedMay 8, 2023
    risk 0.34cvss 5.3epss 0.00

    AXIS OS 11.0.X - 11.3.x use a static RSA key in legacy LUA-components to protect Axis-specific source code. The static RSA key is not used in any other secure communication nor can it be used to compromise the device or any customer data.

  • CVE-2023-23127MedFeb 1, 2023
    risk 0.34cvss 5.3epss 0.00

    In Connectwise Control 22.8.10013.8329, the login page does not implement HSTS headers therefore not enforcing HTTPS. NOTE: the vendor's position is that, by design, this is controlled by a configuration option in which a customer can choose to use HTTP (rather than HTTPS)…

  • CVE-2022-47715MedFeb 1, 2023
    risk 0.34cvss 5.3epss 0.00

    In Last Yard 22.09.8-1, the cookie can be stolen via via unencrypted traffic.

  • CVE-2020-15346MedSep 29, 2022
    risk 0.34cvss 5.3epss 0.01

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a /live/GLOBALS API with the CLOUDCNM key.

  • CVE-2020-15345MedSep 29, 2022
    risk 0.34cvss 5.3epss 0.01

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_get_instances_for_update API.