VYPR

CWE-311

Missing Encryption of Sensitive Data

ClassDraftLikelihood: High

Description

The product does not encrypt sensitive or critical information before storage or transmission.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-157 · CAPEC-158 · CAPEC-204 · CAPEC-31 · CAPEC-37 · CAPEC-383 · CAPEC-384 · CAPEC-385 · CAPEC-386 · CAPEC-387 · CAPEC-388 · CAPEC-477 · CAPEC-609 · CAPEC-65

CVEs mapped to this weakness (530)

page 22 of 27
  • CVE-2020-15344MedSep 29, 2022
    risk 0.34cvss 5.3epss 0.01

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_get_user_id_and_key API.

  • CVE-2020-15343MedSep 29, 2022
    risk 0.34cvss 5.3epss 0.01

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_install_user_key API.

  • CVE-2020-15342MedSep 29, 2022
    risk 0.34cvss 5.3epss 0.01

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_install_user API.

  • CVE-2020-15330MedSep 29, 2022
    risk 0.34cvss 5.3epss 0.01

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded APP_KEY in /opt/axess/etc/default/axess.

  • CVE-2022-39014MedSep 13, 2022
    risk 0.34cvss 5.3epss 0.00

    Under certain conditions SAP BusinessObjects Business Intelligence Platform Central Management Console (CMC) - version 430, allows an attacker to access certain unencrypted sensitive parameters which would otherwise be restricted.

  • CVE-2022-26157MedFeb 28, 2022
    risk 0.34cvss 5.3epss 0.01

    An issue was discovered in the web application in Cherwell Service Management (CSM) 10.2.3. The ASP.NET_Sessionid cookie is not protected by the Secure flag. This makes it prone to interception by an attacker if traffic is sent over unencrypted channels.

  • CVE-2020-29024MedFeb 16, 2021
    risk 0.34cvss 5.3epss 0.01

    Sensitive Cookie in HTTPS Session Without 'Secure' Attribute vulnerability in (GTA) GoToAppliance of Secomea GateManager could allow an attacker to gain access to sensitive cookies. This issue affects: Secomea GateManager all versions prior to 9.3.

  • CVE-2020-15767MedSep 18, 2020
    risk 0.34cvss 5.3epss 0.01

    An issue was discovered in Gradle Enterprise before 2020.2.5. The cookie used to convey the CSRF prevention token is not annotated with the “secure” attribute, which allows an attacker with the ability to MITM plain HTTP requests to obtain it, if the user mistakenly uses a…

  • CVE-2019-4686MedAug 26, 2020
    risk 0.34cvss 5.3epss 0.00

    IBM Security Guardium Data Encryption (GDE) 3.0.0.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie…

  • CVE-2020-9062MedAug 21, 2020
    risk 0.34cvss 5.3epss 0.00

    Diebold Nixdorf ProCash 2100xe USB ATMs running Wincor Probase version 1.1.30 do not encrypt, authenticate, or verify the integrity of messages between the CCDM and the host computer, allowing an attacker with physical access to internal ATM components to commit deposit forgery…

  • CVE-2019-19464MedNov 30, 2019
    risk 0.34cvss 5.3epss 0.01

    The CBC Gem application before 9.24.1 for Android and before 9.26.0 for iOS has Unencrypted Analytics.

  • CVE-2018-10825MedMay 15, 2018
    risk 0.34cvss 5.3epss 0.00

    Mimo Baby 2 devices do not use authentication or encryption for the Bluetooth Low Energy (BLE) communication from a Turtle to a Lilypad, which allows attackers to inject fake information about the position and temperature of a baby via a replay or spoofing attack.

  • CVE-2023-52948MedSep 26, 2024
    risk 0.33cvss 5.0epss 0.00

    Missing encryption of sensitive data vulnerability in settings functionality in Synology Active Backup for Business Agent before 2.7.0-3221 allows local users to obtain user credential via unspecified vectors.

  • CVE-2024-38283MedJun 13, 2024
    risk 0.33cvss —epss 0.00

    Sensitive customer information is stored in the device without encryption.

  • CVE-2024-28250MedMar 18, 2024
    risk 0.33cvss 6.1epss 0.00

    Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Starting in version 1.14.0 and prior to versions 1.14.8 and 1.15.2, In Cilium clusters with WireGuard enabled and traffic matching Layer 7 policies Wireguard-eligible traffic that is sent…

  • CVE-2024-28249MedMar 18, 2024
    risk 0.33cvss 6.1epss 0.00

    Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.13.13, 1.14.8, and 1.15.2, in Cilium clusters with IPsec enabled and traffic matching Layer 7 policies, IPsec-eligible traffic between a node's Envoy proxy and pods on…

  • CVE-2024-25631MedFeb 20, 2024
    risk 0.33cvss 6.1epss 0.00

    Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For Cilium users who have enabled an external kvstore and Wireguard transparent encryption, traffic between pods in the affected cluster is not encrypted. This issue affects Cilium v1.14…

  • CVE-2024-25630MedFeb 20, 2024
    risk 0.33cvss 6.1epss 0.00

    Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For Cilium users who are using CRDs to store Cilium state (the default configuration) and Wireguard transparent encryption, traffic to/from the Ingress and health endpoints is not…

  • CVE-2023-0690MedFeb 8, 2023
    risk 0.33cvss 5.0epss 0.00

    HashiCorp Boundary from 0.10.0 through 0.11.2 contain an issue where when using a PKI-based worker with a Key Management Service (KMS) defined in the configuration file, new credentials created after an automatic rotation may not have been encrypted via the intended KMS. This…

  • CVE-2023-37858MedAug 9, 2023
    risk 0.32cvss 4.9epss 0.00

    In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated, remote attacker with admin privileges is able to read hardcoded cryptographic keys allowing to decrypt an encrypted web application login password.