VYPR

CWE-311

Missing Encryption of Sensitive Data

ClassDraftLikelihood: High

Description

The product does not encrypt sensitive or critical information before storage or transmission.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-157 · CAPEC-158 · CAPEC-204 · CAPEC-31 · CAPEC-37 · CAPEC-383 · CAPEC-384 · CAPEC-385 · CAPEC-386 · CAPEC-387 · CAPEC-388 · CAPEC-477 · CAPEC-609 · CAPEC-65

CVEs mapped to this weakness (522)

page 22 of 27
  • CVE-2022-26157MedFeb 28, 2022
    risk 0.34cvss 5.3epss 0.01

    An issue was discovered in the web application in Cherwell Service Management (CSM) 10.2.3. The ASP.NET_Sessionid cookie is not protected by the Secure flag. This makes it prone to interception by an attacker if traffic is sent over unencrypted channels.

  • CVE-2020-29024MedFeb 16, 2021
    risk 0.34cvss 5.3epss 0.01

    Sensitive Cookie in HTTPS Session Without 'Secure' Attribute vulnerability in (GTA) GoToAppliance of Secomea GateManager could allow an attacker to gain access to sensitive cookies. This issue affects: Secomea GateManager all versions prior to 9.3.

  • CVE-2020-15767MedSep 18, 2020
    risk 0.34cvss 5.3epss 0.01

    An issue was discovered in Gradle Enterprise before 2020.2.5. The cookie used to convey the CSRF prevention token is not annotated with the “secure” attribute, which allows an attacker with the ability to MITM plain HTTP requests to obtain it, if the user mistakenly uses a…

  • CVE-2019-4686MedAug 26, 2020
    risk 0.34cvss 5.3epss 0.00

    IBM Security Guardium Data Encryption (GDE) 3.0.0.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie…

  • CVE-2020-9062MedAug 21, 2020
    risk 0.34cvss 5.3epss 0.00

    Diebold Nixdorf ProCash 2100xe USB ATMs running Wincor Probase version 1.1.30 do not encrypt, authenticate, or verify the integrity of messages between the CCDM and the host computer, allowing an attacker with physical access to internal ATM components to commit deposit forgery…

  • CVE-2019-19464MedNov 30, 2019
    risk 0.34cvss 5.3epss 0.01

    The CBC Gem application before 9.24.1 for Android and before 9.26.0 for iOS has Unencrypted Analytics.

  • CVE-2018-10825MedMay 15, 2018
    risk 0.34cvss 5.3epss 0.00

    Mimo Baby 2 devices do not use authentication or encryption for the Bluetooth Low Energy (BLE) communication from a Turtle to a Lilypad, which allows attackers to inject fake information about the position and temperature of a baby via a replay or spoofing attack.

  • CVE-2023-52948MedSep 26, 2024
    risk 0.33cvss 5.0epss 0.00

    Missing encryption of sensitive data vulnerability in settings functionality in Synology Active Backup for Business Agent before 2.7.0-3221 allows local users to obtain user credential via unspecified vectors.

  • CVE-2024-38283MedJun 13, 2024
    risk 0.33cvss epss 0.00

    Sensitive customer information is stored in the device without encryption.

  • CVE-2024-28250MedMar 18, 2024
    risk 0.33cvss 6.1epss 0.00

    Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Starting in version 1.14.0 and prior to versions 1.14.8 and 1.15.2, In Cilium clusters with WireGuard enabled and traffic matching Layer 7 policies Wireguard-eligible traffic that is sent…

  • CVE-2024-28249MedMar 18, 2024
    risk 0.33cvss 6.1epss 0.00

    Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.13.13, 1.14.8, and 1.15.2, in Cilium clusters with IPsec enabled and traffic matching Layer 7 policies, IPsec-eligible traffic between a node's Envoy proxy and pods on…

  • CVE-2024-25631MedFeb 20, 2024
    risk 0.33cvss 6.1epss 0.00

    Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For Cilium users who have enabled an external kvstore and Wireguard transparent encryption, traffic between pods in the affected cluster is not encrypted. This issue affects Cilium v1.14…

  • CVE-2024-25630MedFeb 20, 2024
    risk 0.33cvss 6.1epss 0.00

    Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For Cilium users who are using CRDs to store Cilium state (the default configuration) and Wireguard transparent encryption, traffic to/from the Ingress and health endpoints is not…

  • CVE-2023-0690MedFeb 8, 2023
    risk 0.33cvss 5.0epss 0.00

    HashiCorp Boundary from 0.10.0 through 0.11.2 contain an issue where when using a PKI-based worker with a Key Management Service (KMS) defined in the configuration file, new credentials created after an automatic rotation may not have been encrypted via the intended KMS. This…

  • CVE-2023-37858MedAug 9, 2023
    risk 0.32cvss 4.9epss 0.00

    In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated, remote attacker with admin privileges is able to read hardcoded cryptographic keys allowing to decrypt an encrypted web application login password.

  • CVE-2023-22948MedApr 13, 2023
    risk 0.32cvss 4.9epss 0.00

    An issue was discovered in TigerGraph Enterprise Free Edition 3.x. There is unsecured read access to an SSH private key. Any code that runs as the tigergraph user is able to read the SSH private key. With this, an attacker is granted password-less SSH access to all machines in…

  • CVE-2022-40295MedOct 31, 2022
    risk 0.32cvss 4.9epss 0.00

    The application was vulnerable to an authenticated information disclosure, allowing administrators to view unsalted user passwords, which could lead to the compromise of plaintext passwords via offline attacks.

  • CVE-2018-17287MedApr 18, 2019
    risk 0.32cvss 4.9epss 0.00

    In Kofax Front Office Server Administration Console 4.1.1.11.0.5212, some fields, such as passwords, are obfuscated in the front-end, but the cleartext value can be exfiltrated by using the back-end "download" feature, as demonstrated by an mfp.password downloadsettingvalue…

  • CVE-2026-55568MedJun 23, 2026
    risk 0.31cvss 5.9epss 0.00

    Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, in certain configurations, traffic expected to be protected by TLS on the hop to the proxy is transmitted in cleartext. Proxy authentication credentials (the Proxy-Authorization header, proxy userinfo in the proxy URL, or…

  • CVE-2024-41982MedAug 12, 2025
    risk 0.31cvss 4.8epss 0.00

    A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Audit (All versions >= V13.2 < V2506), SOA Cockpit (All versions >= V13.2 < V2506). The affected application does not have adequate encryption of sensitive…