VYPR

CWE-311

Missing Encryption of Sensitive Data

ClassDraftLikelihood: High

Description

The product does not encrypt sensitive or critical information before storage or transmission.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-157 · CAPEC-158 · CAPEC-204 · CAPEC-31 · CAPEC-37 · CAPEC-383 · CAPEC-384 · CAPEC-385 · CAPEC-386 · CAPEC-387 · CAPEC-388 · CAPEC-477 · CAPEC-609 · CAPEC-65

CVEs mapped to this weakness (522)

page 23 of 27
  • CVE-2023-37943MedJul 12, 2023
    risk 0.31cvss 5.9epss 0.00

    Jenkins Active Directory Plugin 2.30 and earlier ignores the "Require TLS" and "StartTls" options and always performs the connection test to Active directory unencrypted, allowing attackers able to capture network traffic between the Jenkins controller and Active Directory…

  • CVE-2022-41627MedOct 27, 2022
    risk 0.31cvss 4.8epss 0.00

    The physical IoT device of the AliveCor's KardiaMobile, a smartphone-based personal electrocardiogram (EKG) has no encryption for its data-over-sound protocols. Exploiting this vulnerability could allow an attacker to read patient EKG results or create a denial-of-service…

  • CVE-2020-35168MedJul 11, 2022
    risk 0.31cvss 4.7epss 0.00

    Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timing Discrepancy Vulnerability.

  • CVE-2025-13453MedJan 14, 2026
    risk 0.30cvss 4.6epss 0.00

    A potential vulnerability was reported in some ThinkPlus USB drives that could allow a user with physical access to read data stored on the drive.

  • CVE-2025-65825MedDec 10, 2025
    risk 0.30cvss 4.6epss 0.00

    The firmware on the basestation of the Meatmeet is not encrypted. An adversary with physical access to the Meatmeet device can disassemble the device, connect over UART, and retrieve the firmware dump for analysis. Within the NVS partition they may discover the credentials of…

  • CVE-2025-10227MedSep 10, 2025
    risk 0.30cvss 4.6epss 0.00

    Missing Encryption of Sensitive Data (CWE-311) in the Object Archive component in AxxonSoft Axxon One (C-Werk) before 2.0.8 on Windows and Linux allows a local attacker with access to exported storage or stolen physical drives to extract sensitive archive data in plaintext via…

  • CVE-2024-7142MedJan 10, 2025
    risk 0.30cvss 4.6epss 0.00

    On Arista CloudVision Appliance (CVA) affected releases running on appliances that support hardware disk encryption (DCA-350E-CV only), the disk encryption might not be successfully performed. This results in the disks remaining unsecured and data on them

  • CVE-2023-39841MedAug 15, 2023
    risk 0.30cvss 4.6epss 0.00

    Missing encryption in the RFID tag of Etekcity 3-in-1 Smart Door Lock v1.0 allows attackers to create a cloned tag via brief physical proximity to the original device.

  • CVE-2022-0183MedJan 17, 2022
    risk 0.30cvss 4.6epss 0.00

    Missing encryption of sensitive data vulnerability in 'MIRUPASS' PW10 firmware all versions and 'MIRUPASS' PW20 firmware all versions allows an attacker who can physically access the device to obtain the stored passwords.

  • CVE-2019-18254MedJun 29, 2020
    risk 0.30cvss 4.6epss 0.00

    BIOTRONIK CardioMessenger II, The affected products do not encrypt sensitive information while at rest. An attacker with physical access to the CardioMessenger can disclose medical measurement data and the serial number from the implanted cardiac device the CardioMessenger is…

  • CVE-2019-11836MedMay 9, 2019
    risk 0.30cvss 4.6epss 0.00

    The Rediffmail (aka com.rediff.mail.and) application 2.2.6 for Android has cleartext mail content in file storage, persisting after a logout.

  • CVE-2019-1589MedMay 3, 2019
    risk 0.30cvss 4.6epss 0.00

    A vulnerability in the Trusted Platform Module (TPM) functionality of software for Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an unauthenticated, local attacker with physical access to view sensitive information on an…

  • CVE-2018-18984MedDec 14, 2018
    risk 0.30cvss 4.6epss 0.00

    Medtronic CareLink and Encore Programmers do not encrypt or do not sufficiently encrypt sensitive PII and PHI information while at rest .

  • CVE-2018-8849MedMay 18, 2018
    risk 0.30cvss 4.6epss 0.00

    Medtronic N'Vision Clinician Programmer 8840 N'Vision Clinician Programme and 8870 N'Vision removable Application Card do not encrypt PII and PHI while at rest.

  • CVE-2017-14012MedMay 1, 2018
    risk 0.30cvss 4.6epss 0.00

    Boston Scientific ZOOM LATITUDE PRM Model 3120 does not encrypt PHI at rest. CVSS v3 base score: 4.6; CVSS vector string: AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N.

  • CVE-2018-4847MedApr 23, 2018
    risk 0.30cvss 4.6epss 0.00

    A vulnerability has been identified in SIMATIC WinCC OA Operator iOS App (All versions < V1.4). Insufficient protection of sensitive information (e.g. session key for accessing server) in Siemens WinCC OA Operator iOS app could allow an attacker with physical access to the…

  • CVE-2017-8769MedMay 18, 2017
    risk 0.30cvss 4.6epss 0.00

    Facebook WhatsApp Messenger before 2.16.323 for Android uses the SD card for cleartext storage of files (Audio, Documents, Images, Video, and Voice Notes) associated with a chat, even after that chat is deleted. There may be users who expect file deletion to occur upon chat…

  • CVE-2025-43274MedJul 30, 2025
    risk 0.29cvss 4.4epss 0.00

    A privacy issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.6. A sandboxed process may be able to circumvent sandbox restrictions.

  • CVE-2023-33228MedNov 1, 2023
    risk 0.29cvss 4.5epss 0.00

    The SolarWinds Network Configuration Manager was susceptible to the Exposure of Sensitive Information Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to obtain sensitive information.

  • CVE-2021-20567MedJun 16, 2021
    risk 0.29cvss 4.4epss 0.00

    IBM Resilient SOAR V38.0 could allow a local privileged attacker to obtain sensitive information due to improper or nonexisting encryption.IBM X-Force ID: 199239.