VYPR

CWE-311

Missing Encryption of Sensitive Data

ClassDraftLikelihood: High

Description

The product does not encrypt sensitive or critical information before storage or transmission.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-157 · CAPEC-158 · CAPEC-204 · CAPEC-31 · CAPEC-37 · CAPEC-383 · CAPEC-384 · CAPEC-385 · CAPEC-386 · CAPEC-387 · CAPEC-388 · CAPEC-477 · CAPEC-609 · CAPEC-65

CVEs mapped to this weakness (530)

page 25 of 27
  • CVE-2019-4704MedJul 1, 2020
    risk 0.28cvss 4.3epss 0.01

    IBM Security Identity Manager Virtual Appliance 7.0.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie…

  • CVE-2017-8168MedNov 22, 2017
    risk 0.28cvss 4.3epss 0.00

    FusionSphere OpenStack with software V100R006C00SPC102(NFV) and V100R006C10 have an information leak vulnerability. Due to an incorrect configuration item, the information transmitted by a transmission channel is not encrypted. An attacker accessing the internal network may…

  • CVE-2026-53442MedJun 10, 2026
    risk 0.27cvss 5.3epss 0.00

    Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not encrypt secrets from POST config.xml submissions before storing them in job configurations unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read…

  • CVE-2023-33837MedOct 23, 2023
    risk 0.27cvss 4.1epss 0.00

    IBM Security Verify Governance 10.0 does not encrypt sensitive or critical information before storage or transmission. IBM X-Force ID: 256020.

  • CVE-2023-43618MedSep 20, 2023
    risk 0.27cvss 5.3epss 0.00

    An issue was discovered in Croc through 9.6.5. The protocol requires a sender to provide its local IP addresses in cleartext via an ips? message.

  • CVE-2022-3250MedSep 21, 2022
    risk 0.27cvss 5.3epss 0.01

    Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository ikus060/rdiffweb prior to 2.4.6.

  • CVE-2022-26390MedSep 9, 2022
    risk 0.27cvss 4.2epss 0.00

    The Baxter Spectrum Wireless Battery Module (WBM) stores network credentials and PHI (only applicable to Spectrum IQ pumps using auto programming) in unencrypted form. An attacker with physical access to a device that hasn't had all data and settings erased may be able to…

  • CVE-2020-8150MedNov 9, 2020
    risk 0.27cvss 4.1epss 0.00

    A cryptographic issue in Nextcloud Server 19.0.1 allowed an attacker to downgrade the encryption scheme and break the integrity of encrypted files.

  • CVE-2024-23444MedJul 31, 2024
    risk 0.25cvss 4.9epss 0.00

    It was discovered by Elastic engineering that when elasticsearch-certutil CLI tool is used with the csr option in order to create a new Certificate Signing Requests, the associated private key that is generated is stored on disk unencrypted even if the --pass parameter is passed…

  • CVE-2019-10363MedJul 31, 2019
    risk 0.25cvss 4.9epss 0.01

    Jenkins Configuration as Code Plugin 1.24 and earlier did not reliably identify sensitive values expected to be exported in their encrypted form.

  • CVE-2026-19891LowAug 15, 2026
    risk 0.24cvss 3.7epss 0.00

    A vulnerability was determined in TRENDnet TEW-WLC100 2.05b02. This affects an unknown function of the file /etc/racoon.conf of the component IKE Phase 1 Aggressive Mode. This manipulation of the argument exchange_mode causes missing encryption of sensitive data. It is possible…

  • CVE-2025-13053LowDec 12, 2025
    risk 0.24cvss 3.7epss 0.00

    When a user configures the NAS to retrieve UPS status or control the UPS, a non-enforced TLS certificate verification can allow an attacker able to intercept network traffic between the client and server can perform a man-in-the-middle (MITM) attack, which may obtain the…

  • CVE-2025-59410LowSep 17, 2025
    risk 0.24cvss 3.7epss 0.00

    Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the code in the scheduler for downloading a tiny file is hard coded to use the HTTP protocol, rather than HTTPS. This means that an attacker could perform a Man-in-the-Middle…

  • CVE-2025-8763LowAug 9, 2025
    risk 0.24cvss 3.7epss 0.00

    A vulnerability was found in Ruijie EG306MG 3.0(1)B11P309. It has been rated as problematic. This issue affects some unknown processing of the file /etc/strongswan.conf of the component strongSwan. The manipulation of the argument i_dont_care_about_security_and_use_aggressive_mod…

  • CVE-2023-4384LowAug 16, 2023
    risk 0.24cvss 3.7epss 0.00

    A vulnerability has been found in MaximaTech Portal Executivo 21.9.1.140 and classified as problematic. This vulnerability affects unknown code of the component Cookie Handler. The manipulation leads to missing encryption of sensitive data. The attack can be initiated remotely.…

  • CVE-2023-33849LowJun 7, 2023
    risk 0.24cvss 3.7epss 0.00

    IBM TXSeries for Multiplatforms 8.1, 8.2, 9.1, CICS TX Standard, 11.1, CICS TX Advanced 10.1, and 11.1 could transmit sensitive information in query parameters that could be intercepted using man in the middle techniques. IBM X-Force ID: 257105.

  • CVE-2019-4214LowNov 22, 2019
    risk 0.24cvss 3.7epss 0.00

    IBM SmartCloud Analytics 1.3.1 through 1.3.5 does not set the secure attribute on authorization tokens or session cookies. This could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 159185.

  • CVE-2019-4171LowSep 17, 2019
    risk 0.24cvss 3.7epss 0.01

    IBM Cognos Controller 10.3.0, 10.3.1, 10.4.0, and 10.4.1 does not set the secure attribute on authorization tokens or session cookies. This could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 158876.

  • CVE-2026-81681MedAug 27, 2026
    risk 0.23cvss 4.6epss 0.00

    openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 advertise a portable USB workspace as an 'Encrypted USB Workspace' with AES-256-GCM encryption and write a marker declaring the workspace encrypted, but the workspace directory is actually stored in cleartext and…

  • CVE-2019-19090LowApr 2, 2020
    risk 0.23cvss 3.5epss 0.01

    For ABB eSOMS versions 4.0 to 6.0.2, the Secure Flag is not set in the HTTP response header. Unencrypted connections might access the cookie information, thus making it susceptible to eavesdropping.