VYPR

CWE-311

Missing Encryption of Sensitive Data

ClassDraftLikelihood: High

Description

The product does not encrypt sensitive or critical information before storage or transmission.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-157 · CAPEC-158 · CAPEC-204 · CAPEC-31 · CAPEC-37 · CAPEC-383 · CAPEC-384 · CAPEC-385 · CAPEC-386 · CAPEC-387 · CAPEC-388 · CAPEC-477 · CAPEC-609 · CAPEC-65

CVEs mapped to this weakness (522)

page 26 of 27
  • CVE-2023-33833LowAug 31, 2023
    risk 0.19cvss 2.9epss 0.00

    IBM Security Verify Information Queue 10.0.4 and 10.0.5 stores sensitive information in plain clear text which can be read by a local user. IBM X-Force ID: 256013.

  • CVE-2019-0307LowJun 12, 2019
    risk 0.19cvss 2.4epss 0.02

    Diagnostics Agent in Solution Manager, version 7.2, stores several credentials such as SLD user connection as well as Solman user communication in the SAP Secure Storage file which is not encrypted by default. By decoding these credentials, an attacker with admin privileges…

  • CVE-2019-13922LowSep 13, 2019
    risk 0.18cvss 2.7epss 0.01

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). An attacker with administrative privileges can obtain the hash of a connected device's password. The security vulnerability could be exploited by an attacker with network access to the…

  • CVE-2018-25060LowDec 30, 2022
    risk 0.17cvss 3.7epss 0.01

    A vulnerability was found in Macaron csrf and classified as problematic. Affected by this issue is some unknown functionality of the file csrf.go. The manipulation of the argument Generate leads to sensitive cookie without secure attribute. The attack may be launched remotely.…

  • CVE-2023-39843LowAug 15, 2023
    risk 0.16cvss 2.4epss 0.00

    Missing encryption in the RFID tag of Suleve 5-in-1 Smart Door Lock v1.0 allows attackers to create a cloned tag via brief physical proximity to the original device.

  • CVE-2023-39842LowAug 15, 2023
    risk 0.16cvss 2.4epss 0.00

    Missing encryption in the RFID tag of Digoo DG-HAMB Smart Home Security System v1.0 allows attackers to create a cloned tag via brief physical proximity to the original device.

  • CVE-2019-1573LowApr 9, 2019
    risk 0.16cvss 2.5epss 0.00

    GlobalProtect Agent 4.1.0 for Windows and GlobalProtect Agent 4.1.10 and earlier for macOS may allow a local authenticated attacker who has compromised the end-user account and gained the ability to inspect memory, to access authentication and/or session tokens and replay them…

  • CVE-2020-8173LowNov 2, 2020
    risk 0.14cvss 2.2epss 0.00

    A too small set of random characters being used for encryption in Nextcloud Server 18.0.4 allowed decryption in shorter time than intended.

  • CVE-2025-47274LowMay 12, 2025
    risk 0.09cvss epss 0.00

    ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers. Due to the ordering of code used to start an MCP server container, versions of ToolHive prior to 0.0.33 inadvertently store secrets in the run config files which are…

  • CVE-2025-1243LowFeb 12, 2025
    risk 0.06cvss epss 0.00

    The Temporal api-go library prior to version 1.44.1 did not send `update response` information to Data Converter when the proxy package within the api-go module was used in a gRPC proxy prior to transmission. This resulted in information contained within the `update response`…

  • CVE-2025-63579HigJul 9, 2026
    risk 0.00cvss 7.5epss 0.00

    Unauthorized use of Kyocera printers, allows all information stored in the Kyocera address book to be exported. The security measure that encrypts incoming data ian be bypassed with this vulnerability, allowing encrypted data to be decrypted. Passwords and other sensitive…

  • CVE-2025-53653MedJul 9, 2025
    risk 0.00cvss 4.3epss 0.00

    Jenkins Aqua Security Scanner Plugin 3.2.8 and earlier stores Scanner Tokens for Aqua API unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.

  • CVE-2023-39954LowAug 10, 2023
    risk 0.00cvss 3.8epss 0.00

    user_oidc provides the OIDC connect user backend for Nextcloud, an open-source cloud platform. Starting in version 1.0.0 and prior to version 1.3.3, an attacker that obtained at least read access to a snapshot of the database can impersonate the Nextcloud server towards linked…

  • CVE-2023-28999MedApr 4, 2023
    risk 0.00cvss 6.9epss 0.01

    Nextcloud is an open-source productivity platform. In Nextcloud Desktop client 3.0.0 until 3.8.0, Nextcloud Android app 3.13.0 until 3.25.0, and Nextcloud iOS app 3.0.5 until 4.8.0, a malicious server administrator can gain full access to an end-to-end encrypted folder. They can…

  • CVE-2022-3251MedSep 21, 2022
    risk 0.00cvss 5.3epss 0.01

    Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository ikus060/minarca prior to 4.2.2.

  • CVE-2021-40642MedJun 29, 2022
    risk 0.00cvss 4.3epss 0.01

    Textpattern CMS v4.8.7 and older vulnerability exists through Sensitive Cookie in HTTPS Session Without 'Secure' Attribute via textpattern/lib/txplib_misc.php. The secure flag is not set for txp_login session cookie in the application. If the secure flag is not set, then the…

  • CVE-2022-31085MedJun 27, 2022
    risk 0.00cvss 6.1epss 0.00

    LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 the session files include the LDAP user name and password in clear text if the PHP OpenSSL extension is not installed or…

  • CVE-2021-3882MedOct 14, 2021
    risk 0.00cvss 6.8epss 0.01

    LedgerSMB does not set the 'Secure' attribute on the session authorization cookie when the client uses HTTPS and the LedgerSMB server is behind a reverse proxy. By tricking a user to use an unencrypted connection (HTTP), an attacker may be able to obtain the authentication data…

  • CVE-2020-12273HigApr 27, 2020
    risk 0.00cvss 7.5epss 0.01

    In TestLink 1.9.20, a crafted login.php viewer parameter exposes cleartext credentials.

  • CVE-2019-11405HigApr 22, 2019
    risk 0.00cvss 8.1epss 0.01

    OpenAPI Tools OpenAPI Generator before 4.0.0-20190419.052012-560 uses http:// URLs in various build.gradle, build.gradle.mustache, and build.sbt files, which may have caused insecurely resolved dependencies.