CWE-311— Missing Encryption of Sensitive Data
The product does not encrypt sensitive or critical information before storage or transmission.— MITRE CWE catalog
564 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-311page 10 of 12
- CVE-2023-32290HIGHCVSS 7.5EG 7.52023-05-07
The myMail app through 14.30 for iOS sends cleartext credentials in a situation where STARTTLS is expected by a server.
- CVE-2023-32982MEDIUMCVSS 4.3EG 4.32023-05-16
Jenkins Ansible Plugin 204.v8191fd551eb_f and earlier stores extra variables unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins contro…
- CVE-2023-33037HIGHCVSS 7.1EG 7.12024-01-02
Cryptographic issue in Automotive while unwrapping the key secs2d and verifying with RPMB data.
- CVE-2023-33228MEDIUMCVSS 4.5EG 4.52023-11-01
The SolarWinds Network Configuration Manager was susceptible to the Exposure of Sensitive Information Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to obtain sensitive information.
- CVE-2023-33833LOWCVSS 2.9EG 2.92023-08-31
IBM Security Verify Information Queue 10.0.4 and 10.0.5 stores sensitive information in plain clear text which can be read by a local user. IBM X-Force ID: 256013.
- CVE-2023-33837MEDIUMCVSS 4.1EG 4.12023-10-23
IBM Security Verify Governance 10.0 does not encrypt sensitive or critical information before storage or transmission. IBM X-Force ID: 256020.
- CVE-2023-33849LOWCVSS 3.7EG 3.72023-06-07
IBM TXSeries for Multiplatforms 8.1, 8.2, 9.1, CICS TX Standard, 11.1, CICS TX Advanced 10.1, and 11.1 could transmit sensitive information in query parameters that could be intercepted using man in the middle techniques. IBM X-Force ID: …
- CVE-2023-34258HIGHCVSS 7.5EG 7.52023-05-31
An issue was discovered in BMC Patrol before 22.1.00. The agent's configuration can be remotely queried. This configuration contains the Patrol account password, encrypted with a default AES key. This account can then be used to achieve re…
- CVE-2023-35888MEDIUMCVSS 5.9EG 5.92024-03-20
IBM Security Verify Governance 10.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive …
- CVE-2023-37192HIGHCVSS 7.5EG 7.52023-07-07
Memory management and protection issues in Bitcoin Core v22 allows attackers to modify the stored sending address within the app's memory, potentially allowing them to redirect Bitcoin transactions to wallets of their own choosing.
- CVE-2023-37405MEDIUMCVSS 6.5EG 6.52025-03-27
IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.36 iFix1, 2.3.3.6 iFix2, 2.3.3.7, 2.3.3.7 iFix1, 2.3.4.0, and 2.3.4.1 stores sensitive data in memory, that could be obtained by an unauthorized user.
- CVE-2023-37858MEDIUMCVSS 4.9EG 4.92023-08-09
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated, remote attacker with admin privileges is able to read hardcoded cryptographic keys allowing to decrypt an encrypted web application login password.…
- CVE-2023-37943MEDIUMCVSS 5.9EG 5.92023-07-12
Jenkins Active Directory Plugin 2.30 and earlier ignores the "Require TLS" and "StartTls" options and always performs the connection test to Active directory unencrypted, allowing attackers able to capture network traffic between the Jenki…
- CVE-2023-38267MEDIUMCVSS 6.2EG 6.22024-01-11
IBM Security Access Manager Appliance (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.6.1) could allow a local user to possibly elevate their privileges due to sensitive configurat…
- CVE-2023-38688HIGHCVSS 7.5EG 7.52023-08-04
twitch-tui provides Twitch chat in a terminal. Prior to version 2.4.1, the connection is not using TLS for communication. In the configuration of the irc connection, the software disables TLS, which makes all communication to Twitch IRC se…
- CVE-2023-38699CRITICALCVSS 9.1EG 9.12023-08-04
MindsDB's AI Virtual Database allows developers to connect any AI/ML model to any datasource. Prior to version 23.7.4.0, a call to requests with `verify=False` disables SSL certificate checks. This rule enforces always verifying SSL certif…
- CVE-2023-39841MEDIUMCVSS 4.6EG 4.62023-08-15
Missing encryption in the RFID tag of Etekcity 3-in-1 Smart Door Lock v1.0 allows attackers to create a cloned tag via brief physical proximity to the original device.
- CVE-2023-39842LOWCVSS 2.4EG 2.42023-08-15
Missing encryption in the RFID tag of Digoo DG-HAMB Smart Home Security System v1.0 allows attackers to create a cloned tag via brief physical proximity to the original device.
- CVE-2023-39843LOWCVSS 2.4EG 2.42023-08-15
Missing encryption in the RFID tag of Suleve 5-in-1 Smart Door Lock v1.0 allows attackers to create a cloned tag via brief physical proximity to the original device.
- CVE-2023-39954LOWCVSS 3.8EG 3.82023-08-10
user_oidc provides the OIDC connect user backend for Nextcloud, an open-source cloud platform. Starting in version 1.0.0 and prior to version 1.3.3, an attacker that obtained at least read access to a snapshot of the database can impersona…
- CVE-2023-40251MEDIUMCVSS 5.2EG 5.22023-08-17
Missing Encryption of Sensitive Data vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.0, Genians Genian NAC Suite V5.0, Genians Genian ZTNA allows Man in the Middle Attack.This issue affects Genian NAC V4.0: from V4.0.0 thro…
- CVE-2023-41095CRITICALCVSS 9.1EG 9.12023-10-26
Missing Encryption of Security Keys vulnerability in Silicon Labs OpenThread SDK on 32 bit, ARM (SecureVault High modules) allows potential modification or extraction of network credentials stored in flash. This issue affects Silicon Labs …
- CVE-2023-41096MEDIUMCVSS 6.1EG 6.82023-10-26
Missing Encryption of Security Keys vulnerability in Silicon Labs Ember ZNet SDK on 32 bit, ARM (SecureVault High modules) allows potential modification or extraction of network credentials stored in flash. This issue affects Silicon La…
- CVE-2023-42019MEDIUMCVSS 5.9EG 5.92023-12-01
IBM InfoSphere Information Server 11.7 could allow a remote attacker to cause a denial of service due to improper input validation. IBM X-Force ID: 265161.
- CVE-2023-43618MEDIUMCVSS 5.3EG 5.32023-09-20
An issue was discovered in Croc through 9.6.5. The protocol requires a sender to provide its local IP addresses in cleartext via an ips? message.
- CVE-2023-4384MEDIUMCVSS 5.9EG 5.92023-08-16
A vulnerability has been found in MaximaTech Portal Executivo 21.9.1.140 and classified as problematic. This vulnerability affects unknown code of the component Cookie Handler. The manipulation leads to missing encryption of sensitive data…
- CVE-2023-44098HIGHCVSS 7.5EG 7.52023-11-08
Vulnerability of missing encryption in the card management module. Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2023-4420CRITICALCVSS 7.4EG 9.82023-08-24
A remote unprivileged attacker can intercept the communication via e.g. Man-In-The-Middle, due to the absence of Transport Layer Security (TLS) in the SICK LMS5xx. This lack of encryption in the communication channel can lead to the unauth…
- CVE-2023-4537HIGHCVSS 7.4EG 7.42024-02-15
Comarch ERP XL client is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unencrypted communication vulnerable to data interception and modification. This issue affects ERP XL: from 2020.2.2 throug…
- CVE-2023-4580MEDIUMCVSS 6.5EG 6.52023-09-11
Push notifications stored on disk in private browsing mode were not being encrypted potentially allowing the leak of sensitive information. This vulnerability affects Firefox < 117, Firefox ESR < 115.2, and Thunderbird < 115.2.
- CVE-2023-46219MEDIUMCVSS 5.3EG 5.32023-12-12
When saving HSTS data to an excessively long file name, curl could end up removing all contents, making subsequent requests using that file unaware of the HSTS status they should otherwise use.
- CVE-2023-49927MEDIUMCVSS 5.3EG 5.32024-06-05
An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, Exynos 990, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 9110, Exynos W920, Exynos Modem 512…
- CVE-2023-50126MEDIUMCVSS 6.5EG 6.52024-01-11
Missing encryption in the RFID tags of the Hozard alarm system (Alarmsysteem) v1.0 allow attackers to create a cloned tag via brief physical proximity to one of the original tags, which results in an attacker being able to bring the alarm …
- CVE-2023-50129MEDIUMCVSS 6.5EG 6.52024-01-11
Missing encryption in the NFC tags of the Flient Smart Door Lock v1.0 allows attackers to create a cloned tag via brief physical proximity to the original tags, which results in an attacker gaining access to the perimeter.
- CVE-2023-52948MEDIUMCVSS 5.0EG 5.02024-09-26
Missing encryption of sensitive data vulnerability in settings functionality in Synology Active Backup for Business Agent before 2.7.0-3221 allows local users to obtain user credential via unspecified vectors.
- CVE-2023-52950MEDIUMCVSS 5.3EG 5.32024-09-26
Missing encryption of sensitive data vulnerability in login component in Synology Active Backup for Business Agent before 2.7.0-3221 allows adjacent man-in-the-middle attackers to obtain user credential via unspecified vectors.
- CVE-2023-6339CRITICALCVSS 9.8EG 10.02024-01-02
Google Nest WiFi Pro root code-execution & user-data compromise
- CVE-2024-0220HIGHCVSS 8.3EG 8.32024-02-22
B&R Automation Studio Upgrade Service and B&R Technology Guarding use insufficient cryptography for communication to the upgrade and the licensing servers. A network-based attacker could exploit the vulnerability to execute arbitrary code …
- CVE-2024-20503MEDIUMCVSS 5.5EG 5.52024-09-04
A vulnerability in Cisco Duo Epic for Hyperdrive could allow an authenticated, local attacker to view sensitive information in cleartext on an affected system. This vulnerability is due to improper storage of an unencrypted registry key…
- CVE-2024-20515MEDIUMCVSS 6.5EG 6.52024-10-02
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain sensitive information from an affected device. This vulnerability is due to a lack of …
- CVE-2024-23444MEDIUMCVSS 4.9EG 4.92024-07-31
It was discovered by Elastic engineering that when elasticsearch-certutil CLI tool is used with the csr option in order to create a new Certificate Signing Requests, the associated private key that is generated is stored on disk unencrypte…
- CVE-2024-24768MEDIUMCVSS 6.5EG 6.52024-02-05
1Panel is an open source Linux server operation and maintenance management panel. The HTTPS cookie that comes with the panel does not have the Secure keyword, which may cause the cookie to be sent in plain text if accessed using HTTP. This…
- CVE-2024-25027MEDIUMCVSS 6.2EG 6.22024-03-31
IBM Security Verify Access 10.0.6 could disclose sensitive snapshot information due to missing encryption. IBM X-Force ID: 281607.
- CVE-2024-25630MEDIUMCVSS 6.1EG 6.12024-02-20
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For Cilium users who are using CRDs to store Cilium state (the default configuration) and Wireguard transparent encryption, traffic to/from the Ingr…
- CVE-2024-25631MEDIUMCVSS 6.1EG 6.12024-02-20
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For Cilium users who have enabled an external kvstore and Wireguard transparent encryption, traffic between pods in the affected cluster is not encr…
- CVE-2024-27106MEDIUMCVSS 5.7EG 5.72024-05-14
Vulnerable data in transit in GE HealthCare EchoPAC products
- CVE-2024-28249MEDIUMCVSS 6.1EG 6.12024-03-18
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.13.13, 1.14.8, and 1.15.2, in Cilium clusters with IPsec enabled and traffic matching Layer 7 policies, IPsec-eligible traffic b…
- CVE-2024-28250MEDIUMCVSS 6.1EG 6.12024-03-18
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Starting in version 1.14.0 and prior to versions 1.14.8 and 1.15.2, In Cilium clusters with WireGuard enabled and traffic matching Layer 7 policies …
- CVE-2024-29151CRITICALCVSS 9.1EG 9.12024-03-18
Rocket.Chat.Audit through 5ad78e8 depends on filecachetools, which does not exist in PyPI.
- CVE-2024-31905MEDIUMCVSS 5.9EG 5.92024-08-15
IBM QRadar Network Packet Capture 7.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive …
Map vulnerabilities like CWE-311 to your infrastructure
EchelonGraph correlates every CVE — across CWE-311 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →