CWE-311— Missing Encryption of Sensitive Data
The product does not encrypt sensitive or critical information before storage or transmission.— MITRE CWE catalog
564 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-311page 4 of 12
- CVE-2016-10698HIGHCVSS 8.1EG 8.12018-05-29
mystem-fix is a node.js wrapper for MyStem morphology text analyzer by Yandex.ru mystem-fix downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swappi…
- CVE-2017-12716MEDIUMCVSS 6.5EG 6.52018-04-25
Abbott Laboratories Accent and Anthem pacemakers manufactured prior to Aug 28, 2017 transmit unencrypted patient information via RF communications to programmers and home monitoring units. Additionally, the Accent and Anthem pacemakers sto…
- CVE-2017-12817HIGHCVSS 7.5EG 7.52017-08-25
In Kaspersky Internet Security for Android 11.12.4.1622, some of the application trace files were not encrypted.
- CVE-2017-14012MEDIUMCVSS 4.6EG 4.62018-05-01
Boston Scientific ZOOM LATITUDE PRM Model 3120 does not encrypt PHI at rest. CVSS v3 base score: 4.6; CVSS vector string: AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N.
- CVE-2017-14852CRITICALCVSS 8.6EG 9.82019-06-03
An insecure communication was found between a user and the Orpak SiteOmat management console for all known versions, due to an invalid SSL certificate. The attack allows for an eavesdropper to capture the communication and decrypt the data.
- CVE-2017-14953MEDIUMCVSS 6.5EG 6.52017-12-01
HikVision Wi-Fi IP cameras, when used in a wired configuration, allow physically proximate attackers to trigger association with an arbitrary access point by leveraging a default SSID with no WiFi encryption or authentication. NOTE: Vendor…
- CVE-2017-15397HIGHCVSS 7.4EG 7.42018-02-07
Inappropriate implementation in ChromeVox in Google Chrome OS prior to 62.0.3202.74 allowed a remote attacker in a privileged network position to observe or tamper with certain cleartext HTTP requests by leveraging that position.
- CVE-2017-15581HIGHCVSS 7.5EG 7.52017-10-27
In the "Diary with lock" (aka WriteDiary) application 4.72 for Android, neither HTTPS nor other encryption is used for transmitting data, despite the documentation that the product is intended for "a personal journal of ... secrets and fee…
- CVE-2017-15609HIGHCVSS 7.5EG 7.52017-10-19
Octopus before 3.17.7 allows attackers to obtain sensitive cleartext information by reading a variable JSON file in certain situations involving Offline Drop Targets.
- CVE-2017-16003HIGHCVSS 8.1EG 8.12018-05-29
windows-build-tools is a module for installing C++ Build Tools for Windows using npm. windows-build-tools versions below 1.0.0 download resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote cod…
- CVE-2017-16035HIGHCVSS 8.1EG 8.12018-06-04
The hubl-server module is a wrapper for the HubL Development Server. During installation hubl-server downloads a set of dependencies from api.hubapi.com. It appears in the code that these files are downloaded over HTTPS however the api.hub…
- CVE-2017-16040HIGHCVSS 8.1EG 8.12018-06-04
gfe-sass is a library for promises (CommonJS/Promises/A,B,D) gfe-sass downloads resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resource…
- CVE-2017-16041MEDIUMCVSS 5.9EG 5.92018-06-04
ikst versions before 1.1.2 download resources over HTTP, which leaves it vulnerable to MITM attacks.
- CVE-2017-17763HIGHCVSS 7.5EG 7.52017-12-19
SuperBeam through 4.1.3, when using the LAN or WiFi Direct Share feature, does not use HTTPS or any integrity-protection mechanism for file transfer, which makes it easier for remote attackers to send crafted files, as demonstrated by APK …
- CVE-2017-3198CRITICALCVSS 9.8EG 9.82018-07-09
GIGABYTE BRIX UEFI firmware does not cryptographically validate images prior to updating the system firmware. Additionally, the firmware updates are served over HTTP. An attacker can make arbitrary modifications to firmware images without …
- CVE-2017-3218HIGHCVSS 8.8EG 8.82017-06-21
Samsung Magician 5.0 fails to validate TLS certificates for HTTPS software update traffic. Prior to version 5.0, Samsung Magician uses HTTP for software updates.
- CVE-2017-3219HIGHCVSS 8.8EG 8.82017-06-21
Acronis True Image up to and including version 2017 Build 8053 performs software updates using HTTP. Downloaded updates are only verified using a server-provided MD5 hash.
- CVE-2017-5042MEDIUMCVSS 5.7EG 5.72017-04-24
Cast in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android sent cookies to sites discovered via SSDP, which allowed an attacker on the local network segment to initiate connections to arbitrary UR…
- CVE-2017-5251HIGHCVSS 8.1EG 8.12018-02-22
In version 1012 and prior of Insteon's Insteon Hub, the radio transmissions used for communication between the hub and connected devices are not encrypted.
- CVE-2017-6297MEDIUMCVSS 5.9EG 5.92017-02-27
The L2TP Client in MikroTik RouterOS versions 6.83.3 and 6.37.4 does not enable IPsec encryption after a reboot, which allows man-in-the-middle attackers to view transmitted data unencrypted and gain access to networks on the L2TP server b…
- CVE-2017-6445HIGHCVSS 8.1EG 8.12017-03-05
The auto-update feature of Open Embedded Linux Entertainment Center (OpenELEC) 6.0.3, 7.0.1, and 8.0.4 uses neither encrypted connections nor signed updates. A man-in-the-middle attacker could manipulate the update packages to gain root ac…
- CVE-2017-7406CRITICALCVSS 9.8EG 9.82017-07-07
The D-Link DIR-615 device before v20.12PTb04 doesn't use SSL for any of the authenticated pages. Also, it doesn't allow the user to generate his own SSL Certificate. An attacker can simply monitor network traffic to steal a user's credenti…
- CVE-2017-7485MEDIUMCVSS 5.9EG 5.92017-05-12
In PostgreSQL 9.3.x before 9.3.17, 9.4.x before 9.4.12, 9.5.x before 9.5.7, and 9.6.x before 9.6.3, it was found that the PGREQUIRESSL environment variable was no longer enforcing a SSL/TLS connection to a PostgreSQL server. An active Man-…
- CVE-2017-7729HIGHCVSS 7.5EG 7.52017-07-11
On iSmartAlarm cube devices, there is Incorrect Access Control because a "new key" is transmitted in cleartext.
- CVE-2017-8168MEDIUMCVSS 4.3EG 4.32017-11-22
FusionSphere OpenStack with software V100R006C00SPC102(NFV) and V100R006C10 have an information leak vulnerability. Due to an incorrect configuration item, the information transmitted by a transmission channel is not encrypted. An attacker…
- CVE-2017-8221HIGHCVSS 7.5EG 7.52017-04-25
Wireless IP Camera (P2P) WIFICAM devices rely on a cleartext UDP tunnel protocol (aka the Cloud feature) for communication between an Android application and a camera device, which allows remote attackers to obtain sensitive information by…
- CVE-2017-8769MEDIUMCVSS 4.6EG 4.62017-05-18
Facebook WhatsApp Messenger before 2.16.323 for Android uses the SD card for cleartext storage of files (Audio, Documents, Images, Video, and Voice Notes) associated with a chat, even after that chat is deleted. There may be users who expe…
- CVE-2017-9045MEDIUMCVSS 5.9EG 5.92017-05-18
The Google I/O 2017 application before 5.1.4 for Android downloads multiple .json files from http://storage.googleapis.com without SSL, which makes it easier for man-in-the-middle attackers to spoof Feed and Schedule data by creating a mod…
- CVE-2017-9604HIGHCVSS 7.5EG 7.52017-06-13
KDE kmail before 5.5.2 and messagelib before 5.5.2, as distributed in KDE Applications before 17.04.2, do not ensure that a plugin's sign/encrypt action occurs during use of the Send Later feature, which allows remote attackers to obtain s…
- CVE-2017-9632CRITICALCVSS 9.8EG 9.82017-08-07
A Missing Encryption of Sensitive Data issue was discovered in PDQ Manufacturing LaserWash G5 and G5 S Series all versions, LaserWash M5, all versions, LaserWash 360 and 360 Plus, all versions, LaserWash AutoXpress and AutoExpress Plus, al…
- CVE-2017-9854CRITICALCVSS 9.8EG 9.82017-08-05
An issue was discovered in SMA Solar Technology products. By sniffing for specific packets on the localhost, plaintext passwords can be obtained as they are typed into Sunny Explorer by the user. These passwords can then be used to comprom…
- CVE-2018-10612CRITICALCVSS 9.8EG 9.82019-01-29
In 3S-Smart Software Solutions GmbH CODESYS Control V3 products prior to version 3.5.14.0, user access management and communication encryption is not enabled by default, which could allow an attacker access to the device and sensitive info…
- CVE-2018-10631MEDIUMCVSS 6.3EG 6.82018-07-13
The 8840 Clinician Programmer executes the application program from the 8870 Application Card. An attacker with physical access to an 8870 Application Card and sufficient technical capability can modify the contents of this card, including…
- CVE-2018-10690HIGHCVSS 8.1EG 8.12019-06-07
An issue was discovered on Moxa AWK-3121 1.14 devices. The device by default allows HTTP traffic thus providing an insecure communication mechanism for a user connecting to the web server. This allows an attacker to sniff the traffic easil…
- CVE-2018-10694HIGHCVSS 8.1EG 8.12019-06-07
An issue was discovered on Moxa AWK-3121 1.14 devices. The device provides a Wi-Fi connection that is open and does not use any encryption mechanism by default. An administrator who uses the open wireless connection to set up the device ca…
- CVE-2018-10698CRITICALCVSS 9.8EG 9.82019-06-07
An issue was discovered on Moxa AWK-3121 1.14 devices. The device enables an unencrypted TELNET service by default. This allows an attacker who has been able to gain an MITM position to easily sniff the traffic between the device and the u…
- CVE-2018-10825MEDIUMCVSS 5.3EG 5.32018-05-15
Mimo Baby 2 devices do not use authentication or encryption for the Bluetooth Low Energy (BLE) communication from a Turtle to a Lilypad, which allows attackers to inject fake information about the position and temperature of a baby via a r…
- CVE-2018-1340HIGHCVSS 7.5EG 7.52019-02-07
Prior to 1.0.0, Apache Guacamole used a cookie for client-side storage of the user's session token. This cookie lacked the "secure" flag, which could allow an attacker eavesdropping on the network to intercept the user's session token if u…
- CVE-2018-13992CRITICALCVSS 8.2EG 9.82019-05-07
The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 allows for plaintext transmission (HTTP) of user credentials by default.
- CVE-2018-14607HIGHCVSS 7.5EG 7.52018-07-26
Thomson Reuters UltraTax CS 2017 on Windows, in a client/server configuration, transfers customer records and bank account numbers in cleartext over SMBv2, which allows attackers to (1) obtain sensitive information by sniffing the network …
- CVE-2018-14608HIGHCVSS 7.5EG 7.52018-07-26
Thomson Reuters UltraTax CS 2017 on Windows has a password protection option; however, the level of protection might be inconsistent with some customers' expectations because the data is directly accessible in cleartext. Specifically, it s…
- CVE-2018-1683HIGHCVSS 5.9EG 7.52018-09-26
IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive information, caused by the failure to encrypt ORB communication. IBM X-Force ID: 145455.
- CVE-2018-16837HIGHCVSS 7.8EG 7.82018-10-23
Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases credentials passed as a parameter for the ssh-keygen executable. Showing those credentials …
- CVE-2018-16879CRITICALCVSS 9.8EG 9.82019-01-03
Ansible Tower before version 3.3.3 does not set a secure channel as it is using the default insecure configuration channel settings for messaging celery workers from RabbitMQ. This could lead in data leak of sensitive information such as p…
- CVE-2018-17287MEDIUMCVSS 4.9EG 4.92019-04-18
In Kofax Front Office Server Administration Console 4.1.1.11.0.5212, some fields, such as passwords, are obfuscated in the front-end, but the cleartext value can be exfiltrated by using the back-end "download" feature, as demonstrated by a…
- CVE-2018-17563MEDIUMCVSS 5.3EG 5.32019-04-01
A Malformed Input String to /cgi-bin/api-get_line_status on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to dump the device's configuration in cleartext.
- CVE-2018-17915CRITICALCVSS 9.8EG 9.82018-10-10
All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server do not encrypt all device communication. This includes the XMeye service and firmware update communication. This could allow an attacker to eavesdrop on video fee…
- CVE-2018-18984MEDIUMCVSS 4.6EG 4.62018-12-14
Medtronic CareLink and Encore Programmers do not encrypt or do not sufficiently encrypt sensitive PII and PHI information while at rest .
- CVE-2018-1937MEDIUMCVSS 4.4EG 4.42019-03-05
IBM Cloud Private 3.1.1 could alllow a local user with administrator privileges to intercept highly sensitive unencrypted data. IBM X-Force ID: 153317.
- CVE-2018-1938MEDIUMCVSS 4.4EG 4.42019-03-05
IBM Cloud Private 3.1.1 could alllow a local user with administrator privileges to intercept highly sensitive unencrypted data. IBM X-Force ID: 153318.
Map vulnerabilities like CWE-311 to your infrastructure
EchelonGraph correlates every CVE — across CWE-311 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →