CWE-311— Missing Encryption of Sensitive Data
The product does not encrypt sensitive or critical information before storage or transmission.— MITRE CWE catalog
564 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-311page 6 of 12
- CVE-2019-10139HIGHCVSS 7.8EG 7.82019-05-17
During HE deployment via cockpit-ovirt, cockpit-ovirt generates an ansible variable file `/var/lib/ovirt-hosted-engine-setup/cockpit/ansibleVarFileXXXXXX.var` which contains the admin and the appliance passwords as plain-text. At the of th…
- CVE-2019-11367CRITICALCVSS 9.8EG 9.82019-06-03
An issue was discovered in AUO Solar Data Recorder before 1.3.0. The web portal uses HTTP Basic Authentication and provides the account and password in the WWW-Authenticate attribute. By using this account and password, anyone can login su…
- CVE-2019-11404HIGHCVSS 8.1EG 8.12019-04-22
arrow-kt Arrow before 0.9.0 resolved Gradle build artifacts (for compiling and building the published JARs) over HTTP instead of HTTPS. Any of these dependent artifacts could have been maliciously compromised by an MITM attack.
- CVE-2019-11405HIGHCVSS 8.1EG 8.12019-04-22
OpenAPI Tools OpenAPI Generator before 4.0.0-20190419.052012-560 uses http:// URLs in various build.gradle, build.gradle.mustache, and build.sbt files, which may have caused insecurely resolved dependencies.
- CVE-2019-11523CRITICALCVSS 9.8EG 9.82019-06-06
Anviz Global M3 Outdoor RFID Access Control executes any command received from any source. No authentication/encryption is done. Attackers can fully interact with the device: for example, send the "open door" command, download the users li…
- CVE-2019-11663MEDIUMCVSS 6.5EG 6.52019-09-18
Clear text credentials are used to access managers app in Tomcat in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could be exploited to al…
- CVE-2019-11664MEDIUMCVSS 6.5EG 6.52019-09-18
Clear text password in browser in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could be exploited to allow sensitive data exposure.
- CVE-2019-11836MEDIUMCVSS 4.6EG 4.62019-05-09
The Rediffmail (aka com.rediff.mail.and) application 2.2.6 for Android has cleartext mail content in file storage, persisting after a logout.
- CVE-2019-12121HIGHCVSS 7.5EG 7.52020-03-18
An issue was detected in ONAP Portal through Dublin. By executing a padding oracle attack using the ONAPPORTAL/processSingleSignOn UserId field, an attacker is able to decrypt arbitrary information encrypted with the same symmetric key as …
- CVE-2019-12924CRITICALCVSS 9.8EG 9.82019-07-08
MailEnable Enterprise Premium 10.23 was vulnerable to XML External Entity Injection (XXE) attacks that could be exploited by an unauthenticated user. It was possible for an attacker to use a vulnerability in the configuration of the XML pr…
- CVE-2019-13418HIGHCVSS 7.5EG 7.52019-08-12
Search Guard versions before 24.0 had an issue that values of string arrays in documents are not properly anonymized.
- CVE-2019-13419HIGHCVSS 7.5EG 7.52019-08-13
Search Guard versions before 23.1 had an issue that for aggregations clear text values of anonymised fields were leaked.
- CVE-2019-13922LOWCVSS 2.7EG 2.72019-09-13
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). An attacker with administrative privileges can obtain the hash of a connected device's password. The security vulnerability could be exploited b…
- CVE-2019-14317MEDIUMCVSS 5.3EG 5.32019-12-11
wolfSSL and wolfCrypt 4.1.0 and earlier (formerly known as CyaSSL) generate biased DSA nonces. This allows a remote attacker to compute the long term private key from several hundred DSA signatures via a lattice attack. The issue occurs be…
- CVE-2019-14480CRITICALCVSS 9.8EG 9.82020-12-16
AdRem NetCrunch 10.6.0.4587 has an Improper Session Handling vulnerability in the NetCrunch web client, which can lead to an authentication bypass or escalation of privileges.
- CVE-2019-14954MEDIUMCVSS 5.9EG 5.92019-10-01
JetBrains IntelliJ IDEA before 2019.2 was resolving the markdown plantuml artifact download link via a cleartext http connection.
- CVE-2019-14959MEDIUMCVSS 5.9EG 5.92019-10-02
JetBrains Toolbox before 1.15.5605 was resolving an internal URL via a cleartext http connection.
- CVE-2019-1547MEDIUMCVSS 4.7EG 4.72019-09-10
Normally in OpenSSL EC groups always have a co-factor present and this is used in side channel resistant code paths. However, in some cases, it is possible to construct a group using explicit parameters (instead of using a named curve). In…
- CVE-2019-1563LOWCVSS 3.7EG 3.72019-09-10
In situations where an attacker receives automated notification of the success or failure of a decryption attempt an attacker, after sending a very large number of messages to be decrypted, can recover a CMS/PKCS7 transported encryption ke…
- CVE-2019-15653HIGHCVSS 7.5EG 7.52020-03-19
Comba AP2600-I devices through A02,0202N00PD2 are prone to password disclosure via an insecure authentication mechanism. The HTML source code of the login page contains values that allow obtaining the username and password. The username ar…
- CVE-2019-15704MEDIUMCVSS 5.5EG 5.52019-11-21
A clear text storage of sensitive information vulnerability in FortiClient for Mac may allow a local attacker to read sensitive information logged in the console window when the user connects to an SSL VPN Gateway.
- CVE-2019-1573LOWCVSS 2.5EG 2.52019-04-09
GlobalProtect Agent 4.1.0 for Windows and GlobalProtect Agent 4.1.10 and earlier for macOS may allow a local authenticated attacker who has compromised the end-user account and gained the ability to inspect memory, to access authentication…
- CVE-2019-1589MEDIUMCVSS 4.6EG 4.62019-05-03
A vulnerability in the Trusted Platform Module (TPM) functionality of software for Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an unauthenticated, local attacker with physical access…
- CVE-2019-16062MEDIUMCVSS 6.5EG 6.52020-03-19
NETSAS Enigma NMS 65.0.0 and prior does not encrypt sensitive data stored within the SQL database. It is possible for an attacker to expose unencrypted sensitive data.
- CVE-2019-16063HIGHCVSS 7.5EG 7.52020-03-19
NETSAS Enigma NMS 65.0.0 and prior does not encrypt sensitive data rendered within web pages. It is possible for an attacker to expose unencrypted sensitive data.
- CVE-2019-16206MEDIUMCVSS 5.5EG 5.52019-11-08
The authentication mechanism, in Brocade SANnav versions before v2.0, logs plaintext account credentials at the ‘trace’ and the 'debug' logging level; which could allow a local authenticated attacker to access sensitive information.
- CVE-2019-16210MEDIUMCVSS 5.5EG 5.52019-11-08
Brocade SANnav versions before v2.0, logs plain text database connection password while triggering support save.
- CVE-2019-16274HIGHCVSS 7.5EG 7.52020-01-06
DTEN D5 before 1.3 and D7 before 1.3 devices transfer customer data files via unencrypted HTTP.
- CVE-2019-16672CRITICALCVSS 9.8EG 9.82019-12-06
An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. Sensitive Credentials data is transmitted in cleartext.
- CVE-2019-1692MEDIUMCVSS 5.3EG 5.32019-05-03
A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) Software could allow an unauthenticated, remote attacker to access sensitive system usage information. The vulnerability is …
- CVE-2019-17218CRITICALCVSS 9.1EG 9.12019-10-06
An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. By default, the communication to the web service is unencrypted via http. An attacker is able to intercept and sniff communication to the we…
- CVE-2019-18201HIGHCVSS 7.5EG 7.52019-10-24
An issue was discovered on Fujitsu Wireless Keyboard Set LX390 GK381 devices. Because of the lack of proper encryption of 2.4 GHz communication, an attacker is able to eavesdrop on sensitive data such as passwords.
- CVE-2019-18254MEDIUMCVSS 4.6EG 4.62020-06-29
BIOTRONIK CardioMessenger II, The affected products do not encrypt sensitive information while at rest. An attacker with physical access to the CardioMessenger can disclose medical measurement data and the serial number from the implanted …
- CVE-2019-18376MEDIUMCVSS 5.9EG 5.92020-04-10
A CSRF token disclosure vulnerability allows a remote attacker, with access to an authenticated Management Center (MC) user's web browser history or a network device that intercepts/logs traffic to MC, to obtain CSRF tokens and use them to…
- CVE-2019-18800HIGHCVSS 8.8EG 8.82019-11-06
Viber through 11.7.0.5 allows a remote attacker who can capture a victim's internet traffic to steal their Viber account, because not all Viber protocol traffic is encrypted. TCP data packet 9 on port 4244 from the victim's device contains…
- CVE-2019-18833MEDIUMCVSS 5.9EG 5.92019-12-17
Barco ClickShare Button R9861500D01 devices before 1.9.0 allow Information exposure (issue 2 of 2).. The encryption key of the media content which is shared between a ClickShare Button and a ClickShare Base Unit is randomly generated for e…
- CVE-2019-18980HIGHCVSS 7.5EG 7.52019-11-14
On Signify Philips Taolight Smart Wi-Fi Wiz Connected LED Bulb 9290022656 devices, an unprotected API lets remote users control the bulb's operation. Anyone can turn the bulb on or off, or change its color or brightness remotely. There is …
- CVE-2019-19090LOWCVSS 3.5EG 3.52020-04-02
For ABB eSOMS versions 4.0 to 6.0.2, the Secure Flag is not set in the HTTP response header. Unencrypted connections might access the cookie information, thus making it susceptible to eavesdropping.
- CVE-2019-19463MEDIUMCVSS 5.3EG 5.32019-11-30
The Anhui Huami Mi Fit application before 4.0.11 for Android has an Unencrypted Update Check.
- CVE-2019-19464MEDIUMCVSS 5.3EG 5.32019-11-30
The CBC Gem application before 9.24.1 for Android and before 9.26.0 for iOS has Unencrypted Analytics.
- CVE-2019-19739HIGHCVSS 7.5EG 7.52019-12-30
MFScripts YetiShare 3.5.2 through 4.5.3 does not set the Secure flag on session cookies, allowing the cookie to be sent over cleartext channels.
- CVE-2019-2231MEDIUMCVSS 4.4EG 4.42019-12-06
In Blob::Blob of blob.cpp, there is a possible unencrypted master key due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitatio…
- CVE-2019-3431CRITICALCVSS 9.8EG 9.82019-12-23
All versions up to V4.01.01.02 of ZTE ZXCLOUD GoldenData VAP product have encryption problems vulnerability. Attackers could sniff unencrypted account and password through the network for front-end system access.
- CVE-2019-4171LOWCVSS 3.7EG 3.72019-09-17
IBM Cognos Controller 10.3.0, 10.3.1, 10.4.0, and 10.4.1 does not set the secure attribute on authorization tokens or session cookies. This could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-F…
- CVE-2019-4214LOWCVSS 3.7EG 3.72019-11-22
IBM SmartCloud Analytics 1.3.1 through 1.3.5 does not set the secure attribute on authorization tokens or session cookies. This could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 159…
- CVE-2019-4398LOWCVSS 3.3EG 3.32019-10-24
IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise 2.5 through 2.5.0.9 and 2.4 through 2.4.0.5 could allow a local user to obtain sensitive information from SessionManagement cookies. IBM X-Force ID: 162259.
- CVE-2019-4471MEDIUMCVSS 6.5EG 6.52021-06-01
IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain sensitive information, caused by the failure to set the secure flag for a sensitive cookie in an HTTPS session. A remote attacker could exploit this vulnerability t…
- CVE-2019-4616LOWCVSS 3.5EG 3.52020-02-05
IBM Cloud Automation Manager 3.2.1.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the us…
- CVE-2019-4686MEDIUMCVSS 5.3EG 5.32020-08-26
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link i…
- CVE-2019-4704MEDIUMCVSS 4.3EG 4.32020-07-01
IBM Security Identity Manager Virtual Appliance 7.0.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link…
Map vulnerabilities like CWE-311 to your infrastructure
EchelonGraph correlates every CVE — across CWE-311 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →