CWE-311— Missing Encryption of Sensitive Data
The product does not encrypt sensitive or critical information before storage or transmission.— MITRE CWE catalog
564 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-311page 7 of 12
- CVE-2019-5448HIGHCVSS 8.1EG 8.12019-07-30
Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Data due to HTTP URLs in lockfile causing unencrypted authentication data to be sent over the network.
- CVE-2019-6169HIGHCVSS 7.5EG 7.52019-06-26
A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow unencrypted downloads over FTP.
- CVE-2019-6518HIGHCVSS 7.5EG 7.52019-03-05
Moxa IKS and EDS store plaintext passwords, which may allow sensitive information to be read by someone with access to the device.
- CVE-2019-6526CRITICALCVSS 9.8EG 9.82019-04-15
Moxa IKS-G6824A series Versions 4.5 and prior, EDS-405A series Version 3.8 and prior, EDS-408A series Version 3.8 and prior, and EDS-510A series Version 3.8 and prior use plaintext transmission of sensitive data, which may allow an attacke…
- CVE-2019-7311HIGHCVSS 7.8EG 7.82019-06-06
An issue was discovered on Linksys WRT1900ACS 1.0.3.187766 devices. A lack of encryption in how the user login cookie (admin-auth) is stored on a victim's computer results in the admin password being discoverable by a local attacker, and u…
- CVE-2019-9681MEDIUMCVSS 5.3EG 5.32019-09-17
Online upgrade information in some firmware packages of Dahua products is not encrypted. Attackers can obtain this information by analyzing firmware packages by specific means. Affected products include: IPC-HDW1X2X,IPC-HFW1X2X,IPC-HDW2X2X…
- CVE-2019-9862MEDIUMCVSS 6.5EG 6.52019-03-27
An issue was discovered on ABUS Secvest wireless alarm system FUAA50000 3.01.01 in conjunction with Secvest remote control FUBE50014 or FUBE50015. Because "encrypted signal transmission" is missing, an attacker is able to eavesdrop sensiti…
- CVE-2020-10039HIGHCVSS 8.1EG 8.12020-07-14
A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). An attacker in a privileged network position between a legitimate user and the web server might be able to c…
- CVE-2020-10124HIGHCVSS 7.1EG 7.12020-08-21
NCR SelfServ ATMs running APTRA XFS 05.01.00 do not encrypt, authenticate, or verify the integrity of messages between the BNA and the host computer, which could allow an attacker with physical access to the internal components of the ATM …
- CVE-2020-10267HIGHCVSS 7.5EG 7.52020-04-06
Universal Robots control box CB 3.1 across firmware versions (tested on 1.12.1, 1.12, 1.11 and 1.10) does not encrypt or protect in any way the intellectual property artifacts installed from the UR+ platform of hardware and software compon…
- CVE-2020-10273HIGHCVSS 7.5EG 7.52020-06-24
MiR controllers across firmware versions 2.8.1.1 and before do not encrypt or protect in any way the intellectual property artifacts installed in the robots. This flaw allows attackers with access to the robot or the robot network (while i…
- CVE-2020-10941MEDIUMCVSS 5.9EG 5.92020-03-24
Arm Mbed TLS before 2.16.5 allows attackers to obtain sensitive information (an RSA private key) by measuring cache usage during an import.
- CVE-2020-11685HIGHCVSS 7.5EG 7.52020-04-22
In JetBrains GoLand before 2019.3.2, the plugin repository was accessed via HTTP instead of HTTPS.
- CVE-2020-11826HIGHCVSS 7.5EG 7.52020-04-16
Users can lock their notes with a password in Memono version 3.8. Thus, users needs to know a password to read notes. However, these notes are stored in a database without encryption and an attacker can read the password-protected notes wi…
- CVE-2020-12032CRITICALCVSS 9.1EG 9.12020-06-29
Baxter ExactaMix EM 2400 Versions 1.10, 1.11 and ExactaMix EM1200 Versions 1.1, 1.2 systems store device data with sensitive information in an unencrypted database. This could allow an attacker with network access to view or modify sensiti…
- CVE-2020-12273HIGHCVSS 7.5EG 7.52020-04-27
In TestLink 1.9.20, a crafted login.php viewer parameter exposes cleartext credentials.
- CVE-2020-12398HIGHCVSS 7.5EG 7.52020-07-09
If Thunderbird is configured to use STARTTLS for an IMAP server, and the server sends a PREAUTH response, then Thunderbird will continue with an unencrypted connection, causing email data to be sent without protection. This vulnerability a…
- CVE-2020-12730MEDIUMCVSS 5.3EG 5.32021-07-15
MagicMotion Flamingo 2 lacks BLE encryption, enabling data sniffing and packet forgery.
- CVE-2020-12772HIGHCVSS 8.8EG 8.82020-05-12
An issue was discovered in Ignite Realtime Spark 2.8.3 (and the ROAR plugin for it) on Windows. A chat message can include an IMG element with a SRC attribute referencing an external host's IP address. Upon access to this external host, th…
- CVE-2020-12801MEDIUMCVSS 5.3EG 5.32020-05-18
If LibreOffice has an encrypted document open and crashes, that document is auto-saved encrypted. On restart, LibreOffice offers to restore the document and prompts for the password to decrypt it. If the recovery is successful, and if the …
- CVE-2020-14254HIGHCVSS 7.5EG 7.52020-12-16
TLS-RSA cipher suites are not disabled in HCL BigFix Inventory up to v10.0.2. If TLS 2.0 and secure ciphers are not enabled then an attacker can passively record traffic and later decrypt it.
- CVE-2020-15302HIGHCVSS 7.5EG 7.52020-06-25
In Argent RecoveryManager before 0xdc350d09f71c48c5D22fBE2741e4d6A03970E192, the executeRecovery function does not require any signatures in the zero-guardian case, which allows attackers to cause a denial of service (locking) or a takeove…
- CVE-2020-15330MEDIUMCVSS 5.3EG 5.32022-09-29
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded APP_KEY in /opt/axess/etc/default/axess.
- CVE-2020-15331CRITICALCVSS 9.8EG 9.82022-09-29
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded OAUTH_SECRET_KEY in /opt/axess/etc/default/axess.
- CVE-2020-15340HIGHCVSS 7.5EG 7.52022-09-29
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded opt/axess/AXAssets/default_axess/axess/TR69/Handlers/turbolink/sshkeys/id_rsa SSH key.
- CVE-2020-15342MEDIUMCVSS 5.3EG 5.32022-09-29
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_install_user API.
- CVE-2020-15343MEDIUMCVSS 5.3EG 5.32022-09-29
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_install_user_key API.
- CVE-2020-15344MEDIUMCVSS 5.3EG 5.32022-09-29
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_get_user_id_and_key API.
- CVE-2020-15345MEDIUMCVSS 5.3EG 5.32022-09-29
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_get_instances_for_update API.
- CVE-2020-15346MEDIUMCVSS 5.3EG 5.32022-09-29
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a /live/GLOBALS API with the CLOUDCNM key.
- CVE-2020-15509MEDIUMCVSS 6.5EG 6.52020-07-07
Nordic Semiconductor Android BLE Library through 2.2.1 and DFU Library through 1.10.4 for Android (as used by nRF Connect and other applications) can engage in unencrypted communication while showing the user that the communication is purp…
- CVE-2020-15574HIGHCVSS 7.5EG 7.52020-07-07
SolarWinds Serv-U File Server before 15.2.1 mishandles the Same-Site cookie attribute, aka Case Number 00331893.
- CVE-2020-15767MEDIUMCVSS 5.3EG 5.32020-09-18
An issue was discovered in Gradle Enterprise before 2020.2.5. The cookie used to convey the CSRF prevention token is not annotated with the “secure” attribute, which allows an attacker with the ability to MITM plain HTTP requests to ob…
- CVE-2020-15771HIGHCVSS 7.5EG 7.52020-09-18
An issue was discovered in Gradle Enterprise 2018.2 and Gradle Enterprise Build Cache Node 4.1. Cross-site transmission of cookie containing CSRF token allows remote attacker to bypass CSRF mitigation.
- CVE-2020-1688MEDIUMCVSS 6.5EG 6.52020-10-16
On Juniper Networks SRX Series and NFX Series, a local authenticated user with access to the shell may obtain the Web API service private key that is used to provide encrypted communication between the Juniper device and the authenticator …
- CVE-2020-2239MEDIUMCVSS 4.3EG 4.32020-09-01
Jenkins Parameterized Remote Trigger Plugin 3.1.3 and earlier stores a secret unencrypted in its global configuration file on the Jenkins controller where it can be viewed by attackers with access to the Jenkins controller file system.
- CVE-2020-2249LOWCVSS 3.3EG 3.32020-09-01
Jenkins Team Foundation Server Plugin 5.157.1 and earlier stores a webhook secret unencrypted in its global configuration file on the Jenkins controller where it can be viewed by attackers with access to the Jenkins controller file system.
- CVE-2020-2250MEDIUMCVSS 6.5EG 6.52020-09-01
Jenkins SoapUI Pro Functional Testing Plugin 1.3 and earlier stores project passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by attackers with Extended Read permission, or access to the Jenki…
- CVE-2020-23162HIGHCVSS 7.5EG 7.52021-01-26
Sensitive information disclosure and weak encryption in Pyrescom Termod4 time management devices before 10.04k allows remote attackers to read a session-file and obtain plain-text user credentials.
- CVE-2020-24396HIGHCVSS 7.5EG 7.52021-05-20
homee Brain Cube v2 (2.28.2 and 2.28.4) devices have sensitive SSH keys within downloadable and unencrypted firmware images. This allows remote attackers to use the support server as a SOCKS proxy.
- CVE-2020-25842HIGHCVSS 7.5EG 7.52020-12-31
The encryption function of NHIServiSignAdapter fail to verify the file path input by users. Remote attacker can access arbitrary files through the flaw without privilege.
- CVE-2020-26732HIGHCVSS 7.5EG 7.52021-01-14
SKYWORTH GN542VF Hardware Version 2.0 and Software Version 2.0.0.16 does not set the Secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission…
- CVE-2020-26816MEDIUMCVSS 4.5EG 4.52020-12-09
SAP AS JAVA (Key Storage Service), versions - 7.10, 7.11, 7.20 ,7.30, 7.31, 7.40, 7.50, has the key material which is stored in the SAP NetWeaver AS Java Key Storage service stored in the database in the DER encoded format and is not encry…
- CVE-2020-27055HIGHCVSS 7.5EG 7.52020-12-15
In isSubmittable and showWarningMessagesIfAppropriate of WifiConfigController.java and WifiConfigController2.java, there is a possible insecure WiFi configuration due to improper input validation. This could lead to remote information disc…
- CVE-2020-27650MEDIUMCVSS 5.8EG 5.82020-10-29
Synology DiskStation Manager (DSM) before 6.2.3-25426-2 does not set the Secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an H…
- CVE-2020-27651MEDIUMCVSS 5.8EG 5.82020-10-29
Synology Router Manager (SRM) before 1.2.4-8081 does not set the Secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP sess…
- CVE-2020-28216HIGHCVSS 7.5EG 7.52020-12-11
A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Easergy T300 (firmware 2.7 and older), that would allow an attacker to read network traffic over HTTP protocol.
- CVE-2020-28217HIGHCVSS 7.5EG 7.52020-12-11
A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Easergy T300 (firmware 2.7 and older), that would allow an attacker to read network traffic over HTTP protocol.
- CVE-2020-29024MEDIUMCVSS 5.3EG 5.32021-02-16
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute vulnerability in (GTA) GoToAppliance of Secomea GateManager could allow an attacker to gain access to sensitive cookies. This issue affects: Secomea GateManager all versions prio…
- CVE-2020-3389MEDIUMCVSS 4.4EG 4.42020-08-26
A vulnerability in the installation component of Cisco Hyperflex HX-Series Software could allow an authenticated, local attacker to retrieve the password that was configured at installation on an affected device. The vulnerability exists b…
Map vulnerabilities like CWE-311 to your infrastructure
EchelonGraph correlates every CVE — across CWE-311 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →