CWE-311— Missing Encryption of Sensitive Data
The product does not encrypt sensitive or critical information before storage or transmission.— MITRE CWE catalog
564 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-311page 8 of 12
- CVE-2020-35168CRITICALCVSS 4.7EG 9.82022-07-11
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timing Discrepancy Vulnerability.
- CVE-2020-35587HIGHCVSS 7.5EG 7.52020-12-23
In Solstice Pod before 3.0.3, the firmware can easily be decompiled/disassembled. The decompiled/disassembled files contain non-obfuscated code. NOTE: it is unclear whether lack of obfuscation is directly associated with a negative impact,…
- CVE-2020-35658MEDIUMCVSS 5.3EG 5.32020-12-23
SpamTitan before 7.09 allows attackers to tamper with backups, because backups are not encrypted.
- CVE-2020-4126MEDIUMCVSS 5.9EG 5.92020-12-01
HCL iNotes is susceptible to a sensitive cookie exposure vulnerability. This can allow an unauthenticated remote attacker to capture the cookie by intercepting its transmission within an http session. Fixes are available in HCL Domino and …
- CVE-2020-4233MEDIUMCVSS 5.3EG 5.32020-05-28
IBM Security Identity Governance and Intelligence 5.2.6 could allow a remote attacker to obtain sensitive information, caused by the failure to set the secure flag for the session cookie in SSL mode. By intercepting its transmission within…
- CVE-2020-4591LOWCVSS 3.3EG 3.32020-08-28
IBM Spectrum Protect Server 8.1.0.000 through 8.1.10.000 could disclose sensitive information in nondefault settings due to occasionally not encrypting the second chunk of an object in an encrypted container pool. IBM X-Force ID: 184746.
- CVE-2020-4597MEDIUMCVSS 4.3EG 4.32021-01-13
IBM Security Guardium Insights 2.0.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the us…
- CVE-2020-4695HIGHCVSS 7.5EG 7.52021-03-08
IBM API Connect V10 is impacted by insecure communications during database replication. As the data replication happens over insecure communication channels, an attacker can view unencrypted data leading to a loss of confidentiality.
- CVE-2020-5879HIGHCVSS 7.5EG 7.52020-04-30
On BIG-IP ASM 11.6.1-11.6.5.1, under certain configurations, the BIG-IP system sends data plane traffic to back-end servers unencrypted, even when a Server SSL profile is applied.
- CVE-2020-7567MEDIUMCVSS 5.7EG 5.72020-11-19
A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Modicon M221 (all references, all versions) that could allow the attacker to find the password hash when the attacker has captured the traffic between EcoStruxure Mach…
- CVE-2020-8150MEDIUMCVSS 4.1EG 4.12020-11-09
A cryptographic issue in Nextcloud Server 19.0.1 allowed an attacker to downgrade the encryption scheme and break the integrity of encrypted files.
- CVE-2020-8173LOWCVSS 2.2EG 2.22020-11-02
A too small set of random characters being used for encryption in Nextcloud Server 18.0.4 allowed decryption in shorter time than intended.
- CVE-2020-9057HIGHCVSS 8.8EG 8.82022-01-10
Z-Wave devices based on Silicon Labs 100, 200, and 300 series chipsets do not support encryption, allowing an attacker within radio range to take control of or cause a denial of service to a vulnerable device. An attacker can also capture …
- CVE-2020-9058HIGHCVSS 8.1EG 8.12022-01-10
Z-Wave devices based on Silicon Labs 500 series chipsets using CRC-16 encapsulation, including but likely not limited to the Linear LB60Z-1 version 3.5, Dome DM501 version 4.26, and Jasco ZW4201 version 4.05, do not implement encryption or…
- CVE-2020-9062MEDIUMCVSS 5.3EG 5.32020-08-21
Diebold Nixdorf ProCash 2100xe USB ATMs running Wincor Probase version 1.1.30 do not encrypt, authenticate, or verify the integrity of messages between the CCDM and the host computer, allowing an attacker with physical access to internal A…
- CVE-2020-9470HIGHCVSS 7.8EG 7.82020-03-07
An issue was discovered in Wing FTP Server 6.2.5 before February 2020. Due to insecure permissions when handling session cookies, a local user may view the contents of the session and session_admin directories, which expose active session …
- CVE-2020-9774HIGHCVSS 7.5EG 7.52020-10-27
An issue existed with Siri Suggestions access to encrypted data. The issue was fixed by limiting access to encrypted data. This issue is fixed in macOS Catalina 10.15.3, Security Update 2020-001 Mojave, Security Update 2020-001 High Sierra…
- CVE-2021-20567MEDIUMCVSS 4.4EG 4.42021-06-16
IBM Resilient SOAR V38.0 could allow a local privileged attacker to obtain sensitive information due to improper or nonexisting encryption.IBM X-Force ID: 199239.
- CVE-2021-21963MEDIUMCVSS 5.9EG 5.92022-02-04
An information disclosure vulnerability exists in the Web Server functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A specially-crafted man-in-the-middle attack can lead to a disclosure of sensitive information. An attacker c…
- CVE-2021-22782MEDIUMCVSS 5.5EG 5.52021-07-14
Missing Encryption of Sensitive Data vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Process Expert (all versions, including all versions of EcoStruxure…
- CVE-2021-22932HIGHCVSS 7.5EG 7.52021-08-16
An issue has been identified in the CTX269106 mitigation tool for Citrix ShareFile storage zones controller which causes the ShareFile file encryption option to become disabled if it had previously been enabled. Customers are only affected…
- CVE-2021-23211MEDIUMCVSS 6.0EG 6.02021-06-11
Cleartext Storage of Sensitive Information in Memory vulnerability in Gallagher Command Centre Server allows Cloud end-to-end encryption key to be discoverable in server memory dumps. This issue affects: Gallagher Command Centre 8.40 versi…
- CVE-2021-26100HIGHCVSS 5.9EG 7.52021-07-09
A missing cryptographic step in the Identity-Based Encryption service of FortiMail before 7.0.0 may allow an unauthenticated attacker who intercepts the encrypted messages to manipulate them in such a way that makes the tampering and the r…
- CVE-2021-27764HIGHCVSS 7.4EG 7.42022-05-06
Cookie without HTTPONLY flag set. NUMBER cookie(s) was set without Secure or HTTPOnly flags. The images show the cookie with the missing flag. (WebUI)
- CVE-2021-27779CRITICALCVSS 9.1EG 9.12022-05-25
VersionVault Express exposes sensitive information that an attacker can use to impersonate the server or eavesdrop on communications with the server.
- CVE-2021-27783MEDIUMCVSS 6.8EG 6.82022-05-25
User generated PPKG file for Bulk Enroll may have unencrypted sensitive information exposed.
- CVE-2021-28496MEDIUMCVSS 5.7EG 6.52021-10-21
On systems running Arista EOS and CloudEOS with the affected release version, when using shared secret profiles the password configured for use by BiDirectional Forwarding Detection (BFD) will be leaked when displaying output over eAPI or …
- CVE-2021-29248MEDIUMCVSS 5.3EG 5.32021-05-05
BTCPay Server through 1.0.7.0 could allow a remote attacker to obtain sensitive information, caused by failure to set the Secure flag for a cookie.
- CVE-2021-29883MEDIUMCVSS 4.3EG 4.32021-10-21
IBM Standards Processing Engine (IBM Transformation Extender Advanced 9.0 and 10.0) does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a…
- CVE-2021-31386MEDIUMCVSS 5.3EG 5.32021-10-19
A Protection Mechanism Failure vulnerability in the J-Web HTTP service of Juniper Networks Junos OS allows a remote unauthenticated attacker to perform Person-in-the-Middle (PitM) attacks against the device. This issue affects: Juniper Net…
- CVE-2021-32001MEDIUMCVSS 6.5EG 6.52021-07-28
K3s in SUSE Rancher allows any user with direct access to the datastore, or a copy of a datastore backup, to extract the cluster's confidential keying material (cluster certificate authority private keys, secrets encryption configuration p…
- CVE-2021-33020HIGHCVSS 8.2EG 8.22022-04-01
Philips Vue PACS versions 12.2.x.x and prior uses a cryptographic key or password past its expiration date, which diminishes its safety significantly by increasing the timing window for cracking attacks against that key.
- CVE-2021-33900HIGHCVSS 7.5EG 7.52021-07-26
While investigating DIRSTUDIO-1219 it was noticed that configured StartTLS encryption was not applied when any SASL authentication mechanism (DIGEST-MD5, GSSAPI) was used. While investigating DIRSTUDIO-1220 it was noticed that any configur…
- CVE-2021-34825HIGHCVSS 7.5EG 7.52021-06-17
Quassel through 0.13.1, when --require-ssl is enabled, launches without SSL or TLS support if a usable X.509 certificate is not found on the local system.
- CVE-2021-35236MEDIUMCVSS 3.1EG 5.32021-10-27
The Secure flag is not set in the SSL Cookie of Kiwi Syslog Server 9.7.2 and previous versions. The Secure attribute tells the browser to only send the cookie if the request is being sent over a secure channel such as HTTPS. This will help…
- CVE-2021-36189MEDIUMCVSS 6.8EG 6.82021-12-09
A missing encryption of sensitive data in Fortinet FortiClientEMS version 7.0.1 and below, version 6.4.4 and below allows attacker to information disclosure via inspecting browser decrypted data
- CVE-2021-37050HIGHCVSS 7.5EG 7.52021-12-08
There is a Missing sensitive data encryption vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2021-37189HIGHCVSS 7.5EG 7.52021-12-10
An issue was discovered on Digi TransPort Gateway devices through 5.2.13.4. They do not set the Secure attribute for sensitive cookies in HTTPS sessions, which could cause the user agent to send those cookies in cleartext over an HTTP sess…
- CVE-2021-37209MEDIUMCVSS 6.7EG 6.72022-03-08
A vulnerability has been identified in RUGGEDCOM i800 (All versions < V4.3.8), RUGGEDCOM i801 (All versions < V4.3.8), RUGGEDCOM i802 (All versions < V4.3.8), RUGGEDCOM i803 (All versions < V4.3.8), RUGGEDCOM M2100 (All versions < V4.3.8),…
- CVE-2021-3774HIGHCVSS 7.4EG 7.42021-11-05
Meross Smart Wi-Fi 2 Way Wall Switch (MSS550X), on its 3.1.3 version and before, creates an open Wi-Fi Access Point without the required security measures in its initial setup. This could allow a remote attacker to obtain the Wi-Fi SSID as…
- CVE-2021-3882MEDIUMCVSS 6.8EG 6.82021-10-14
LedgerSMB does not set the 'Secure' attribute on the session authorization cookie when the client uses HTTPS and the LedgerSMB server is behind a reverse proxy. By tricking a user to use an unencrypted connection (HTTP), an attacker may be…
- CVE-2021-38977MEDIUMCVSS 4.3EG 4.32021-11-15
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this …
- CVE-2021-39090MEDIUMCVSS 5.9EG 5.92024-02-29
IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.6.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerabilit…
- CVE-2021-40148HIGHCVSS 7.5EG 7.52022-01-04
In Modem EMM, there is a possible information disclosure due to a missing data encryption. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Pa…
- CVE-2021-40366HIGHCVSS 7.4EG 7.42021-11-09
A vulnerability has been identified in Climatix POL909 (AWB module) (All versions < V11.42), Climatix POL909 (AWM module) (All versions < V11.34). The web server of affected devices transmits data without TLS encryption. This could allow a…
- CVE-2021-40642MEDIUMCVSS 4.3EG 4.32022-06-29
Textpattern CMS v4.8.7 and older vulnerability exists through Sensitive Cookie in HTTPS Session Without 'Secure' Attribute via textpattern/lib/txplib_misc.php. The secure flag is not set for txp_login session cookie in the application. If …
- CVE-2021-40650MEDIUMCVSS 6.5EG 6.52022-06-14
In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the secure flag set.
- CVE-2021-41302HIGHCVSS 7.3EG 7.32021-09-30
ECOA BAS controller stores sensitive data (backup exports) in clear-text, thus the unauthenticated attacker can remotely query user password and obtain user’s privilege.
- CVE-2021-4239HIGHCVSS 7.5EG 7.52022-12-27
The Noise protocol implementation suffers from weakened cryptographic security after encrypting 2^64 messages, and a potential denial of service attack. After 2^64 (~18.4 quintillion) messages are encrypted with the Encrypt function, the n…
- CVE-2021-44480HIGHCVSS 8.1EG 8.12021-12-01
Wokka Lokka Q50 devices through 2021-11-30 allow remote attackers (who know the SIM phone number and password) to listen to a device's surroundings via a callback in an SMS command, as demonstrated by the 123456 and 523681 default password…
Map vulnerabilities like CWE-311 to your infrastructure
EchelonGraph correlates every CVE — across CWE-311 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →