CWE-311— Missing Encryption of Sensitive Data
The product does not encrypt sensitive or critical information before storage or transmission.— MITRE CWE catalog
564 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-311page 9 of 12
- CVE-2021-44518MEDIUMCVSS 6.8EG 6.82021-12-02
An issue was discovered in the eGeeTouch 3rd Generation Travel Padlock application for Android. The lock sends a pairing code before each operation (lock or unlock) activated via the companion app. The code is sent unencrypted, allowing an…
- CVE-2022-0183MEDIUMCVSS 4.6EG 4.62022-01-17
Missing encryption of sensitive data vulnerability in 'MIRUPASS' PW10 firmware all versions and 'MIRUPASS' PW20 firmware all versions allows an attacker who can physically access the device to obtain the stored passwords.
- CVE-2022-20219MEDIUMCVSS 5.5EG 5.52022-07-13
In multiple functions of StorageManagerService.java and UserManagerService.java, there is a possible way to leave user's directories unencrypted due to a logic error in the code. This could lead to local information disclosure with no addi…
- CVE-2022-21940HIGHCVSS 7.5EG 7.52023-02-09
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 prior to 14.2.3 and version 15 prior to 15.0.3 could allow access to the cookie.
- CVE-2022-22377MEDIUMCVSS 5.3EG 5.32023-10-17
IBM Security Verify Privilege On-Premises 11.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain s…
- CVE-2022-22386MEDIUMCVSS 5.3EG 5.32023-10-17
IBM Security Verify Privilege On-Premises 11.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain …
- CVE-2022-22401MEDIUMCVSS 5.9EG 5.92023-09-08
IBM Aspera Faspex 5.0.5 could allow a remote attacker to gather or persuade a naive user to supply sensitive information. IBM X-Force ID: 222567.
- CVE-2022-22405MEDIUMCVSS 5.9EG 5.92023-09-08
IBM Aspera Faspex 5.0.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information us…
- CVE-2022-23116HIGHCVSS 7.5EG 7.52022-01-12
Jenkins Conjur Secrets Plugin 1.0.9 and earlier implements functionality that allows attackers able to control agent processes to decrypt secrets stored in Jenkins obtained through another method.
- CVE-2022-24045MEDIUMCVSS 6.5EG 6.52022-05-20
A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.142.4-18), Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142.10-10884). The appl…
- CVE-2022-26157MEDIUMCVSS 5.3EG 5.32022-02-28
An issue was discovered in the web application in Cherwell Service Management (CSM) 10.2.3. The ASP.NET_Sessionid cookie is not protected by the Secure flag. This makes it prone to interception by an attacker if traffic is sent over unencr…
- CVE-2022-26281HIGHCVSS 7.5EG 7.52022-04-05
BigAnt Server v5.6.06 was discovered to contain an incorrect access control issue.
- CVE-2022-26390MEDIUMCVSS 4.2EG 4.22022-09-09
The Baxter Spectrum Wireless Battery Module (WBM) stores network credentials and PHI (only applicable to Spectrum IQ pumps using auto programming) in unencrypted form. An attacker with physical access to a device that hasn't had all data a…
- CVE-2022-27225MEDIUMCVSS 6.5EG 6.52022-03-16
Gradle Enterprise before 2021.4.3 relies on cleartext data transmission in some situations. It uses Keycloak for identity management services. During the sign-in process, Keycloak sets browser cookies that effectively provide remember-me f…
- CVE-2022-29945HIGHCVSS 4.0EG 7.52022-04-29
DJI drone devices sold in 2017 through 2022 broadcast unencrypted information about the drone operator's physical location via the AeroScope protocol.
- CVE-2022-30237HIGHCVSS 8.2EG 8.22022-06-02
A CWE-311: Missing Encryption of Sensitive Data vulnerability exists that could allow authentication credentials to be recovered when an attacker breaks the encoding. Affected Products: Wiser Smart, EER21000 & EER21001 (V4.5 and prior)
- CVE-2022-31085MEDIUMCVSS 6.1EG 6.12022-06-27
LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 the session files include the LDAP user name and password in clear text if the PHP O…
- CVE-2022-3174HIGHCVSS 7.5EG 7.52022-09-13
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository ikus060/rdiffweb prior to 2.4.2.
- CVE-2022-3250MEDIUMCVSS 5.3EG 5.32022-09-21
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository ikus060/rdiffweb prior to 2.4.6.
- CVE-2022-3251MEDIUMCVSS 5.3EG 5.32022-09-21
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository ikus060/minarca prior to 4.2.2.
- CVE-2022-33161MEDIUMCVSS 5.3EG 5.32023-10-14
IBM Security Directory Server 6.4.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive in…
- CVE-2022-34307MEDIUMCVSS 4.3EG 4.32022-08-01
IBM CICS TX 11.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cook…
- CVE-2022-35860MEDIUMCVSS 6.8EG 6.82022-10-19
Missing AES encryption in Corsair K63 Wireless 3.1.3 allows physically proximate attackers to inject and sniff keystrokes via 2.4 GHz radio transmissions.
- CVE-2022-3781MEDIUMCVSS 6.5EG 6.52022-11-01
Dashlane password and Keepass Server password in My Account Settings are not encrypted in the database in Devolutions Remote Desktop Manager 2022.2.26 and prior versions and Devolutions Server 2022.3.1 and prior versions which allows dat…
- CVE-2022-38194MEDIUMCVSS 6.7EG 6.72022-08-16
In Esri Portal for ArcGIS versions 10.8.1, a system property is not properly encrypted. This may lead to a local user reading sensitive information from a properties file.
- CVE-2022-38458MEDIUMCVSS 6.5EG 6.52023-03-21
A cleartext transmission vulnerability exists in the Remote Management functionality of Netgear Orbi Router RBR750 4.6.8.5. A specially-crafted man-in-the-middle attack can lead to a disclosure of sensitive information.
- CVE-2022-38658HIGHCVSS 7.7EG 7.72022-12-24
BigFix deployments that have installed the Notification Service on Windows are susceptible to disclosing SMTP BigFix operator's sensitive data in clear text. Operators who use Notification Service related content from BES Support are at ri…
- CVE-2022-39014MEDIUMCVSS 5.3EG 5.32022-09-13
Under certain conditions SAP BusinessObjects Business Intelligence Platform Central Management Console (CMC) - version 430, allows an attacker to access certain unencrypted sensitive parameters which would otherwise be restricted.
- CVE-2022-40295MEDIUMCVSS 4.9EG 4.92022-10-31
The application was vulnerable to an authenticated information disclosure, allowing administrators to view unsalted user passwords, which could lead to the compromise of plaintext passwords via offline attacks.
- CVE-2022-41627HIGHCVSS 4.8EG 7.62022-10-27
The physical IoT device of the AliveCor's KardiaMobile, a smartphone-based personal electrocardiogram (EKG) has no encryption for its data-over-sound protocols. Exploiting this vulnerability could allow an attacker to read patient EKG res…
- CVE-2022-4409HIGHCVSS 7.5EG 7.52022-12-11
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository thorsten/phpmyfaq prior to 3.1.9.
- CVE-2022-4683MEDIUMCVSS 6.5EG 6.52022-12-23
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository usememos/memos prior to 0.9.0.
- CVE-2022-47715MEDIUMCVSS 5.3EG 5.32023-02-01
In Last Yard 22.09.8-1, the cookie can be stolen via via unencrypted traffic.
- CVE-2023-0690MEDIUMCVSS 5.0EG 5.02023-02-08
HashiCorp Boundary from 0.10.0 through 0.11.2 contain an issue where when using a PKI-based worker with a Key Management Service (KMS) defined in the configuration file, new credentials created after an automatic rotation may not have bee…
- CVE-2023-0750CRITICALCVSS 9.8EG 9.82023-04-06
Yellobrik PEC-1864 implements authentication checks via javascript in the frontend interface. When the device can be accessed over the network an attacker could bypass authentication. This would allow an attacker to : - Change the p…
- CVE-2023-21404MEDIUMCVSS 5.3EG 5.32023-05-08
AXIS OS 11.0.X - 11.3.x use a static RSA key in legacy LUA-components to protect Axis-specific source code. The static RSA key is not used in any other secure communication nor can it be used to compromise the device or any customer data.
- CVE-2023-22948MEDIUMCVSS 4.9EG 4.92023-04-13
An issue was discovered in TigerGraph Enterprise Free Edition 3.x. There is unsecured read access to an SSH private key. Any code that runs as the tigergraph user is able to read the SSH private key. With this, an attacker is granted passw…
- CVE-2023-23127MEDIUMCVSS 5.3EG 5.32023-02-01
In Connectwise Control 22.8.10013.8329, the login page does not implement HSTS headers therefore not enforcing HTTPS. NOTE: the vendor's position is that, by design, this is controlled by a configuration option in which a customer can choo…
- CVE-2023-23371MEDIUMCVSS 5.2EG 5.22023-10-06
A cleartext transmission of sensitive information vulnerability has been reported to affect QVPN Device Client. If exploited, the vulnerability could allow local authenticated administrators to read sensitive data via unspecified vectors. …
- CVE-2023-27291MEDIUMCVSS 4.5EG 4.52024-03-03
IBM Watson CP4D Data Stores 4.6.0, 4.6.1, 4.6.2, and 4.6.3 does not encrypt sensitive or critical information before storage or transmission which could allow an attacker to obtain sensitive information. IBM X-Force ID: 248740.
- CVE-2023-28045MEDIUMCVSS 6.3EG 6.32023-05-19
Dell CloudIQ Collector version 1.10.2 contains a missing encryption of sensitive data vulnerability. An attacker with low privileges could potentially exploit this vulnerability, leading to gain access to unauthorized data.
- CVE-2023-28841MEDIUMCVSS 6.8EG 6.82023-04-04
Moby is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon component (`dockerd`), which is developed as mob…
- CVE-2023-28999MEDIUMCVSS 6.9EG 6.92023-04-04
Nextcloud is an open-source productivity platform. In Nextcloud Desktop client 3.0.0 until 3.8.0, Nextcloud Android app 3.13.0 until 3.25.0, and Nextcloud iOS app 3.0.5 until 4.8.0, a malicious server administrator can gain full access to …
- CVE-2023-30523MEDIUMCVSS 4.3EG 4.32023-04-12
Jenkins Report Portal Plugin 0.5 and earlier stores ReportPortal access tokens unencrypted in job config.xml files on the Jenkins controller as part of its configuration where they can be viewed by users with Item/Extended Read permission …
- CVE-2023-30561MEDIUMCVSS 6.1EG 6.12023-07-13
The data flowing between the PCU and its modules is insecure. A threat actor with physical access could potentially read or modify data by attaching a specially crafted device while an infusion is running.
- CVE-2023-30602HIGHCVSS 7.5EG 7.52023-06-02
Hitron Technologies CODA-5310’s Telnet function transfers sensitive data in plaintext. An unauthenticated remote attacker can exploit this vulnerability to access credentials of normal users and administrator.
- CVE-2023-31819HIGHCVSS 7.5EG 7.52023-07-13
An issue found in KEISEI STORE Co, Ltd. LIVRE KEISEI v.13.6.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp function.
- CVE-2023-31820HIGHCVSS 7.5EG 7.52023-07-13
An issue found in Shizutetsu Store v.13.6.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp function.
- CVE-2023-31822HIGHCVSS 7.5EG 7.52023-07-13
An issue found in Entetsu Store v.13.4.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp Entetsu Store function.
- CVE-2023-31825HIGHCVSS 7.5EG 7.52023-07-13
An issue found in Inageya v.13.4.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp Inageya function.
Map vulnerabilities like CWE-311 to your infrastructure
EchelonGraph correlates every CVE — across CWE-311 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →