CWE-311

High likelihood

Missing Encryption of Sensitive Data

Parent: CWE-693 - Protection Mechanism Failure

The product does not encrypt sensitive or critical information before storage or transmission.

508 vulnerabilities with CWE-311
CVE-2023-50129 MEDIUM
Flient Smart Door Lock v1.0 - Missing Encryption of Sensitive Data in NFC Tags
CVSS 6.5
CVE-2023-50126 MEDIUM
Hozard Alarm System v1.0 - Missing Encryption of Sensitive Data in RFID Tags
CVSS 6.5
CVE-2023-38267 MEDIUM
IBM Security Verify Access <10.0.6.1 - Privilege Escalation
CVSS 6.2
CVE-2023-6339 CRITICAL
Google Nest WiFi Pro Firmware - Missing Encryption of Sensitive Data
CVSS 10.0
CVE-2023-33037 HIGH
Qualcomm AR8035 Firmware - Cryptographic Issue in Key Unwrapping and RPMB Verification
CVSS 7.1
CVE-2023-46219 MEDIUM
curl 7.84.0-8.4.0 - Missing Encryption of Sensitive Data via HSTS File Handling
CVSS 5.3
CVE-2023-42019 MEDIUM
IBM InfoSphere Information Server 11.7.0.0-11.7.1.4 DoS via Improper Input Validation
CVSS 5.9
CVE-2023-44098 HIGH
Card Management Module - Info Disclosure
CVSS 7.5
CVE-2023-33228 MEDIUM
SolarWinds Network Configuration Manager - Info Disclosure
CVSS 4.5
CVE-2023-41096 MEDIUM
Silicon Labs Ember ZNet SDK <7.3.1 - Info Disclosure
CVSS 6.8
CVE-2023-41095 MEDIUM
Silicon Labs OpenThread SDK <2.3.1 - Info Disclosure
CVSS 6.8
CVE-2023-33837 MEDIUM
IBM Security Verify Governance 10.0 - Info Disclosure
CVSS 4.1
CVE-2023-23371 MEDIUM
QVPN 2.2.0-2.2.0.0823 - Authenticated Cleartext Transmission of Sensitive Information
CVSS 5.2
CVE-2023-43618 MEDIUM
schollz/croc < 9.6.5 - Unauthenticated Local IP Address Exposure via Cleartext Protocol Message
CVSS 5.3
CVE-2023-4580 MEDIUM
Firefox <117, Firefox ESR <115.2, Thunderbird <115.2 - Info Disclosure
CVSS 6.5
CVE-2023-33833 LOW
IBM Security Verify Information Queue <10.0.4,10.0.5 - Info Disclosure
CVSS 2.9
CVE-2023-4420 CRITICAL
SICK LMS5xx Firmware - Unauthenticated Sensitive Data Exposure via Missing TLS Encryption
CVSS 9.8
CVE-2023-40251 MEDIUM
Genian NAC 4.0.0-4.0.155, 5.0.0-5.0.42 & Suite 5.0.0-5.0.54 & ZTNA 6.0.0-6.0.15 - Sensitive Data Unencrypted
CVSS 5.2
CVE-2023-4384 LOW
MaximaTech Portal Executivo 21.9.1.140 - Info Disclosure
CVSS 3.7
CVE-2023-39843 LOW
Sulimet 5-in-1 Smart Door Lock Firmware v1.0 - Missing Encryption of Sensitive Data in RFID Tag
CVSS 2.4
CVE-2023-39842 LOW
Digoo DG-HAMB Smart Home Security System v1.0 - Missing Encryption of Sensitive Data in RFID Tag
CVSS 2.4
CVE-2023-39841 MEDIUM
Etekcity 3-in-1 Smart Door Lock Firmware v1.0 - Missing Encryption of Sensitive Data in RFID Tag
CVSS 4.6
CVE-2023-39954 LOW
nextcloud/user_oidc 1.0.0-1.3.2 - Missing Encryption of Sensitive Data
CVSS 3.8
CVE-2023-37858 MEDIUM
PHOENIX CONTACT WP 6xxx Series Firmware < 4.0.10 - Authenticated Hardcoded Cryptographic Key Exposure
CVSS 4.9
CVE-2023-38699 CRITICAL
MindsDB's AI Virtual Database <23.7.4.0 - Info Disclosure
CVSS 9.1
Details
Vulnerabilities 508
Exploit Likelihood High