CWE-311

High likelihood

Missing Encryption of Sensitive Data

Parent: CWE-693 - Protection Mechanism Failure

The product does not encrypt sensitive or critical information before storage or transmission.

511 vulnerabilities with CWE-311
CVE-2022-27225 MEDIUM
Gradle Enterprise >=2020.1 <2021.4.3 - Session Hijacking via Insecure Keycloak Cookie Transmission
CVSS 6.5
CVE-2022-26157 MEDIUM
Cherwell Service Mgmt <10.2.3 - Info Disclosure
CVSS 5.3
CVE-2022-0183 MEDIUM
MIRUPASS PW10 and PW20 Firmware - Unprotected Password Exposure via Physical Access
CVSS 4.6
CVE-2022-23116 HIGH
Jenkins Conjur Secrets Plugin < 1.0.9 - Sensitive Data Exposure via Agent Process Decryption
CVSS 7.5
CVE-2021-39090 MEDIUM
IBM Cloud Pak for Security 1.10.0.0-1.10.6.0 - Cleartext Transmission of Sensitive Information via Missing HSTS
CVSS 5.9
CVE-2021-4239 HIGH
Noise protocol - Cryptographic Weakness & DoS
CVSS 7.5
CVE-2021-40642 MEDIUM
Textpattern CMS <4.8.7 - Info Disclosure
CVSS 4.3
CVE-2021-40650 MEDIUM
Connx <6.2.0.1269 - Info Disclosure
CVSS 6.5
CVE-2021-27783 MEDIUM
HCL BigFix Mobile - Unencrypted Sensitive Data Exposure in PPKG File
CVSS 6.8
CVE-2021-27779 CRITICAL
VersionVault Express - Info Disclosure
CVSS 9.1
CVE-2021-27764 HIGH
HCL BigFix WebUI - Insecure Cookie Permission Assignment
CVSS 7.4
CVE-2021-37209 MEDIUM
Siemens RUGGEDCOM ROS - Inadequate Encryption Strength in SSH Server
CVSS 6.7
CVE-2021-21963 MEDIUM
Sealevel SeaConnect 370W v1.3.34 - Information Disclosure via Man-in-the-Middle Attack
CVSS 5.9
CVE-2021-37189 HIGH
Digi TransPort Gateway Firmware < 6.0.0.0 - Sensitive Cookie Information Disclosure via Missing Secure Attribute
CVSS 7.5
CVE-2021-36189 MEDIUM
Fortinet FortiClientEMS <7.0.1 & <6.4.4 - Info Disclosure
CVSS 6.8
CVE-2021-37050 HIGH
HarmonyOS < 2.0 - Missing Encryption of Sensitive Data
CVSS 7.5
CVE-2021-38977 MEDIUM
IBM Tivoli Key Lifecycle Manager <4.1 - Open Redirect
CVSS 4.3
CVE-2021-40366 HIGH
Climatix POL909 Firmware < 11.34 (AWM)/< 11.42 (AWB) Cleartext Transmission of Sensitive Info
CVSS 7.4
CVE-2021-35236 LOW
Kiwi Syslog Server <9.7.2 - Info Disclosure
CVSS 3.1
CVE-2021-29883 MEDIUM
IBM Transformation Extender Advanced 9.0.0.0-9.0.2.4 - Missing Encryption of Sensitive Data in Session Cookies
CVSS 4.3
CVE-2021-28496 MEDIUM
Arista EOS 4.22-4.26.1 Authenticated Password Exposure via eAPI
CVSS 5.7
CVE-2021-31386 MEDIUM
Juniper Networks Junos OS <12.3R12-S20, <15.1R7-S11, <18.3R3-S6, <1...
CVSS 5.3
CVE-2021-3882 MEDIUM
LedgerSMB 1.8.0-1.8.21 - Sensitive Cookie Without 'Secure' Attribute
CVSS 6.8
CVE-2021-41302 HIGH
ECOA BAS Controller - Unauthenticated Cleartext Storage of Sensitive Information in Backup Exports
CVSS 7.3
CVE-2021-22932 HIGH
Citrix ShareFile storage zones controller < 5.11.19 - Missing Encryption of Sensitive Data via CTX269106 Mitigation Tool
CVSS 7.5
Details
Vulnerabilities 511
Exploit Likelihood High