CWE-311
519 CVEs • Abstraction: Class • Likelihood of Exploit: High
Missing Encryption of Sensitive Data
The product does not encrypt sensitive or critical information before storage or transmission.
CVEs (519)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Geoip Lite Country Project 1Geoip Lite Country Nov 21, 2024 May 29, 2018 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 geoip-lite-country is a stripped down version of geoip-lite, supporting only country lookup. geoip-lite-country before 1.1.4 downloads data resources over HTTP, which leaves it vulnerable to MITM attacks. |
1Product Monitor Project 1Product Monitor Nov 21, 2024 May 29, 2018 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 product-monitor is a HTML/JavaScript template for monitoring a product by encouraging product developers to gather all the information about the status of a product, including live monitoring, statistics, endpoints, and...Show more |
install-nw is a module which quickly and robustly installs and caches NW.js. install-nw versions below 1.1.5 download binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause re...Show more |
selenium-download downloads the latest versions of the selenium standalone server and the chromedriver. selenium-download before 2.0.7 downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It...Show more |
aerospike is an Aerospike add-on module for Node.js. aerospike versions below 2.4.2 download binary resources over HTTP, which leaves the module vulnerable to MITM attacks. It may be possible to cause remote code executi...Show more |
1Atisystem 4Alert4000 Firmware Hpss16 FirmwareHpss32 Firmware+1 moreJun 17, 2026 May 25, 2018 N/A· v4 3.1 LOW· v3 2.9 LOW· v2 In ATI Systems Emergency Mass Notification Systems (HPSS16, HPSS32, MHPSS, and ALERT4000) devices, a missing encryption of sensitive data vulnerability caused by specially crafted malicious radio transmissions may allow...Show more |
Privilege Escalation vulnerability in Microsoft Windows client (McTray.exe) in McAfee VirusScan Enterprise (VSE) 8.8 prior to Patch 13 allows local users to spawn unrelated processes with elevated privileges via the syst...Show more |
1Medtronic 2N'vision 8840 Firmware N'vision 8870 FirmwareJun 17, 2026 May 18, 2018 N/A· v4 4.6 MEDIUM· v3 2.1 LOW· v2 Medtronic N'Vision Clinician Programmer 8840 N'Vision Clinician Programme and 8870 N'Vision removable Application Card do not encrypt PII and PHI while at rest. |
1Mimobaby 1Mimo Baby 2 Firmware Nov 21, 2024 May 15, 2018 N/A· v4 5.3 MEDIUM· v3 2.9 LOW· v2 Mimo Baby 2 devices do not use authentication or encryption for the Bluetooth Low Energy (BLE) communication from a Turtle to a Lilypad, which allows attackers to inject fake information about the position and temperatur...Show more |
1Bostonscientific 1Zoom Latitude Prm 3120 Firmware Nov 21, 2024 May 1, 2018 N/A· v4 4.6 MEDIUM· v3 2.1 LOW· v2 Boston Scientific ZOOM LATITUDE PRM Model 3120 does not encrypt PHI at rest. CVSS v3 base score: 4.6; CVSS vector string: AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N. |
1Abbott 4Accent Firmware Accent Mri FirmwareAccent St Firmware+1 moreNov 21, 2024 Apr 25, 2018 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 Abbott Laboratories Accent and Anthem pacemakers manufactured prior to Aug 28, 2017 transmit unencrypted patient information via RF communications to programmers and home monitoring units. Additionally, the Accent and An...Show more |
1Siemens 1Simatic Wincc Oa Operator Nov 21, 2024 Apr 23, 2018 N/A· v4 4.6 MEDIUM· v3 2.1 LOW· v2 A vulnerability has been identified in SIMATIC WinCC OA Operator iOS App (All versions < V1.4). Insufficient protection of sensitive information (e.g. session key for accessing server) in Siemens WinCC OA Operator iOS ap...Show more |
In Philips Alice 6 System version R8.0.2 or prior, the lack of proper data encryption passes up the guarantees of confidentiality, integrity, and accountability that properly implemented encryption conveys. |
In version 1012 and prior of Insteon's Insteon Hub, the radio transmissions used for communication between the hub and connected devices are not encrypted. |
Inappropriate implementation in ChromeVox in Google Chrome OS prior to 62.0.3202.74 allowed a remote attacker in a privileged network position to observe or tamper with certain cleartext HTTP requests by leveraging that...Show more |
An issue was discovered in Flexense DiskBoss 8.8.16 and earlier. Due to the usage of plaintext information from the handshake as input for the encryption key used for the encryption of the rest of the session, the server...Show more |
SuperBeam through 4.1.3, when using the LAN or WiFi Direct Share feature, does not use HTTPS or any integrity-protection mechanism for file transfer, which makes it easier for remote attackers to send crafted files, as d...Show more |
1Hikvision 1Ds 2cd2432f I(w) Firmware May 13, 2026 Dec 1, 2017 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 HikVision Wi-Fi IP cameras, when used in a wired configuration, allow physically proximate attackers to trigger association with an arbitrary access point by leveraging a default SSID with no WiFi encryption or authentic...Show more |
FusionSphere OpenStack with software V100R006C00SPC102(NFV) and V100R006C10 have an information leak vulnerability. Due to an incorrect configuration item, the information transmitted by a transmission channel is not enc...Show more |
In the "Diary with lock" (aka WriteDiary) application 4.72 for Android, neither HTTPS nor other encryption is used for transmitting data, despite the documentation that the product is intended for "a personal journal of...Show more |