Vulnerabilities > Missing Encryption of Sensitive Data

DATE CVE VULNERABILITY TITLE RISK
2018-02-22 CVE-2017-5251 Missing Encryption of Sensitive Data vulnerability in Insteon HUB Firmware
In version 1012 and prior of Insteon's Insteon Hub, the radio transmissions used for communication between the hub and connected devices are not encrypted.
network
high complexity
insteon CWE-311
8.1
2018-02-07 CVE-2017-15397 Missing Encryption of Sensitive Data vulnerability in Google Chrome OS
Inappropriate implementation in ChromeVox in Google Chrome OS prior to 62.0.3202.74 allowed a remote attacker in a privileged network position to observe or tamper with certain cleartext HTTP requests by leveraging that position.
network
high complexity
google CWE-311
7.4
2018-02-02 CVE-2018-5261 Missing Encryption of Sensitive Data vulnerability in Flexense Diskboss
An issue was discovered in Flexense DiskBoss 8.8.16 and earlier.
network
high complexity
flexense CWE-311
8.1
2017-12-19 CVE-2017-17763 Missing Encryption of Sensitive Data vulnerability in Liveqos Superbeam
SuperBeam through 4.1.3, when using the LAN or WiFi Direct Share feature, does not use HTTPS or any integrity-protection mechanism for file transfer, which makes it easier for remote attackers to send crafted files, as demonstrated by APK injection.
network
high complexity
liveqos CWE-311
7.5
2017-12-01 CVE-2017-14953 Missing Encryption of Sensitive Data vulnerability in Hikvision Ds-2Cd2432F-Iw Firmware 5.3.0/5.4.0
HikVision Wi-Fi IP cameras, when used in a wired configuration, allow physically proximate attackers to trigger association with an arbitrary access point by leveraging a default SSID with no WiFi encryption or authentication.
low complexity
hikvision CWE-311
6.5
2017-11-22 CVE-2017-8168 Missing Encryption of Sensitive Data vulnerability in Huawei Fusionsphere Openstack V100R006C00Spc102(Nfv)/V100R006C10
FusionSphere OpenStack with software V100R006C00SPC102(NFV) and V100R006C10 have an information leak vulnerability.
low complexity
huawei CWE-311
4.3
2017-10-27 CVE-2017-15581 Missing Encryption of Sensitive Data vulnerability in Writediary Diary With Lock 4.72
In the "Diary with lock" (aka WriteDiary) application 4.72 for Android, neither HTTPS nor other encryption is used for transmitting data, despite the documentation that the product is intended for "a personal journal of ...
network
low complexity
writediary CWE-311
7.5
2017-10-19 CVE-2017-15609 Missing Encryption of Sensitive Data vulnerability in Octopus Deploy
Octopus before 3.17.7 allows attackers to obtain sensitive cleartext information by reading a variable JSON file in certain situations involving Offline Drop Targets.
network
low complexity
octopus CWE-311
7.5
2017-08-25 CVE-2017-12817 Missing Encryption of Sensitive Data vulnerability in Kaspersky Internet Security 11.12.4.1622
In Kaspersky Internet Security for Android 11.12.4.1622, some of the application trace files were not encrypted.
network
low complexity
kaspersky CWE-311
7.5
2017-08-07 CVE-2017-9632 Missing Encryption of Sensitive Data vulnerability in Pdqinc products
A Missing Encryption of Sensitive Data issue was discovered in PDQ Manufacturing LaserWash G5 and G5 S Series all versions, LaserWash M5, all versions, LaserWash 360 and 360 Plus, all versions, LaserWash AutoXpress and AutoExpress Plus, all versions, LaserJet, all versions, ProTouch Tandem, all versions, ProTouch ICON, all versions, and ProTouch AutoGloss, all versions.
network
low complexity
pdqinc CWE-311
critical
9.8