Cyber Posture

CWE · MITRE source

CWE-311Missing Encryption of Sensitive Data

Abstraction: Class · CVEs in our corpus: 506

The product does not encrypt sensitive or critical information before storage or transmission.

Last updated: 09 May 2026 03:25 UTC

NIST 800-53 r5 controls that address this weakness (12)AI

Control Title Family Why it addresses this CWE
CM-13Data Action MappingCMThe map highlights data actions that involve sensitive data, enabling identification of missing encryption requirements.
CM-6Configuration SettingsCMSettings can require encryption of sensitive data, preventing missing encryption weaknesses.
PM-13Security and Privacy WorkforcePMPrivacy and security curricula stress encryption requirements, reducing missing encryption of sensitive data.
PM-17Protecting Controlled Unclassified Information on External SystemsPMRequires encryption and similar controls for CUI processed or stored externally, preventing missing encryption of sensitive data.
RA-5Vulnerability Monitoring and ScanningRAMonitoring detects missing encryption of sensitive data in storage or transit configurations.
RA-8Privacy Impact AssessmentsRAPrivacy assessments routinely identify the need for encryption of PII, directly lowering the impact of missing encryption weaknesses.
SA-3System Development Life CycleSAPrivacy and security considerations mandated across the SDLC make identification and protection of sensitive data (including encryption decisions) a required activity rather than an afterthought.
SA-9External System ServicesSAPrivacy and security requirements placed on external providers, together with monitoring, tangibly reduce missing encryption of sensitive data processed or stored by those services.
AT-3Role-based TrainingATPrivacy and security training stresses encryption of sensitive data, reducing missing encryption weaknesses.
CA-3Information ExchangeCAExchange agreements must document security requirements, which would include encryption to protect sensitive data in transit.
PL-8Security and Privacy ArchitecturesPLArchitectures must describe confidentiality protections, which includes mandating encryption for sensitive data in transit and at rest.
SC-13Cryptographic ProtectionSCMandates encryption for specified data uses, directly preventing missing encryption of sensitive information.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2017-82212.67.50.19072017-04-25
CVE-2026-279442.39.80.05832026-03-05
CVE-2019-113672.29.80.03532019-06-03
CVE-2019-115232.19.80.02512019-06-06
CVE-2017-74062.09.80.00102017-07-07
CVE-2017-98542.09.80.00202017-08-05
CVE-2017-96322.09.80.00072017-08-07
CVE-2018-74982.09.80.00092018-03-28
CVE-2017-31982.09.80.00212018-07-09
CVE-2018-179152.09.80.00092018-10-10
CVE-2018-201002.09.80.00162019-01-02
CVE-2018-168792.09.80.00232019-01-03
CVE-2018-106122.09.80.00222019-01-29
CVE-2019-65262.09.80.00122019-04-15
CVE-2018-106982.09.80.00192019-06-07
CVE-2019-129242.09.80.00112019-07-08
CVE-2019-34312.09.80.00072019-12-23
CVE-2019-144802.09.80.00292020-12-16
CVE-2020-153312.09.80.00282022-09-29
CVE-2023-07502.09.80.00242023-04-06
CVE-2023-44202.09.80.00072023-08-24
CVE-2023-63392.010.00.00042024-01-02
CVE-2025-699691.99.60.00052026-03-04
CVE-2017-32181.88.80.00022017-06-21
CVE-2017-32191.88.80.00032017-06-21