CWE · MITRE source
CWE-311Missing Encryption of Sensitive Data
The product does not encrypt sensitive or critical information before storage or transmission.
Last updated: 21 August 2026 20:21 UTC
Cumulative inbound coverage
How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.
Collective: full · 19 mapping(s) from 9 framework(s): CAPEC 9 (partial) · CSF 2.0 2 (mostly) · ATT&CK 2 (partial) · STIG windows server 2019 1 (full) · STIG oracle linux 8 1 (mostly) · STIG oracle linux 9 1 (mostly) · STIG rhel 8 1 (mostly) · STIG rhel 9 1 (mostly) · STIG windows server 2016 1 (mostly)
OWASP Top 10 for Web (2025)
This weakness contributes to A06:2025 Insecure Design.
Control responseHuman-reviewed
Answering this weakness across the control lifecycle, from our framework cross-walks.
—
- 7 hardening rules · 7 OS baselines
—
NIST 800-53 r5 controls that address this weakness (12)AI-assisted
| Control | Title | Family | Why it addresses this CWE |
|---|---|---|---|
CM-13 | Data Action Mapping | CM | The map highlights data actions that involve sensitive data, enabling identification of missing encryption requirements. |
CM-6 | Configuration Settings | CM | Settings can require encryption of sensitive data, preventing missing encryption weaknesses. |
PM-13 | Security and Privacy Workforce | PM | Privacy and security curricula stress encryption requirements, reducing missing encryption of sensitive data. |
PM-17 | Protecting Controlled Unclassified Information on External Systems | PM | Requires encryption and similar controls for CUI processed or stored externally, preventing missing encryption of sensitive data. |
RA-5 | Vulnerability Monitoring and Scanning | RA | Monitoring detects missing encryption of sensitive data in storage or transit configurations. |
RA-8 | Privacy Impact Assessments | RA | Privacy assessments routinely identify the need for encryption of PII, directly lowering the impact of missing encryption weaknesses. |
SA-3 | System Development Life Cycle | SA | Privacy and security considerations mandated across the SDLC make identification and protection of sensitive data (including encryption decisions) a required activity rather than an afterthought. |
SA-9 | External System Services | SA | Privacy and security requirements placed on external providers, together with monitoring, tangibly reduce missing encryption of sensitive data processed or stored by those services. |
AT-3 | Role-based Training | AT | Privacy and security training stresses encryption of sensitive data, reducing missing encryption weaknesses. |
CA-3 | Information Exchange | CA | Exchange agreements must document security requirements, which would include encryption to protect sensitive data in transit. |
PL-8 | Security and Privacy Architectures | PL | Architectures must describe confidentiality protections, which includes mandating encryption for sensitive data in transit and at rest. |
SC-13 | Cryptographic Protection | SC | Mandates encryption for specified data uses, directly preventing missing encryption of sensitive information. |
MITRE ATT&CK techniques this weakness enables
Our own two-way CWE↔ATT&CK cross-walk — a direct mapping with no public source (the CWE→CAPEC→ATT&CK chain leaves most top weaknesses, incl. XSS and SQLi, mapped to nothing).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Top CVEs of this weakness type, ranked by Risk Priority
| CVE | Risk | CVSS | EPSS | Published |
|---|---|---|---|---|
CVE-2026-27944 | 8.6 | 9.8 | 0.2216 | 2026-03-05 |
CVE-2026-34486 KEV UPD | 8.5 | 7.5 | 0.8293 | 2026-04-09 |
CVE-2019-11367 UPD | 7.8 | 9.8 | 0.0282 | 2019-06-03 |
CVE-2018-10698 UPD | 7.7 | 9.8 | 0.0234 | 2019-06-07 |
CVE-2017-3198 UPD | 7.6 | 9.8 | 0.0160 | 2018-07-09 |
CVE-2017-9854 UPD | 7.5 | 9.8 | 0.0113 | 2017-08-05 |
CVE-2018-17915 UPD | 7.5 | 9.8 | 0.0110 | 2018-10-10 |
CVE-2018-16879 UPD | 7.5 | 9.8 | 0.0111 | 2019-01-03 |
CVE-2018-10612 UPD | 7.5 | 9.8 | 0.0127 | 2019-01-29 |
CVE-2019-6526 UPD | 7.5 | 9.8 | 0.0100 | 2019-04-15 |
CVE-2019-11523 UPD | 7.5 | 9.8 | 0.0121 | 2019-06-06 |
CVE-2019-12924 UPD | 7.5 | 9.8 | 0.0090 | 2019-07-08 |
CVE-2019-14480 UPD | 7.5 | 9.8 | 0.0112 | 2020-12-16 |
CVE-2020-15331 UPD | 7.5 | 9.8 | 0.0089 | 2022-09-29 |
CVE-2017-7406 UPD | 7.4 | 9.8 | 0.0069 | 2017-07-07 |
CVE-2018-7498 UPD | 7.4 | 9.8 | 0.0065 | 2018-03-28 |
CVE-2018-20100 UPD | 7.4 | 9.8 | 0.0071 | 2019-01-02 |
CVE-2017-9632 UPD | 7.3 | 9.8 | 0.0047 | 2017-08-07 |
CVE-2019-3431 UPD | 7.3 | 9.8 | 0.0040 | 2019-12-23 |
CVE-2023-0750 UPD | 7.3 | 9.8 | 0.0045 | 2023-04-06 |
CVE-2023-4420 UPD | 7.2 | 9.8 | 0.0024 | 2023-08-24 |
CVE-2023-6339 UPD | 7.2 | 10.0 | 0.0018 | 2024-01-02 |
CVE-2020-12032 UPD | 7.0 | 9.1 | 0.0094 | 2020-06-29 |
CVE-2019-18800 UPD | 6.9 | 8.8 | 0.0166 | 2019-11-06 |
CVE-2021-27779 UPD | 6.9 | 9.1 | 0.0058 | 2022-05-25 |