E of Information Disclosure
Personal data is being sent over a plaintext connection or email.
Threat |
|
You’re communicating the personal information of your customers via some means that isn’t encrypted so an attacker who is capturing your network traffic as it passes over the internet can read their details. |
|
CAPEC |
CAPEC-94 - Adversary in the Middle (AiTM) CAPEC-157 - Sniffing Attacks CAPEC-158 - Sniffing Network Traffic |
ASVS |
1.9.1 - Ensure you’re using TLS everywhere. 9.1.1 - Ensure the TLS version can’t be downgraded. 9.2.2 - Ensure TLS is also used for monitoring and management interfaces and can’t be downgraded. |
CWE |
CWE-319 - Cleartext Transmission... |