Property
Languagehcl
Severitylow
CWECWE-320: CWE CATEGORY: Key Management Errors
OWASPA03:2017 - Sensitive Data Exposure
Confidence LevelLow
Impact LevelLow
Likelihood LevelLow

Description#

The Service Fabric cluster configuration does not enforce the highest protection level (‘EncryptAndSign’) for communications. This means data exchanged between cluster nodes may not be fully encrypted and authenticated.

Impact#

Without full encryption and signing, sensitive data within the cluster could be intercepted or tampered with by attackers, potentially leading to data breaches, unauthorized access, or manipulation of cluster operations.