Insecure SQL Connection

Transport security disabled for a C# SQL connection

Description

If a SQL Server client does not require encryption of all traffic or skips server certificate validation, database traffic can be exposed to a network attacker. A server can force encryption even with Encrypt=False, so check the server settings and driver version when assessing the actual protection.

Potential impact

  • Database credentials and query results can be exposed or modified through a man-in-the-middle attack.

Remediation

Use Encrypt=true and validate the server certificate. Do not use Encrypt=false or TrustServerCertificate=true outside temporary development environments.

Examples

Before

csharp
using var connection = new SqlConnection(
    "Server=db;Database=App;Encrypt=False");

After

csharp
using var connection = new SqlConnection(
    "Server=db;Database=App;Encrypt=True;TrustServerCertificate=False");

Explanation:

  • Before: Encrypt=False means that the client does not require encryption of all traffic. The actual protection depends on the server's forced-encryption setting and the driver.
  • After: Require an encrypted SQL connection and validate the server certificate instead of setting Encrypt=false or TrustServerCertificate=true.

References