Weaknesses of type CWE-319

538 results

Transmissão de dados sensíveis em texto plano

A aplicação envia informações críticas (senhas, tokens, dados pessoais) sem criptografia em canais de comunicação que podem ser interceptados. Um atacante na rede consegue capturar esses dados diretamente, comprometendo a confidencialidade da informação e permitindo roubo de credenciais ou dados sensíveis.

Example

Um app mobile envia login e senha via HTTP (não HTTPS), ou um sistema transmite números de cartão de crédito em requisições não criptografadas. Ferramentas simples como Wireshark permitem capturar esse tráfego em redes abertas ou mesmo corporativas.

How to mitigate

Sempre usar HTTPS/TLS para qualquer transmissão de dados sensíveis, implementar pinning de certificado em apps mobile, validar certificados no lado cliente, e nunca transmitir segredos em URLs ou headers sem criptografia. Na prática: configure HTTPS em produção, force redirecionamento HTTP → HTTPS, e audite logs de requisições para detectar canais desprotegidos.

CVE-2022-46680HIGH A CWE-319: Cleartext transmission of sensitive information vulnerability exists that could cause disclosure of sensitive information, deniaEPSS 0.4%CVE-2023-46447MEDIUMThe POPS! Rebel application 5.0 for Android, in POPS! Rebel Bluetooth Glucose Monitoring System, sends unencrypted glucose measurements overEPSS 0.4%CVE-2024-1657HIGHPlatform: insecure websocket used when interacting with eda serverEPSS 0.4%CVE-2023-51741HIGHCleartext Submission of Password vulnerability in Skyworth RouterEPSS 0.4%CVE-2019-5635MEDIUMHickory Smart Lock Cleartext PasswordEPSS 0.4%CVE-2022-27619MEDIUMCleartext transmission of sensitive information vulnerability in authentication management in Synology Note Station Client before 2.2.2-609 EPSS 0.4%CVE-2023-51740HIGHCleartext Submission of Password vulnerability in Skyworth RouterEPSS 0.4%CVE-2023-50614HIGHAn issue discovereed in EBYTE E880-IR01-V1.1 allows an attacker to obtain sensitive information via crafted POST request to /cgi-bin/luci.EPSS 0.4%CVE-2021-3494—A smart proxy that provides a restful API to various sub-systems of the Foreman is affected by the flaw which can cause a Man-in-the-Middle EPSS 0.4%CVE-2025-8741MEDIUMmacrozheng mall login cleartext transmissionEPSS 0.4%CVE-2023-22806HIGHCVE-2023-22806EPSS 0.4%CVE-2024-0220HIGHB&R products use insufficient communication encryptionEPSS 0.4%CVE-2022-22758HIGHWhen clicking on a tel: link, USSD codes, specified after a <code>\*</code> character, would be included in the phone number. On certain phoEPSS 0.4%CVE-2024-31840MEDIUMAn issue was discovered in Italtel Embrace 1.6.4. The web application inserts cleartext passwords in the HTML source code. An authenticated EPSS 0.4%CVE-2023-31300HIGHAn issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitivEPSS 0.4%CVE-2023-38276MEDIUMIBM Cognos Dashboards information disclosureEPSS 0.4%CVE-2023-38275MEDIUMIBM Cognos Dashboards information disclosureEPSS 0.4%CVE-2022-32906MEDIUMThis issue was addressed with using HTTPS when sending information over the network. This issue is fixed in Apple Music 3.9.10 for Android. EPSS 0.4%CVE-2024-47789HIGHCredential Leakage VulnerabilityEPSS 0.4%CVE-2023-22863MEDIUMIBM Robotic Process Automation information disclosureEPSS 0.4%