Weaknesses of type CWE-319

538 results

Transmissão de dados sensíveis em texto plano

A aplicação envia informações críticas (senhas, tokens, dados pessoais) sem criptografia em canais de comunicação que podem ser interceptados. Um atacante na rede consegue capturar esses dados diretamente, comprometendo a confidencialidade da informação e permitindo roubo de credenciais ou dados sensíveis.

Example

Um app mobile envia login e senha via HTTP (não HTTPS), ou um sistema transmite números de cartão de crédito em requisições não criptografadas. Ferramentas simples como Wireshark permitem capturar esse tráfego em redes abertas ou mesmo corporativas.

How to mitigate

Sempre usar HTTPS/TLS para qualquer transmissão de dados sensíveis, implementar pinning de certificado em apps mobile, validar certificados no lado cliente, e nunca transmitir segredos em URLs ou headers sem criptografia. Na prática: configure HTTPS em produção, force redirecionamento HTTP → HTTPS, e audite logs de requisições para detectar canais desprotegidos.

CVE-2022-45478MEDIUMTelepad allows an attacker (in a man-in-the-middle position between the server and a connected device) to see all data (including keypressesEPSS 0.3%CVE-2024-31905MEDIUMIBM QRadar Network Packet Capture information disclosureEPSS 0.3%CVE-2025-66573MEDIUMSolstice Pod API Session Key Extraction via API EndpointEPSS 0.3%CVE-2022-32510HIGHAn issue was discovered on certain Nuki Home Solutions devices. The HTTP API exposed by a Bridge used an unencrypted channel to provide an aEPSS 0.3%CVE-2022-41545MEDIUMThe administrative web interface of a Netgear C7800 Router running firmware version 6.01.07 (and possibly others) authenticates users via baEPSS 0.3%CVE-2025-67159HIGHVatilon v1.12.37-20240124 was discovered to transmit user credentials in plaintext.EPSS 0.3%CVE-2024-46505CRITICALInfoblox BloxOne v2.4 was discovered to contain a business logic flaw due to thick client vulnerabilities.EPSS 0.3%CVE-2024-11946LOWiXsystems TrueNAS CORE fetch_plugin_packagesites tar Cleartext Transmission of Sensitive Information VulnerabilityEPSS 0.3%CVE-2025-56447CRITICALTM2 Monitoring v3.04 contains an authentication bypass and plaintext credential disclosure.EPSS 0.3%CVE-2023-40729HIGHA vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected application lacks security control to prevent unEPSS 0.3%CVE-2026-64742MEDIUMThis issue was addressed by using HTTPS when sending information over the network. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOEPSS 0.3%CVE-2024-36426HIGHIn TARGIT Decision Suite 23.2.15007.0 before Autumn 2023, the session token is part of the URL and may be sent in a cleartext HTTP session.EPSS 0.3%CVE-2025-27720CRITICALPixmeo OsiriX MD Cleartext Transmission of Sensitive InformationEPSS 0.3%CVE-2023-25848MEDIUMBUG-000158039 - There is an information disclosure issue in ArcGIS Server.EPSS 0.3%CVE-2024-32946MEDIUMA vulnerability in the LevelOne WBR-6012 router's firmware version R0.40e6 allows sensitive information to be transmitted in cleartext via WEPSS 0.3%CVE-2025-5270HIGHSNI was sometimes unencryptedEPSS 0.3%CVE-2024-53246MEDIUMSensitive Information Disclosure through SPL commandsEPSS 0.3%CVE-2025-53139HIGHWindows Hello Security Feature Bypass VulnerabilityEPSS 0.3%CVE-2023-33187MEDIUMhighlight vulnerable to cleartext transmission of sensitive informationEPSS 0.3%CVE-2025-27722MEDIUMCleartext transmission of sensitive information issue exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If exploited, a man-in-the-middle attackEPSS 0.3%