Weaknesses of type CWE-319

538 results

Transmissão de dados sensíveis em texto plano

A aplicação envia informações críticas (senhas, tokens, dados pessoais) sem criptografia em canais de comunicação que podem ser interceptados. Um atacante na rede consegue capturar esses dados diretamente, comprometendo a confidencialidade da informação e permitindo roubo de credenciais ou dados sensíveis.

Example

Um app mobile envia login e senha via HTTP (não HTTPS), ou um sistema transmite números de cartão de crédito em requisições não criptografadas. Ferramentas simples como Wireshark permitem capturar esse tráfego em redes abertas ou mesmo corporativas.

How to mitigate

Sempre usar HTTPS/TLS para qualquer transmissão de dados sensíveis, implementar pinning de certificado em apps mobile, validar certificados no lado cliente, e nunca transmitir segredos em URLs ou headers sem criptografia. Na prática: configure HTTPS em produção, force redirecionamento HTTP → HTTPS, e audite logs de requisições para detectar canais desprotegidos.

CVE-2017-20200MEDIUMCoinomi cleartext transmissionEPSS 0.3%CVE-2023-50703MEDIUM Cleartext Transmission of Sensitive Information in EFACEC UC 500EEPSS 0.3%CVE-2022-32857MEDIUMThis issue was addressed by using HTTPS when sending information over the network. This issue is fixed in macOS Monterey 12.5, macOS Big SurEPSS 0.3%CVE-2024-44276HIGHThis issue was addressed by using HTTPS when sending information over the network. This issue is fixed in iOS 18.2 and iPadOS 18.2. A user iEPSS 0.3%CVE-2026-48978LOWoras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokensEPSS 0.3%CVE-2025-65827CRITICALThe mobile application is configured to allow clear text traffic to all domains and communicates with an API server over HTTP. As a result, EPSS 0.3%CVE-2025-41718HIGHMurrelektronik: Unprotected Transport of CredentialsEPSS 0.3%CVE-2026-55844HIGHHome Assistant: iOS Companion App ignores internal SSID allowlist for connections – possible leak of access token and sensor dataEPSS 0.3%CVE-2024-40090MEDIUMVilo 5 Mesh WiFi System <= 5.16.1.33 is vulnerable to Information Disclosure. An information leak in the Boa webserver allows remote, unauthEPSS 0.3%CVE-2024-49819MEDIUMIBM Security Guardium Key Lifecycle Manager information disclosureEPSS 0.3%CVE-2025-27457MEDIUMCVE-2025-27457EPSS 0.3%CVE-2024-7408HIGHInformation Disclosure Vulnerability in Airveda Air Quality MonitorEPSS 0.3%CVE-2024-50624MEDIUMispdbservice.cpp in KDE Kmail before 6.2.0 allows man-in-the-middle attackers to trigger use of an attacker-controlled mail server because cEPSS 0.3%CVE-2021-29892MEDIUMIBM Cognos Controller information disclosureEPSS 0.3%CVE-2026-85720MEDIUMAsyncHttpClient: Origin credentials sent to the proxy on the plaintext CONNECT requestEPSS 0.3%CVE-2026-5119MEDIUMLibsoup: libsoup: information disclosure via cleartext transmission of cookies during https tunnel establishmentEPSS 0.3%CVE-2025-58107HIGHIn Microsoft Exchange through 2019, Exchange ActiveSync (EAS) configurations on on-premises servers may transmit sensitive data from SamsungEPSS 0.3%CVE-2026-47255HIGHAgenticMail API/storage and outbound relay hardeningEPSS 0.3%CVE-2026-48902CRITICALJoomla! Core - [20260518] - Transport encryption downgrade for password and username reset linksEPSS 0.3%CVE-2025-10776MEDIUMLionCoders SalePro POS Login cleartext transmissionEPSS 0.3%