Weaknesses of type CWE-319

538 results

Transmissão de dados sensíveis em texto plano

A aplicação envia informações críticas (senhas, tokens, dados pessoais) sem criptografia em canais de comunicação que podem ser interceptados. Um atacante na rede consegue capturar esses dados diretamente, comprometendo a confidencialidade da informação e permitindo roubo de credenciais ou dados sensíveis.

Example

Um app mobile envia login e senha via HTTP (não HTTPS), ou um sistema transmite números de cartão de crédito em requisições não criptografadas. Ferramentas simples como Wireshark permitem capturar esse tráfego em redes abertas ou mesmo corporativas.

How to mitigate

Sempre usar HTTPS/TLS para qualquer transmissão de dados sensíveis, implementar pinning de certificado em apps mobile, validar certificados no lado cliente, e nunca transmitir segredos em URLs ou headers sem criptografia. Na prática: configure HTTPS em produção, force redirecionamento HTTP → HTTPS, e audite logs de requisições para detectar canais desprotegidos.

CVE-2022-2003HIGHAutomationDirect DirectLOGIC with Serial Communication Cleartext TransmissionEPSS 0.7%CVE-2021-27251HIGHThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR Nighthawk R7800. AuthentEPSS 0.7%CVE-2021-3774HIGHMeross MSS550X Missing Encryption of Sensitive DataEPSS 0.7%CVE-2026-23662HIGHAzure IoT Explorer Information Disclosure VulnerabilityEPSS 0.7%CVE-2020-10281HIGHRVD#3315: Cleartext transmission of sensitive information in MAVLink protocol version 1.0 and 2.0EPSS 0.7%CVE-2020-5426HIGHScheduler for TAS can transmit privileged UAA token in plaintextEPSS 0.7%CVE-2026-23661HIGHAzure IoT Explorer Information Disclosure VulnerabilityEPSS 0.7%CVE-2025-34271HIGHNagios Log Server < 2024R2.0.2 Cluster Manager Credential Requests Sent Over PlaintextEPSS 0.7%CVE-2022-0162HIGHVulnerability in TP-LinK TL-WR841N wireless routerEPSS 0.7%CVE-2021-26564HIGHCleartext transmission of sensitive information vulnerability in synorelayd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allowEPSS 0.7%CVE-2021-4161CRITICALICSA-21-357-01 Moxa MGate Protocol GatewaysEPSS 0.7%CVE-2022-32227MEDIUMA cleartext transmission of sensitive information exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 relating to Oauth tokens by having the permEPSS 0.7%CVE-2026-24212HIGHNVIDIA Isaac Launchable for Linux contains a vulnerability where sensitive information is transmitted in clear text. A successful exploit ofEPSS 0.7%CVE-2021-32982HIGHAutomation Direct CLICK PLC CPU Modules Cleartext Transmission of Sensitive InformationEPSS 0.7%CVE-2022-40693MEDIUMA cleartext transmission vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. AEPSS 0.6%CVE-2026-3182MEDIUMSensitive Data ExposureEPSS 0.6%CVE-2021-33022HIGHPhilips Vue PACS Cleartext Transmission of Sensitive InformationEPSS 0.6%CVE-2021-32934CRITICALThroughTek P2P SDK - Cleartext Transmission of Sensitive InformationEPSS 0.6%CVE-2020-2013HIGHPAN-OS: Panorama context switch session cookie disclosureEPSS 0.6%CVE-2020-15785A vulnerability has been identified in Siveillance Video Client (All versions). In environments where Windows NTLM authentication is enabledEPSS 0.6%