Weaknesses of type CWE-319

538 results

Transmissão de dados sensíveis em texto plano

A aplicação envia informações críticas (senhas, tokens, dados pessoais) sem criptografia em canais de comunicação que podem ser interceptados. Um atacante na rede consegue capturar esses dados diretamente, comprometendo a confidencialidade da informação e permitindo roubo de credenciais ou dados sensíveis.

Example

Um app mobile envia login e senha via HTTP (não HTTPS), ou um sistema transmite números de cartão de crédito em requisições não criptografadas. Ferramentas simples como Wireshark permitem capturar esse tráfego em redes abertas ou mesmo corporativas.

How to mitigate

Sempre usar HTTPS/TLS para qualquer transmissão de dados sensíveis, implementar pinning de certificado em apps mobile, validar certificados no lado cliente, e nunca transmitir segredos em URLs ou headers sem criptografia. Na prática: configure HTTPS em produção, force redirecionamento HTTP → HTTPS, e audite logs de requisições para detectar canais desprotegidos.

CVE-2022-43724CRITICALA vulnerability has been identified in SICAM PAS/PQS (All versions < V7.0). Affected software transmits the database credentials for the inbEPSS 0.6%CVE-2022-21798HIGHICSA-22-053-02 GE Proficy CIMPLICITY-CleartextEPSS 0.6%CVE-2023-3272HIGHCleartext Transmission of Sensitive Information in the SICK ICR890-4 could allow a remote attacker to gather sensitive information by intercEPSS 0.6%CVE-2022-47714CRITICALLast Yard 22.09.8-1 does not enforce HSTS headersEPSS 0.6%CVE-2022-39269CRITICALMedia transport downgrade from the secure version (SRTP) to non-secure (RTP) in pjsipEPSS 0.6%CVE-2021-22703MEDIUMA CWE-319: Cleartext transmission of sensitive information vulnerability exists in PowerLogic ION7400, ION7650, ION83xx/84xx/85xx/8600, ION8EPSS 0.6%CVE-2021-40392MEDIUMAn information disclosure vulnerability exists in the Web Application functionality of Moxa MXView Series 3.2.4. Network sniffing can lead tEPSS 0.6%CVE-2023-3763LOWIntergard SGS SQL Query cleartext transmissionEPSS 0.6%CVE-2022-30994—Cleartext transmission of sensitive informationEPSS 0.6%CVE-2022-30993—Cleartext transmission of sensitive informationEPSS 0.6%CVE-2021-22702MEDIUMA CWE-319: Cleartext transmission of sensitive information vulnerability exists in PowerLogic ION7400, ION7650, ION7700/73xx, ION83xx/84xx/8EPSS 0.6%CVE-2023-39245CRITICAL DELL ESI (Enterprise Storage Integrator) for SAP LAMA, version 10.0, contains an information disclosure vulnerability in EHAC component. AnEPSS 0.6%CVE-2020-27657MEDIUMCleartext transmission of sensitive information vulnerability in DDNS in Synology Router Manager (SRM) before 1.2.4-8081 allows man-in-the-mEPSS 0.6%CVE-2023-39172CRITICALSENEC: Storage Box V1,V2 and V3 transmitting sensitive data unencryptedEPSS 0.6%CVE-2023-32328HIGHIBM Security Verify Access information disclosureEPSS 0.6%CVE-2017-8444—The client-forwarder in Elastic Cloud Enterprise versions prior to 1.0.2 do not properly encrypt traffic to ZooKeeper. If an attacker is ablEPSS 0.6%CVE-2018-8842—Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software transmits sensitive or security-critical data in cleartext iEPSS 0.6%CVE-2025-26199CRITICALCloudClassroom-PHP-Project v1.0 is affected by an insecure credential transmission vulnerability. The application transmits passwords over uEPSS 0.6%CVE-2021-38418HIGHDelta Electronics DIALinkEPSS 0.6%CVE-2024-48788HIGHAn issue in YESCAM (com.yescom.YesCam.zwave) 1.0.2 allows a remote attacker to obtain sensitive information via the firmware update process.EPSS 0.6%