Weaknesses of type CWE-319

538 results

Transmissão de dados sensíveis em texto plano

A aplicação envia informações críticas (senhas, tokens, dados pessoais) sem criptografia em canais de comunicação que podem ser interceptados. Um atacante na rede consegue capturar esses dados diretamente, comprometendo a confidencialidade da informação e permitindo roubo de credenciais ou dados sensíveis.

Example

Um app mobile envia login e senha via HTTP (não HTTPS), ou um sistema transmite números de cartão de crédito em requisições não criptografadas. Ferramentas simples como Wireshark permitem capturar esse tráfego em redes abertas ou mesmo corporativas.

How to mitigate

Sempre usar HTTPS/TLS para qualquer transmissão de dados sensíveis, implementar pinning de certificado em apps mobile, validar certificados no lado cliente, e nunca transmitir segredos em URLs ou headers sem criptografia. Na prática: configure HTTPS em produção, force redirecionamento HTTP → HTTPS, e audite logs de requisições para detectar canais desprotegidos.

CVE-2023-1802MEDIUMIn Docker Desktop 4.17.x the Artifactory Integration falls back to sending registry credentials over plain HTTP if the HTTPS health check has failedEPSS 0.5%CVE-2020-27656MEDIUMCleartext transmission of sensitive information vulnerability in DDNS in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-EPSS 0.5%CVE-2021-23018—Intra-cluster communication does not use TLS. The services within the NGINX Controller 3.x before 3.4.0 namespace are using cleartext protocEPSS 0.5%CVE-2020-8356MEDIUMAn internal product security audit of LXCO, prior to version 1.2.2, discovered that optional passwords, if specified, for the Syslog and SMTEPSS 0.5%CVE-2021-3417MEDIUMAn internal product security audit of LXCO, prior to version 1.2.2, discovered that credentials for Lenovo XClarity Administrator (LXCA), ifEPSS 0.5%CVE-2022-38122HIGHPOWERCOM CO., LTD. UPSMON PRO - Cleartext Transmission of Sensitive InformationEPSS 0.5%CVE-2020-8355MEDIUMAn internal product security audit of Lenovo XClarity Administrator (LXCA) prior to version 3.1.0 discovered the Windows OS credentials provEPSS 0.5%CVE-2020-5399HIGHCredHub does not properly enable TLS for MySQL database connectionsEPSS 0.5%CVE-2022-2005HIGHAutomationDirect C-more EA9 HMI Cleartext TransmissionEPSS 0.5%CVE-2022-2485CRITICALAutomationDirect Stride Field I/O Cleartext Transmission of Sensitive InformationEPSS 0.5%CVE-2022-32245—SAP BusinessObjects Business Intelligence Platform (Open Document) - versions 420, 430, allows an unauthenticated attacker to retrieve sensiEPSS 0.5%CVE-2022-0988HIGHDelta Electronics DIAEnergie CLEARTEXT Transmission of Sensitive InformationEPSS 0.5%CVE-2023-22597MEDIUM InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-S-V2.3.0.r5542, contain vulnerEPSS 0.5%CVE-2024-0860HIGHCleartext Transmission of Sensitive Information in Softing edgeConnector and edgeAggregatorEPSS 0.5%CVE-2021-42699MEDIUMAzeoTech DAQFactoryEPSS 0.5%CVE-2020-7308MEDIUMTransmission of data in clear text by McAfee ENSEPSS 0.5%CVE-2023-25070MEDIUMCleartext transmission of sensitive information exists in SkyBridge MB-A100/110 firmware Ver. 4.2.0 and earlier. If the telnet connection isEPSS 0.5%CVE-2021-0296HIGHCTPView: HSTS not being enforced on CTPView server.EPSS 0.5%CVE-2022-45546HIGHInformation Disclosure in Authentication Component of ScreenCheck BadgeMaker 2.6.2.0 application allows internal attacker to obtain credentiEPSS 0.5%CVE-2024-12378CRITICALOn affected platforms running Arista EOS with secure Vxlan configured, restarting the Tunnelsec agent will result in packets being sent over the secure Vxlan tunnels in the clear.EPSS 0.5%