Weaknesses of type CWE-319

538 results

Transmissão de dados sensíveis em texto plano

A aplicação envia informações críticas (senhas, tokens, dados pessoais) sem criptografia em canais de comunicação que podem ser interceptados. Um atacante na rede consegue capturar esses dados diretamente, comprometendo a confidencialidade da informação e permitindo roubo de credenciais ou dados sensíveis.

Example

Um app mobile envia login e senha via HTTP (não HTTPS), ou um sistema transmite números de cartão de crédito em requisições não criptografadas. Ferramentas simples como Wireshark permitem capturar esse tráfego em redes abertas ou mesmo corporativas.

How to mitigate

Sempre usar HTTPS/TLS para qualquer transmissão de dados sensíveis, implementar pinning de certificado em apps mobile, validar certificados no lado cliente, e nunca transmitir segredos em URLs ou headers sem criptografia. Na prática: configure HTTPS em produção, force redirecionamento HTTP → HTTPS, e audite logs de requisições para detectar canais desprotegidos.

CVE-2025-8205MEDIUMComodo Dragon IP DNS Leakage Detector cleartext transmissionEPSS 0.4%CVE-2023-32290HIGHThe myMail app through 14.30 for iOS sends cleartext credentials in a situation where STARTTLS is expected by a server.EPSS 0.4%CVE-2024-27163MEDIUMLeak of admin password and passwordsEPSS 0.4%CVE-2003-5002LOWISS BlackICE PC Protection Update cleartext transmissionEPSS 0.4%CVE-2022-41636CRITICALCommunication traffic involving "Ethernet Q Commands" service of Haas Controller version 100.20.000.1110 is transmitted in cleartext. This aEPSS 0.4%CVE-2026-15806MEDIUM`HTTPPasswordMgr` can send saved HTTPS credentials via HTTP because of incorrect scheme matchingEPSS 0.4%CVE-2022-22385MEDIUMIBM Security Verify Privilege information disclosureEPSS 0.4%CVE-2023-29680MEDIUMCleartext Transmission in set-cookie:ecos_pw: Tenda N301 v6.0, Firmware v12.02.01.61_multi allows an authenticated attacker on the LAN or WLEPSS 0.4%CVE-2023-29681MEDIUMCleartext Transmission in cookie:ecos_pw: in Tenda N301 v6.0, firmware v12.03.01.06_pt allows an authenticated attacker on the LAN or WLAN tEPSS 0.4%CVE-2023-30515HIGHJenkins Thycotic DevOps Secrets Vault Plugin 1.0.0 and earlier does not properly mask (i.e., replace with asterisks) credentials in the builEPSS 0.4%CVE-2023-5461LOWDelta Electronics WPLSoft Modbus cleartext transmissionEPSS 0.4%CVE-2021-21387HIGHPartial secret key disclosure, improper safety number calculation, & inadequate encryption strengthEPSS 0.4%CVE-2024-6515HIGHunauthorized file accessEPSS 0.4%CVE-2022-3929HIGHCommunication between the client and server partially using CORBA over TCP/IPEPSS 0.4%CVE-2022-21951MEDIUMRancher: Weave CNI password is not set if RKE template is used with CNI value overriddenEPSS 0.4%CVE-2020-4497MEDIUMIBM Spectrum Protect Plus information disclosureEPSS 0.4%CVE-2023-0053HIGHSAUTER Controls Nova 200–220 Series Cleartext Transmission of Sensitive InformationEPSS 0.4%CVE-2023-31193HIGH Snap One OvrC Pro versions prior to 7.3 use HTTP connections when downloading a program from their servers. Because they do notEPSS 0.4%CVE-2022-45483MEDIUMLazy Mouse allows an attacker (in a man in the middle position between the server and a connected device) to see all data (including keypresEPSS 0.4%CVE-2022-45480MEDIUMPC Keyboard WiFi & Bluetooth allows an attacker (in a man-in-the-middle position between the server and a connected device) to see all data EPSS 0.4%