Fallos del tipo CWE-300

59 resultados

Ataque de intermediário (Man-in-the-Middle)

É a capacidade de um atacante interceptar, ler ou modificar a comunicação entre dois pontos (cliente-servidor, sistema-sistema) sem que nenhum dos dois saiba. Acontece quando não há autenticação mútua, criptografia ou validação adequada do canal. O risco é crítico: vazamento de dados sensíveis, injeção de comandos maliciosos ou desvio de tráfego.

Ejemplo

Um aplicativo mobile se conecta a uma API via HTTP (não HTTPS) ou não valida o certificado SSL/TLS. Um atacante na mesma rede Wi-Fi consegue interceptar requisições, roubar tokens de autenticação ou injetar respostas falsas que o app acredita ser legítimas.

Cómo mitigar

Use HTTPS/TLS obrigatoriamente com validação rigorosa de certificados (pinning em apps críticos). Implemente autenticação mútua entre os pontos de comunicação e valide sempre a origem e integridade dos dados. Em redes não confiáveis, use VPN ou túneis cifrados.

CVE-2023-38272MEDIUMIBM Cloud Pak System information disclosureEPSS 0.3%CVE-2024-31206HIGHUse of Unencrypted HTTP Request in dectalk-ttsEPSS 0.3%CVE-2021-27768MEDIUMAn SSL certificate host verification vulnerability affects HCL Verse for AndroidEPSS 0.3%CVE-2023-4885MEDIUMMultiple vulnerabilities in Open5GSEPSS 0.3%CVE-2024-36553HIGHForever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h is vulnerable to MITM attack.EPSS 0.3%CVE-2019-19751MEDIUMeasyMINE before 2019-12-05 ships with SSH host keys baked into the installation image, which allows man-in-the-middle attacks and makes idenEPSS 0.3%CVE-2025-63363HIGHA lack of Management Frame Protection in Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1:EPSS 0.3%CVE-2024-27263MEDIUMIBM Sterling B2B Integrator information disclosureEPSS 0.3%CVE-2025-54792CRITICALLocalSend is Vulnerable to Man-in-the-Middle Attacks, Leading to File InterceptionEPSS 0.3%CVE-2024-12602MEDIUMIdentity verification vulnerability in the ParamWatcher module Impact: Successful exploitation of this vulnerability may affect service confEPSS 0.2%CVE-2026-84197CRITICALIn Eclipse Ditto's Node.js JavaScript client, all released versions of @eclipse-ditto/ditto-javascript-client-node from 2.0.0 to 3.9.0 and oEPSS 0.2%CVE-2025-29419HIGHCTFd v3.7.6 was discovered to be vulnerable to a man-in-the-middle attack.EPSS 0.2%CVE-2026-23810MEDIUMCross-BSSID GTK Re-encryption and Traffic InjectionEPSS 0.2%CVE-2026-23811MEDIUMUnauthorized Bi-Directional Traffic Interception via L2/L3 ManipulationEPSS 0.2%CVE-2025-20122HIGHCisco Catalyst SD-WAN Manager Privilege Escalation VulnerabilityEPSS 0.1%CVE-2026-23812MEDIUMSecurity Boundary Bypass via Routing Node ImpersonationEPSS 0.1%CVE-2026-12991HIGHMultiple vulnerabilities in Ghost Robotics' Vision 60EPSS 0.1%CVE-2025-40770HIGHA vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions). The affected application uses a monitorinEPSS 0.1%CVE-2026-76715HIGHUnauthenticated Man-in-the-Middle Attach Leads to Remote Code Execution Vulnerability in HPE Networking Analytics and Location Engine (ALE)EPSS