Fallos del tipo CWE-319

538 resultados

Transmissão de dados sensíveis em texto plano

A aplicação envia dados críticos (senhas, tokens, informações pessoais) sem criptografia em um canal de comunicação que pode ser interceptado. Um atacante na mesma rede ou posicionado no caminho do tráfego consegue ler esses dados diretamente, comprometendo confidencialidade.

Ejemplo

Um aplicativo mobile que envia credenciais de login via HTTP simples em vez de HTTPS, ou um sistema legado que transmite números de cartão de crédito em texto plano pela rede corporativa. Qualquer um fazendo sniffing de pacotes consegue capturar essas informações.

Cómo mitigar

Use HTTPS/TLS para toda comunicação que envolva dados sensíveis, implemente verificação de certificados válidos no cliente, e nunca transmita senhas ou tokens em parâmetros GET — prefira POST com corpo criptografado. Em APIs, aplique autenticação com tokens seguros e considere criptografia adicional end-to-end para dados ultra-críticos.

CVE-2022-46680HIGH A CWE-319: Cleartext transmission of sensitive information vulnerability exists that could cause disclosure of sensitive information, deniaEPSS 0.4%CVE-2023-46447MEDIUMThe POPS! Rebel application 5.0 for Android, in POPS! Rebel Bluetooth Glucose Monitoring System, sends unencrypted glucose measurements overEPSS 0.4%CVE-2024-1657HIGHPlatform: insecure websocket used when interacting with eda serverEPSS 0.4%CVE-2023-51741HIGHCleartext Submission of Password vulnerability in Skyworth RouterEPSS 0.4%CVE-2019-5635MEDIUMHickory Smart Lock Cleartext PasswordEPSS 0.4%CVE-2022-27619MEDIUMCleartext transmission of sensitive information vulnerability in authentication management in Synology Note Station Client before 2.2.2-609 EPSS 0.4%CVE-2023-51740HIGHCleartext Submission of Password vulnerability in Skyworth RouterEPSS 0.4%CVE-2023-50614HIGHAn issue discovereed in EBYTE E880-IR01-V1.1 allows an attacker to obtain sensitive information via crafted POST request to /cgi-bin/luci.EPSS 0.4%CVE-2021-3494A smart proxy that provides a restful API to various sub-systems of the Foreman is affected by the flaw which can cause a Man-in-the-Middle EPSS 0.4%CVE-2025-8741MEDIUMmacrozheng mall login cleartext transmissionEPSS 0.4%CVE-2023-22806HIGHCVE-2023-22806EPSS 0.4%CVE-2024-0220HIGHB&R products use insufficient communication encryptionEPSS 0.4%CVE-2022-22758HIGHWhen clicking on a tel: link, USSD codes, specified after a <code>\*</code> character, would be included in the phone number. On certain phoEPSS 0.4%CVE-2024-31840MEDIUMAn issue was discovered in Italtel Embrace 1.6.4. The web application inserts cleartext passwords in the HTML source code. An authenticated EPSS 0.4%CVE-2023-31300HIGHAn issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitivEPSS 0.4%CVE-2023-38276MEDIUMIBM Cognos Dashboards information disclosureEPSS 0.4%CVE-2023-38275MEDIUMIBM Cognos Dashboards information disclosureEPSS 0.4%CVE-2022-32906MEDIUMThis issue was addressed with using HTTPS when sending information over the network. This issue is fixed in Apple Music 3.9.10 for Android. EPSS 0.4%CVE-2024-47789HIGHCredential Leakage VulnerabilityEPSS 0.4%CVE-2023-22863MEDIUMIBM Robotic Process Automation information disclosureEPSS 0.4%