Fallos del tipo CWE-319

538 resultados

Transmissão de dados sensíveis em texto plano

A aplicação envia dados críticos (senhas, tokens, informações pessoais) sem criptografia em um canal de comunicação que pode ser interceptado. Um atacante na mesma rede ou posicionado no caminho do tráfego consegue ler esses dados diretamente, comprometendo confidencialidade.

Ejemplo

Um aplicativo mobile que envia credenciais de login via HTTP simples em vez de HTTPS, ou um sistema legado que transmite números de cartão de crédito em texto plano pela rede corporativa. Qualquer um fazendo sniffing de pacotes consegue capturar essas informações.

Cómo mitigar

Use HTTPS/TLS para toda comunicação que envolva dados sensíveis, implemente verificação de certificados válidos no cliente, e nunca transmita senhas ou tokens em parâmetros GET — prefira POST com corpo criptografado. Em APIs, aplique autenticação com tokens seguros e considere criptografia adicional end-to-end para dados ultra-críticos.

CVE-2026-19683MEDIUMUnencrypted Credential Transmission in Omada Gateway Dynamic DNS Authentication in Omada GatewaysEPSS 0.3%CVE-2026-91988CRITICALatomic-agents-stack before 1.1.0 Remote Code Execution via HTTP MCPEPSS 0.3%CVE-2026-31923HIGHApache APISIX: Openid-connect `tls_verify` field is disabled by defaultEPSS 0.3%CVE-2024-25650MEDIUMInsecure key exchange between Delinea PAM Secret Server 11.4 and the Distributed Engine 8.4.3 allows a PAM administrator to obtain the SymmeEPSS 0.3%CVE-2022-30312MEDIUMThe Trend Controls IC protocol through 2022-05-06 allows Cleartext Transmission of Sensitive Information. According to FSCT-2022-0050, thereEPSS 0.3%CVE-2023-34829MEDIUMIncorrect access control in TP-Link Tapo before v3.1.315 allows attackers to access user credentials in plaintext.EPSS 0.2%CVE-2024-43187MEDIUMIBM Security Verify Access information disclosureEPSS 0.2%CVE-2025-1060HIGHCWE-319: Cleartext Transmission of Sensitive Information vulnerability exists that could result in the exposure of data when network trafficEPSS 0.2%CVE-2024-37183MEDIUMWestermo L210-F2G Lynx Cleartext Transmission of Sensitive InformationEPSS 0.2%CVE-2026-24455HIGHJinan USR IOT Technology Limited (PUSR) USR-W610 Cleartext Transmission of Sensitive InformationEPSS 0.2%CVE-2024-49820LOWIBM Security Guardium Key Lifecycle Manager information disclosureEPSS 0.2%CVE-2023-34441MEDIUMBaker Hughes Bently Nevada 3500 System Cleartext Transmission of Sensitive InformationEPSS 0.2%CVE-2025-5087MEDIUMCleartext Transmission of Sensitive Information in Kaleris Navis N4EPSS 0.2%CVE-2026-45180HIGHCatalyst::Plugin::Statsd versions through 0.10.0 for Perl may leak session idsEPSS 0.2%CVE-2026-45432HIGHCleartext Transmission of Credentials Vulnerability in GX Earth ONT ModelsEPSS 0.2%CVE-2023-41088MEDIUMCleartext Transmission of Sensitive Information in DEXMA DEXGateEPSS 0.2%CVE-2024-26155MEDIUMETIC Telecom Remote Access Server (RAS) Cleartext Transmission of Sensitive InformationEPSS 0.2%CVE-2023-6094MEDIUMOnCell G3150A-LTE Series: Web Server Transmits Cleartext CredentialsEPSS 0.2%CVE-2026-69658CRITICALEbyte NA111-M Cleartext Transmission of Sensitive InformationEPSS 0.2%CVE-2026-31924MEDIUMApache APISIX: Plugin tencent-cloud-cls log export uses plaintext HTTPEPSS 0.2%