Fallos del tipo CWE-319

538 resultados

Transmissão de dados sensíveis em texto plano

A aplicação envia dados críticos (senhas, tokens, informações pessoais) sem criptografia em um canal de comunicação que pode ser interceptado. Um atacante na mesma rede ou posicionado no caminho do tráfego consegue ler esses dados diretamente, comprometendo confidencialidade.

Ejemplo

Um aplicativo mobile que envia credenciais de login via HTTP simples em vez de HTTPS, ou um sistema legado que transmite números de cartão de crédito em texto plano pela rede corporativa. Qualquer um fazendo sniffing de pacotes consegue capturar essas informações.

Cómo mitigar

Use HTTPS/TLS para toda comunicação que envolva dados sensíveis, implemente verificação de certificados válidos no cliente, e nunca transmita senhas ou tokens em parâmetros GET — prefira POST com corpo criptografado. Em APIs, aplique autenticação com tokens seguros e considere criptografia adicional end-to-end para dados ultra-críticos.

CVE-2024-5631MEDIUMLongse NVR (Network Video Recorder) model NVR3608PGE2W, as well as products based on this device, are transmitting user's login and passwordEPSS 0.2%CVE-2025-36274HIGHIBM Aspera HTTP Gateway information disclosureEPSS 0.2%CVE-2024-0066MEDIUMJohan Fagerström, member of the AXIS OS Bug Bounty Program, has found that a O3C feature may expose sensitive traffic between the client (AxEPSS 0.2%CVE-2022-2338MEDIUMSofting Secure Integration Server Cleartext Transmission of Sensitive InformationEPSS 0.2%CVE-2025-11492CRITICALHTTP Configuration and Encryption in TransitEPSS 0.2%CVE-2026-32309HIGHCryptomator: Hub unlocking accepts plaintext HTTP and unvalidated endpoint schemesEPSS 0.2%CVE-2025-54156CRITICALSantesoft Sante PACS Server Cleartext Transmission of Sensitive InformationEPSS 0.2%CVE-2021-23896LOWCleartext Transmission of Sensitive Information in McAfee DBSecEPSS 0.2%CVE-2024-45101MEDIUMA privilege escalation vulnerability was discovered when Single Sign On (SSO) is enabled that could allow an attacker to intercept a valid, EPSS 0.2%CVE-2025-36421MEDIUMMultiple vulnerabilities in IBM ControllerEPSS 0.2%CVE-2025-12530MEDIUMVulnerabilities found in Watson Data IntelligenceEPSS 0.2%CVE-2025-36336MEDIUMCleartext Transmission of Sensitive Information in Watson Data IntelligenceEPSS 0.2%CVE-2024-47577LOWInformation Disclosure vulnerability in SAP Commerce CloudEPSS 0.2%CVE-2024-45102MEDIUMA privilege escalation vulnerability was discovered that could allow a valid, authenticated LXCA user to escalate their permissions for a coEPSS 0.2%CVE-2022-0005LOWSensitive information accessible by physical probing of JTAG interface for some Intel(R) Processors with SGX may allow an unprivileged user EPSS 0.2%CVE-2026-2671LOWMendi Neurofeedback Headset Bluetooth Low Energy cleartext transmissionEPSS 0.2%CVE-2026-24060CRITICALAutomated Logic WebCTRL Premium Server Cleartext Transmission of Sensitive InformationEPSS 0.2%CVE-2026-81691HIGHopenssl_encrypt before 1.4.9 Credential Leakage via Unvalidated Server URLsEPSS 0.2%CVE-2026-55857MEDIUMMariaDB Connector/J: Cleartext Transmission of Sensitive Information and Insufficiently Protected CredentialsEPSS 0.2%CVE-2024-35495MEDIUMAn Information Disclosure vulnerability in the Telemetry component in TP-Link Kasa KP125M V1.0.0 and Tapo P125M 1.0.0 Build 220930 Rel.14394EPSS 0.2%