Fallos del tipo CWE-319

538 resultados

Transmissão de dados sensíveis em texto plano

A aplicação envia dados críticos (senhas, tokens, informações pessoais) sem criptografia em um canal de comunicação que pode ser interceptado. Um atacante na mesma rede ou posicionado no caminho do tráfego consegue ler esses dados diretamente, comprometendo confidencialidade.

Ejemplo

Um aplicativo mobile que envia credenciais de login via HTTP simples em vez de HTTPS, ou um sistema legado que transmite números de cartão de crédito em texto plano pela rede corporativa. Qualquer um fazendo sniffing de pacotes consegue capturar essas informações.

Cómo mitigar

Use HTTPS/TLS para toda comunicação que envolva dados sensíveis, implemente verificação de certificados válidos no cliente, e nunca transmita senhas ou tokens em parâmetros GET — prefira POST com corpo criptografado. Em APIs, aplique autenticação com tokens seguros e considere criptografia adicional end-to-end para dados ultra-críticos.

CVE-2018-0025MEDIUMJunos OS: SRX Series: Credentials exposed when using HTTP and HTTPS Firewall Pass-through User AuthenticationEPSS 1.4%CVE-2020-1749HIGHA flaw was found in the Linux kernel's implementation of some networking protocols in IPsec, such as VXLAN and GENEVE tunnels over IPv6. WheEPSS 1.2%CVE-2023-6248CRITICALData leakage and arbitrary remote code execution in Syrus cloud devicesEPSS 1.2%CVE-2023-34998HIGHAn authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v18.00.0072. A speciaEPSS 1.2%CVE-2023-33730CRITICALPrivilege Escalation in the "GetUserCurrentPwd" function in Microworld Technologies eScan Management Console 14.0.1400.2281 allows any remotEPSS 1.2%CVE-2015-0987CRITICALOmron CX-One CX-Programmer before 9.6, CJ2M PLC devices before 2.1, and CJ2H PLC devices before 1.5 rely on cleartext password transmission,EPSS 1.2%CVE-2024-0056HIGHMicrosoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass VulnerabilityEPSS 1.2%CVE-2022-26077HIGHA cleartext transmission of sensitive information vulnerability exists in the OAS Engine configuration communications functionality of Open EPSS 1.1%CVE-2018-14627MEDIUMThe IIOP OpenJDK Subsystem in WildFly before version 14.0.0 does not honour configuration when SSL transport is required. Servers before thiEPSS 1.1%CVE-2019-6845A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists in Modicon M580, Modicon M340, Modicon Premium , Modicon QuaEPSS 1.1%CVE-2024-48894MEDIUMA cleartext transmission vulnerability exists in the WEBVIEW-M functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted HTTP EPSS 1.1%CVE-2019-18285A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The RMI communication between tEPSS 1.0%CVE-2012-5562HIGHRhn-proxy: rhn-satellite: rhn-proxy: information disclosure via clear-text credential transmission when accessing rhn satelliteEPSS 1.0%CVE-2020-25169Reolink P2P CamerasEPSS 1.0%CVE-2019-6846A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists in Modicon M580, Modicon M340, Modicon BMxCRA and 140CRA modEPSS 1.0%CVE-2020-7003In Moxa ioLogik 2500 series firmware, Version 3.0 or lower, and IOxpress configuration utility, Version 2.3.0 or lower, sensitive informatioEPSS 1.0%CVE-2020-6997In Moxa EDS-G516E Series firmware, Version 5.2 or lower, sensitive information is transmitted over some web applications in cleartext.EPSS 1.0%CVE-2022-33321CRITICALCleartext Transmission of Sensitive Information vulnerability due to the use of Basic Authentication for HTTP connections in Mitsubishi ElecEPSS 1.0%CVE-2020-25190HIGHMOXA NPort IAW5000A-I/O SeriesEPSS 1.0%CVE-2018-5401CRITICALThe Auto-Maskin DCU 210E, RP-210E, and Marine Pro Observer Android App transmit sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actorsEPSS 1.0%