Fallos del tipo CWE-319

539 resultados

Transmissão de dados sensíveis em texto plano

A aplicação envia dados críticos (senhas, tokens, informações pessoais) sem criptografia em um canal de comunicação que pode ser interceptado. Um atacante na mesma rede ou posicionado no caminho do tráfego consegue ler esses dados diretamente, comprometendo confidencialidade.

Ejemplo

Um aplicativo mobile que envia credenciais de login via HTTP simples em vez de HTTPS, ou um sistema legado que transmite números de cartão de crédito em texto plano pela rede corporativa. Qualquer um fazendo sniffing de pacotes consegue capturar essas informações.

Cómo mitigar

Use HTTPS/TLS para toda comunicação que envolva dados sensíveis, implemente verificação de certificados válidos no cliente, e nunca transmita senhas ou tokens em parâmetros GET — prefira POST com corpo criptografado. Em APIs, aplique autenticação com tokens seguros e considere criptografia adicional end-to-end para dados ultra-críticos.

CVE-2024-9620MEDIUMEvent-driven automation in ansible automation platform (aap): ansible event-driven automation (eda) lacks encryptionEPSS 0.2%CVE-2025-32884MEDIUMAn issue was discovered on goTenna Mesh devices with app 5.5.3 and firmware 1.1.12. By default, a GID is the user's phone number unless theyEPSS 0.2%CVE-2025-32881MEDIUMAn issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. By default, the GID is the user's phone number unless theyEPSS 0.2%CVE-2023-0864HIGHConfiguration data is exchanged in plaintext and could be available to a nearby attacker if present during configuration or usage of the device via Bluetooth Low Energy (BLE).EPSS 0.2%CVE-2025-62330MEDIUMHCL DevOps Deploy is susceptible to a cleartext transmission of sensitive informationEPSS 0.2%CVE-2026-18536HIGHData::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTPEPSS 0.2%CVE-2024-36558HIGHForever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h suffers from Cleartext Transmission of Sensitive InformatioEPSS 0.2%CVE-2024-28786MEDIUMIBM QRadar SIEM information disclosureEPSS 0.2%CVE-2023-43124MEDIUMBIG-IP APM Clients TunnelCrack vulnerabilityEPSS 0.2%CVE-2024-40595MEDIUMAn authentication-bypass issue in the RDP component of One Identity Safeguard for Privileged Sessions (SPS) On Premise before 7.5.1 (and LTSEPSS 0.2%CVE-2020-3442MEDIUMDuoConnect SSH Connection VulnerabilityEPSS 0.2%CVE-2026-77131MEDIUMCleartext Transmission of Sensitive Information in extension "SYSSY - TYPO3 Monitoring & Security Checks" (syssy)EPSS 0.2%CVE-2024-41927MEDIUMCleartext transmission of sensitive information vulnerability exists in multiple IDEC PLCs. If an attacker sends a specific command to PLC'sEPSS 0.2%CVE-2025-43013MEDIUMIn JetBrains Toolbox App before 2.6 unencrypted credential transmission during SSH authentication was possibleEPSS 0.2%CVE-2026-55860MEDIUMMariaDB Connector/R2DBC: Cleartext password disclosure to a man-in-the-middle server (clear-text auth plugins not gated on a secure transport)EPSS 0.2%CVE-2026-20115MEDIUMA vulnerability in Cisco IOS XE Software for Cisco Meraki could allow a remote, unauthenticated attacker to view confidential device informaEPSS 0.2%CVE-2024-0098MEDIUMCVEEPSS 0.2%CVE-2026-86689HIGHCleartext Transmission of Sensitive Information in Bransys ELDEPSS 0.1%CVE-2026-29988HIGHA cleartext transmission of sensitive information vulnerability in the NFC interface of multiple Milesight IoT device models running affecteEPSS 0.1%CVE-2026-7666LOWPotential unencrypted email transmission via STARTTLS in the SMTP backendEPSS 0.1%