Fallos del tipo CWE-319

536 resultados

Transmissão de dados sensíveis em texto plano

A aplicação envia dados críticos (senhas, tokens, informações pessoais) sem criptografia em um canal de comunicação que pode ser interceptado. Um atacante na mesma rede ou posicionado no caminho do tráfego consegue ler esses dados diretamente, comprometendo confidencialidade.

Ejemplo

Um aplicativo mobile que envia credenciais de login via HTTP simples em vez de HTTPS, ou um sistema legado que transmite números de cartão de crédito em texto plano pela rede corporativa. Qualquer um fazendo sniffing de pacotes consegue capturar essas informações.

Cómo mitigar

Use HTTPS/TLS para toda comunicação que envolva dados sensíveis, implemente verificação de certificados válidos no cliente, e nunca transmita senhas ou tokens em parâmetros GET — prefira POST com corpo criptografado. Em APIs, aplique autenticação com tokens seguros e considere criptografia adicional end-to-end para dados ultra-críticos.

CVE-2026-21742MEDIUMA cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 throughEPSS 0.1%CVE-2024-28169MEDIUMCleartext transmission of sensitive information for some BigDL software maintained by Intel(R) before version 2.5.0 may allow an authenticatEPSS 0.1%CVE-2026-55568MEDIUMGuzzle: Silent HTTPS-Proxy Downgrade to CleartextEPSS 0.1%CVE-2025-54818HIGHCognex In-Sight Explorer and In-Sight Camera Firmware Cleartext Transmission of Sensitive InformationEPSS 0.1%CVE-2026-36610MEDIUMMercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 transmits DDNS credentials over plaintext HTTP with only Base64 encoding. The firmwEPSS 0.1%CVE-2026-73743LOWUnauthenticated Information Disclosure Leading to Data Exposure in HPE Networking Fabric ComposerEPSS 0.1%CVE-2025-0252LOWHCL IEM is affected by a password in cleartext vulnerabilityEPSS 0.1%CVE-2026-32838HIGHEdimax GS-5008PL <= 1.00.54 Transmits Credentials Over Cleartext HTTPEPSS 0.1%CVE-2026-73174HIGHNozomi Networks Labs identified a CWE-319: Cleartext Transmission of Sensitive Information vulnerability in the edgserver management protocoEPSS 0.1%CVE-2025-0432MEDIUMHMS Networks Ewon Flexy 202 Cleartext Transmission of Sensitive InformationEPSS 0.1%CVE-2023-30565LOW CQI Data Sniffing EPSS 0.1%CVE-2025-43704MEDIUMArctera/Veritas Data Insight before 7.1.2 can send cleartext credentials when configured to use HTTP Basic Authentication to a Dell Isilon OEPSS 0.1%CVE-2025-32793MEDIUMCilium packets from terminating endpoints may not be encrypted in Wireguard-enabled clustersEPSS 0.1%CVE-2025-47698HIGHAn adjacent attacker without authentication can exploit this vulnerability to retrieve a set of user-privileged credentials. These credentiaEPSS 0.1%CVE-2025-27903MEDIUMMultiple vulnerabilities in IBM Java SDK affecting Db2 Recovery Expert for Linux, Unix and WindowsEPSS 0.1%CVE-2026-8874HIGHCVE-2026-8874EPSS 0.1%CVE-2021-20335MEDIUMSSL may be unexpectedly disabled during upgrade of multiple-server MongoDB Ops ManagerEPSS 0.1%CVE-2024-9834CRITICALImproper data protection on Life2000 ventilator serial interfaceEPSS 0.1%CVE-2026-54586MEDIUMmport permits repository and package mirror fetches over insecure transportEPSS 0.1%CVE-2026-20294MEDIUMCisco Catalyst SD-WAN Manager Information Disclosure VulnerabilityEPSS 0.1%