Fallos del tipo CWE-319

536 resultados

Transmissão de dados sensíveis em texto plano

A aplicação envia dados críticos (senhas, tokens, informações pessoais) sem criptografia em um canal de comunicação que pode ser interceptado. Um atacante na mesma rede ou posicionado no caminho do tráfego consegue ler esses dados diretamente, comprometendo confidencialidade.

Ejemplo

Um aplicativo mobile que envia credenciais de login via HTTP simples em vez de HTTPS, ou um sistema legado que transmite números de cartão de crédito em texto plano pela rede corporativa. Qualquer um fazendo sniffing de pacotes consegue capturar essas informações.

Cómo mitigar

Use HTTPS/TLS para toda comunicação que envolva dados sensíveis, implemente verificação de certificados válidos no cliente, e nunca transmita senhas ou tokens em parâmetros GET — prefira POST com corpo criptografado. Em APIs, aplique autenticação com tokens seguros e considere criptografia adicional end-to-end para dados ultra-críticos.

CVE-2026-23564MEDIUMTransmission of Unencrypted Data in Content Distribution ServiceEPSS 0.1%CVE-2026-79782CRITICALrclone before 1.74.4 Security Token Disclosure via HTTPS to HTTP RedirectEPSS 0.1%CVE-2026-38740MEDIUMFoscam VD1 Video Doorbell before V5.3.13_1072 is vulnerable to Cleartext Transmission of Sensitive Information. The device transmits sensitiEPSS 0.1%CVE-2025-10174HIGHImproper Access Control in Pan Software's PanCafe ProEPSS 0.1%CVE-2023-52951MEDIUMA cleartext transmission of sensitive information vulnerability in Synology Note Station Client before 2.2.4-703 allows man-in-the-middle atEPSS 0.1%CVE-2021-39077MEDIUMIBM Security Guardium information disclosureEPSS 0.1%CVE-2022-22457MEDIUMIBM Security Verify Governance, Identity Manager information disclosureEPSS 0.1%CVE-2022-41327HIGHA cleartext transmission of sensitive information vulnerability [CWE-319] in Fortinet FortiOS version 7.2.0 through 7.2.4, 7.0.0 through 7.0EPSS 0.1%CVE-2025-53703HIGHDuraComm DP-10iN-100-MU Cleartext Transmission of Sensitive InformationEPSS 0.1%CVE-2025-10540MEDIUMUnencrypted and Unauthenticated Communication Allows Data Exposure and Manipulation in iMonitor EAMEPSS 0.1%CVE-2023-45321HIGHThe Android Client application, when enrolled with the define method 1 (the user manually inserts the server ip address), use HTTP protocolEPSS 0.1%CVE-2025-66604LOWA vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. The library version could be displayed on the webEPSS 0.1%CVE-2024-8013LOWCSFLE and Queryable Encryption self-lookup may fail to encrypt values in subpipelinesEPSS 0.1%CVE-2026-22080HIGHInsecure Transmission Vulnerability in Tenda Wireless RoutersEPSS 0.1%CVE-2026-22079HIGHCleartext Transmission Vulnerability in Tenda Wireless RoutersEPSS 0.1%CVE-2026-0714HIGHA physical attack vulnerability exists in certain Moxa industrial computers using TPM-backed LUKS full-disk encryption on Moxa Industrial LiEPSS 0.1%CVE-2026-40045MEDIUMOpenClaw < 2026.4.2 - Cleartext Credential Transmission via Unencrypted WebSocket Gateway EndpointsEPSS 0.1%CVE-2023-47745MEDIUMIBM MQ Container information disclosureEPSS 0.1%CVE-2026-25599MEDIUMMissing authentication and clear‑text data transmission affecting Orca heat pumpsEPSS 0.1%CVE-2024-25960HIGHDell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains a cleartext transmission of sensitive information vulnerability. A local lowEPSS 0.1%