Fallos del tipo CWE-319

536 resultados

Transmissão de dados sensíveis em texto plano

A aplicação envia dados críticos (senhas, tokens, informações pessoais) sem criptografia em um canal de comunicação que pode ser interceptado. Um atacante na mesma rede ou posicionado no caminho do tráfego consegue ler esses dados diretamente, comprometendo confidencialidade.

Ejemplo

Um aplicativo mobile que envia credenciais de login via HTTP simples em vez de HTTPS, ou um sistema legado que transmite números de cartão de crédito em texto plano pela rede corporativa. Qualquer um fazendo sniffing de pacotes consegue capturar essas informações.

Cómo mitigar

Use HTTPS/TLS para toda comunicação que envolva dados sensíveis, implemente verificação de certificados válidos no cliente, e nunca transmita senhas ou tokens em parâmetros GET — prefira POST com corpo criptografado. Em APIs, aplique autenticação com tokens seguros e considere criptografia adicional end-to-end para dados ultra-críticos.

CVE-2026-25599MEDIUMMissing authentication and clear‑text data transmission affecting Orca heat pumpsEPSS 0.1%CVE-2024-25960HIGHDell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains a cleartext transmission of sensitive information vulnerability. A local lowEPSS 0.1%CVE-2025-2818MEDIUMA vulnerability was reported in version 1.0 of the Bluetooth Transmission Alliance protocol adopted by Motorola Smart Connect Android ApplicEPSS 0.1%CVE-2025-6180HIGHAuthentication HijackEPSS 0.1%CVE-2025-40583MEDIUMA vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V2.1 HF0 with SINEMA Remote Connect Edge ClientEPSS 0.1%CVE-2026-79779MEDIUMrclone before v1.75.0 WebDAV Credential Exposure via HTTPS-to-HTTP RedirectEPSS 0.1%CVE-2023-42144MEDIUMCleartext Transmission during initial setup in Shelly TRV 20220811-15234 v.2.1.8 allows a local attacker to obtain the Wi-Fi password.EPSS 0.1%CVE-2025-22493MEDIUMImproper cookie attributes in Foreseer Reporting Software (FRS)EPSS 0.1%CVE-2023-23371MEDIUMQVPN Device ClientEPSS 0.1%CVE-2025-63292LOWFreebox v5 HD (firmware = 1.7.20), Freebox v5 Crystal (firmware = 1.7.20), Freebox v6 Révolution r1–r3 (firmware = 4.7.x), Freebox Mini 4K (EPSS 0.1%CVE-2026-33472MEDIUMCryptomator Hub OAuth token exchange HTTP downgrade via getAuthority() scheme confusion (CVE-2026-32303 bypass)EPSS 0.1%CVE-2026-79588MEDIUMU-speed WIFI4 N300 T1 Pro v1.0.0 is vulnerable to Cleartext transmission of administration credentials over HTTP.EPSS 0.1%CVE-2025-65855MEDIUMThe OTA firmware update mechanism in Netun Solutions HelpFlash IoT (firmware v18_178_221102_ASCII_PRO_1R5_50) uses hard-coded WiFi credentiaEPSS 0.1%CVE-2026-9741HIGHClient side encryption fails to encrypt values in a $vectorSearchEPSS 0.1%CVE-2025-13454MEDIUMA potential vulnerability was reported in ThinkPlus configuration software that could allow a local authenticated user to gain access to senEPSS 0.1%CVE-2026-20801MEDIUMCleartext Transmission of Sensitive Information (CWE-319) in a component used in the Gallagher Hanwha VMS and Gallagher NxWitness VMS integrEPSS 0.1%CVE-2026-10584HIGHHTTPS Fallback to HTTP in Graph ExplorerEPSS 0.1%CVE-2025-53861LOWAap: sensitive cookie(s) set without security flagsEPSS 0.1%CVE-2026-34126HIGHBluetooth Communication Uses Unencrypted Transmission During Initial Setup on TP-Link's Tapo L535E, P300 and D100CEPSS 0.1%CVE-2024-47124LOWCleartext Transmission of Sensitive Information in goTenna ProEPSS 0.1%