Fallos del tipo CWE-319

536 resultados

Transmissão de dados sensíveis em texto plano

A aplicação envia dados críticos (senhas, tokens, informações pessoais) sem criptografia em um canal de comunicação que pode ser interceptado. Um atacante na mesma rede ou posicionado no caminho do tráfego consegue ler esses dados diretamente, comprometendo confidencialidade.

Ejemplo

Um aplicativo mobile que envia credenciais de login via HTTP simples em vez de HTTPS, ou um sistema legado que transmite números de cartão de crédito em texto plano pela rede corporativa. Qualquer um fazendo sniffing de pacotes consegue capturar essas informações.

Cómo mitigar

Use HTTPS/TLS para toda comunicação que envolva dados sensíveis, implemente verificação de certificados válidos no cliente, e nunca transmita senhas ou tokens em parâmetros GET — prefira POST com corpo criptografado. Em APIs, aplique autenticação com tokens seguros e considere criptografia adicional end-to-end para dados ultra-críticos.

CVE-2025-31972MEDIUMHCL BigFix Service Management (SM) is affected by a Sensitive Information Exposure vulnerabilityEPSS 0.1%CVE-2026-41281MEDIUMAndroid App "あんしんフィルター for au" provided by KDDI CORPORATION contains Cleartext Transmission of Sensitive Information (CWE-319) vulnerabilityEPSS 0.1%CVE-2024-45838LOWgoTenna Pro ATAK Plugin Cleartext Transmission of Sensitive InformationEPSS 0.1%CVE-2025-24849HIGHDario Health USB-C Blood Glucose Monitoring System Starter Kit Android Application Cleartext Transmission of Sensitive InformationEPSS 0.1%CVE-2026-32683MEDIUMSome EZVIZ products utilize older versions of cloud feature modules with legacy API interfaces, which pose a data transmission risk. AttackeEPSS 0.1%CVE-2025-59852LOWHCL DFXAnalytics is affected by an Insufficient Transport Layer Protection vulnerabilityEPSS 0.1%CVE-2025-31981MEDIUMHCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryptionEPSS 0.1%CVE-2026-6066HIGHUnencrypted Client‑Server Communication in ConnectWise Automate™ Solution CenterEPSS 0.1%CVE-2025-62311MEDIUMHCL AION is affected by a vulnerability where backend service details may be transmitted over insecure HTTP channels.EPSS 0.1%CVE-2026-84381HIGHHTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxiesEPSS 0.1%CVE-2025-52586HIGHEG4 Electronics EG4 Inverters Cleartext Transmission of Sensitive InformationEPSS 0.1%CVE-2026-85628HIGHCleartext Transmission of Sensitive Information in the Pairing Process vulnerabilityEPSS 0.1%CVE-2024-43766MEDIUMIn multiple functions of btm_ble_sec.cc, there is a possible unencrypted communication due to Invalid error handling. This could lead to remEPSS 0.1%CVE-2026-81330HIGHSoftish C6 Ear Camera and EarVision Android Application Cleartext transmission of sensitive informationEPSS 0.1%CVE-2026-19854MEDIUMCVE-2026-19854 CVE RecordEPSS 0.1%CVE-2025-62310MEDIUMHCL AION is affected by a vulnerability where encryption is not enforced for certain data transmissions or operationsEPSS 0.0%