Fallos del tipo CWE-319

538 resultados

Transmissão de dados sensíveis em texto plano

A aplicação envia dados críticos (senhas, tokens, informações pessoais) sem criptografia em um canal de comunicação que pode ser interceptado. Um atacante na mesma rede ou posicionado no caminho do tráfego consegue ler esses dados diretamente, comprometendo confidencialidade.

Ejemplo

Um aplicativo mobile que envia credenciais de login via HTTP simples em vez de HTTPS, ou um sistema legado que transmite números de cartão de crédito em texto plano pela rede corporativa. Qualquer um fazendo sniffing de pacotes consegue capturar essas informações.

Cómo mitigar

Use HTTPS/TLS para toda comunicação que envolva dados sensíveis, implemente verificação de certificados válidos no cliente, e nunca transmita senhas ou tokens em parâmetros GET — prefira POST com corpo criptografado. Em APIs, aplique autenticação com tokens seguros e considere criptografia adicional end-to-end para dados ultra-críticos.

CVE-2018-5471A Cleartext Transmission of Sensitive Information issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, aEPSS 1.0%CVE-2020-12040Sigma Spectrum Infusion System v's6.x (model 35700BAX) and Baxter Spectrum Infusion System Version(s) 8.x (model 35700BAX2) at the applicatiEPSS 0.9%CVE-2020-12008Baxter ExactaMix EM 2400 Versions 1.10, 1.11 and ExactaMix EM1200 Versions 1.1, 1.2 systems use cleartext messages to communicate order infoEPSS 0.9%CVE-2023-2754HIGHPlaintext transmission of DNS requests in Windows 1.1.1.1 WARP clientEPSS 0.9%CVE-2020-7488HIGHA CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists which could leak sensitive information transmitted between tEPSS 0.9%CVE-2023-23915MEDIUMA cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality to behave incorrEPSS 0.9%CVE-2023-23914CRITICALA cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality fail when multipEPSS 0.9%CVE-2024-21406HIGHWindows Printing Service Spoofing VulnerabilityEPSS 0.9%CVE-2018-8929HIGHImproper restriction of communication channel to intended endpoints vulnerability in HTTP daemon in Synology SSL VPN Client before 1.2.4-022EPSS 0.8%CVE-2018-19944Cleartext Transmission of Sensitive Information in SNMPEPSS 0.8%CVE-2018-5402CRITICALThe Auto-Maskin DCU 210E, RP-210E, and Marine Pro Observer Android App use an embedded webserver that uses unencrypted plaintext for the transmission of the administrator PINEPSS 0.8%CVE-2018-8855CRITICALEchelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versionsEPSS 0.8%CVE-2019-18231Advantech Spectre RT ERT351 Versions 5.1.3 and prior logins and passwords are transmitted in clear text form, which may allow an attacker toEPSS 0.8%CVE-2021-39342MEDIUMCredova_Financial <= 1.4.8 Sensitive Information DisclosureEPSS 0.8%CVE-2021-26560CRITICALCleartext transmission of sensitive information vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 6.2.3-25426EPSS 0.8%CVE-2020-10624ControlEdge PLC (R130.2, R140, R150, and R151) and RTU (R101, R110, R140, R150, and R151) exposes a session token on the network.EPSS 0.7%CVE-2020-25155The affected product transmits unencrypted sensitive information, which may allow an attacker to access this information on the NIO 50 (all EPSS 0.7%CVE-2020-10628ControlEdge PLC (R130.2, R140, R150, and R151) and RTU (R101, R110, R140, R150, and R151) exposes unencrypted passwords on the network.EPSS 0.7%CVE-2022-29874HIGHA vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices do not encrypt web traffic with clients but communicaEPSS 0.7%CVE-2021-26565HIGHCleartext transmission of sensitive information vulnerability in synorelayd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allowEPSS 0.7%