Fallos del tipo CWE-319

536 resultados

Transmissão de dados sensíveis em texto plano

A aplicação envia dados críticos (senhas, tokens, informações pessoais) sem criptografia em um canal de comunicação que pode ser interceptado. Um atacante na mesma rede ou posicionado no caminho do tráfego consegue ler esses dados diretamente, comprometendo confidencialidade.

Ejemplo

Um aplicativo mobile que envia credenciais de login via HTTP simples em vez de HTTPS, ou um sistema legado que transmite números de cartão de crédito em texto plano pela rede corporativa. Qualquer um fazendo sniffing de pacotes consegue capturar essas informações.

Cómo mitigar

Use HTTPS/TLS para toda comunicação que envolva dados sensíveis, implemente verificação de certificados válidos no cliente, e nunca transmita senhas ou tokens em parâmetros GET — prefira POST com corpo criptografado. Em APIs, aplique autenticação com tokens seguros e considere criptografia adicional end-to-end para dados ultra-críticos.

CVE-2022-2003HIGHAutomationDirect DirectLOGIC with Serial Communication Cleartext TransmissionEPSS 0.7%CVE-2021-27251HIGHThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR Nighthawk R7800. AuthentEPSS 0.7%CVE-2021-3774HIGHMeross MSS550X Missing Encryption of Sensitive DataEPSS 0.7%CVE-2026-23662HIGHAzure IoT Explorer Information Disclosure VulnerabilityEPSS 0.7%CVE-2020-10281HIGHRVD#3315: Cleartext transmission of sensitive information in MAVLink protocol version 1.0 and 2.0EPSS 0.7%CVE-2020-5426HIGHScheduler for TAS can transmit privileged UAA token in plaintextEPSS 0.7%CVE-2026-23661HIGHAzure IoT Explorer Information Disclosure VulnerabilityEPSS 0.7%CVE-2025-34271HIGHNagios Log Server < 2024R2.0.2 Cluster Manager Credential Requests Sent Over PlaintextEPSS 0.7%CVE-2022-0162HIGHVulnerability in TP-LinK TL-WR841N wireless routerEPSS 0.7%CVE-2021-26564HIGHCleartext transmission of sensitive information vulnerability in synorelayd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allowEPSS 0.7%CVE-2021-4161CRITICALICSA-21-357-01 Moxa MGate Protocol GatewaysEPSS 0.7%CVE-2026-24212HIGHNVIDIA Isaac Launchable for Linux contains a vulnerability where sensitive information is transmitted in clear text. A successful exploit ofEPSS 0.7%CVE-2021-32982HIGHAutomation Direct CLICK PLC CPU Modules Cleartext Transmission of Sensitive InformationEPSS 0.7%CVE-2026-3182MEDIUMSensitive Data ExposureEPSS 0.6%CVE-2022-40693MEDIUMA cleartext transmission vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. AEPSS 0.6%CVE-2021-33022HIGHPhilips Vue PACS Cleartext Transmission of Sensitive InformationEPSS 0.6%CVE-2021-32934CRITICALThroughTek P2P SDK - Cleartext Transmission of Sensitive InformationEPSS 0.6%CVE-2020-2013HIGHPAN-OS: Panorama context switch session cookie disclosureEPSS 0.6%CVE-2020-15785A vulnerability has been identified in Siveillance Video Client (All versions). In environments where Windows NTLM authentication is enabledEPSS 0.6%CVE-2022-43724CRITICALA vulnerability has been identified in SICAM PAS/PQS (All versions < V7.0). Affected software transmits the database credentials for the inbEPSS 0.6%