Fallos del tipo CWE-319

538 resultados

Transmissão de dados sensíveis em texto plano

A aplicação envia dados críticos (senhas, tokens, informações pessoais) sem criptografia em um canal de comunicação que pode ser interceptado. Um atacante na mesma rede ou posicionado no caminho do tráfego consegue ler esses dados diretamente, comprometendo confidencialidade.

Ejemplo

Um aplicativo mobile que envia credenciais de login via HTTP simples em vez de HTTPS, ou um sistema legado que transmite números de cartão de crédito em texto plano pela rede corporativa. Qualquer um fazendo sniffing de pacotes consegue capturar essas informações.

Cómo mitigar

Use HTTPS/TLS para toda comunicação que envolva dados sensíveis, implemente verificação de certificados válidos no cliente, e nunca transmita senhas ou tokens em parâmetros GET — prefira POST com corpo criptografado. Em APIs, aplique autenticação com tokens seguros e considere criptografia adicional end-to-end para dados ultra-críticos.

CVE-2007-4786MEDIUMCisco Adaptive Security Appliance (ASA) running PIX 7.0 before 7.0.7.1, 7.1 before 7.1.2.61, 7.2 before 7.2.2.34, and 8.0 before 8.0.2.11, wEPSS 0.5%CVE-2020-12036Baxter PrismaFlex all versions, PrisMax all versions prior to 3.x, The affected devices do not implement data-in-transit encryption (e.g., TEPSS 0.5%CVE-2024-28134HIGHPHOENIX CONTACT: MitM attack gains privileges of the current logged in user in CHARX Series EPSS 0.5%CVE-2023-30513HIGHJenkins Kubernetes Plugin 3909.v1f2c633e8590 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log EPSS 0.5%CVE-2023-30602HIGHHitron Technologies Inc. CODA-5310 - Insecure service TelnetEPSS 0.5%CVE-2021-3792MEDIUMSome device communications in some Motorola-branded Binatone Hubble Cameras with backend Hubble services are not encrypted which could lead EPSS 0.5%CVE-2023-3761LOWIntergard SGS Password Change cleartext transmissionEPSS 0.5%CVE-2026-1777HIGHCleartext transmission of sensitive materials in aws/sagemaker-python-sdkEPSS 0.5%CVE-2023-0922MEDIUMThe Samba AD DC administration tool, when operating against a remote LDAP server, will by default send new or reset passwords over a signed-EPSS 0.5%CVE-2025-0784MEDIUMIntelbras InControl Registered User usuario cleartext transmissionEPSS 0.5%CVE-2023-30514HIGHJenkins Azure Key Vault Plugin 187.va_cd5fecd198a_ and earlier does not properly mask (i.e., replace with asterisks) credentials in the builEPSS 0.5%CVE-2021-3473MEDIUMAn internal product security audit of Lenovo XClarity Controller (XCC) discovered that the XCC configuration backup/restore password may be EPSS 0.5%CVE-2018-10634MEDIUMMedtronic MiniMed MMT-500/MMT-503 Remote Controllers Cleartext Transmission of Sensitive InformationEPSS 0.5%CVE-2024-4161HIGHSyslog traffic sent in clear-textEPSS 0.5%CVE-2021-23846HIGHB426 Credential DisclosureEPSS 0.5%CVE-2020-9420MEDIUMThe login password of the web administrative dashboard in Arcadyan Wifi routers VRV9506JAC23 is sent in cleartext, allowing an attacker to sEPSS 0.5%CVE-2024-35060HIGHAn issue in the YAML Python library of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary commands via supplying a crafted YAML fileEPSS 0.5%CVE-2022-43691MEDIUMConcrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 inadvertently disclose server-side sensitive information (secretsEPSS 0.5%CVE-2025-69969CRITICALA lack of authentication and authorization mechanisms in the Bluetooth Low Energy (BLE) communication protocol of SRK Powertech Pvt Ltd PebbEPSS 0.5%CVE-2022-21184MEDIUMAn information disclosure vulnerability exists in the License registration functionality of Bachmann Visutec GmbH Atvise 3.5.4, 3.6 and 3.7.EPSS 0.5%