Fallos del tipo CWE-319

538 resultados

Transmissão de dados sensíveis em texto plano

A aplicação envia dados críticos (senhas, tokens, informações pessoais) sem criptografia em um canal de comunicação que pode ser interceptado. Um atacante na mesma rede ou posicionado no caminho do tráfego consegue ler esses dados diretamente, comprometendo confidencialidade.

Ejemplo

Um aplicativo mobile que envia credenciais de login via HTTP simples em vez de HTTPS, ou um sistema legado que transmite números de cartão de crédito em texto plano pela rede corporativa. Qualquer um fazendo sniffing de pacotes consegue capturar essas informações.

Cómo mitigar

Use HTTPS/TLS para toda comunicação que envolva dados sensíveis, implemente verificação de certificados válidos no cliente, e nunca transmita senhas ou tokens em parâmetros GET — prefira POST com corpo criptografado. Em APIs, aplique autenticação com tokens seguros e considere criptografia adicional end-to-end para dados ultra-críticos.

CVE-2021-32966LOWPhilips Interoperability Solution XDS - Clear Text Transmission of Sensitive InformationEPSS 0.5%CVE-2019-14942MEDIUMAn issue was discovered in GitLab Community and Enterprise Edition before 11.11.8, 12 before 12.0.6, and 12.1 before 12.1.6. Cookies for GitEPSS 0.5%CVE-2023-23841HIGHSolarWinds Serv-U Exposure of Sensitive Information VulnerabilityEPSS 0.5%CVE-2024-35059HIGHAn issue in the Pickle Python library of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary commands.EPSS 0.5%CVE-2020-12048Phoenix Hemodialysis Delivery System SW 3.36 and 3.40, The Phoenix Hemodialysis device does not support data-in-transit encryption (e.g., TLEPSS 0.5%CVE-2025-32880CRITICALAn issue was discovered on COROS PACE 3 devices through 3.0808.0. It implements a function to connect the watch to a WLAN. With WLAN access,EPSS 0.5%CVE-2022-40939MEDIUMIn certain Secustation products the administrator account password can be read. This affects V2.5.5.3116-S50-SMA-B20171107A, V2.3.4.1301-M20EPSS 0.4%CVE-2022-44411HIGHWeb Based Quiz System v1.0 transmits user passwords in plaintext during the authentication process, allowing attackers to obtain users' passEPSS 0.4%CVE-2023-25016HIGHCouchbase Server before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2 exposes Sensitive Information to an Unauthorized Actor.EPSS 0.4%CVE-2023-30354CRITICALShenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 does not defend against physical access to U-Boot via the UART: the Wi-Fi passwoEPSS 0.4%CVE-2023-53875HIGHGOM Player 2.3.90.5360 Remote Code Execution via Insecure IE ComponentEPSS 0.4%CVE-2025-27594HIGHUnencrypted transmission of password hashEPSS 0.4%CVE-2024-35058HIGHAn issue in the API wait function of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary code via supplying a crafted string.EPSS 0.4%CVE-2023-28348HIGHAn issue was discovered in Faronics Insight 10.0.19045 on Windows. A suitably positioned attacker could perform a man-in-the-middle attack oEPSS 0.4%CVE-2026-49486HIGHApache Airflow FTP provider: FTP Provider does not protect FTPS data channel (missing PROT_P)EPSS 0.4%CVE-2024-50634HIGHA vulnerability in a weak JWT token in Watcharr v1.43.0 and below allows attackers to perform privilege escalation using a crafted JWT tokenEPSS 0.4%CVE-2022-39287HIGHPlaintext transmission of CSRF tokens in tiny-csrfEPSS 0.4%CVE-2024-38891CRITICALAn issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker tEPSS 0.4%CVE-2022-39339MEDIUMCleartext Transmission of Sensitive Information in user_oidcEPSS 0.4%CVE-2024-35057HIGHAn issue in NASA AIT-Core v2.5.2 allows attackers to execute arbitrary code via a crafted packet.EPSS 0.4%