Fallos del tipo CWE-319

538 resultados

Transmissão de dados sensíveis em texto plano

A aplicação envia dados críticos (senhas, tokens, informações pessoais) sem criptografia em um canal de comunicação que pode ser interceptado. Um atacante na mesma rede ou posicionado no caminho do tráfego consegue ler esses dados diretamente, comprometendo confidencialidade.

Ejemplo

Um aplicativo mobile que envia credenciais de login via HTTP simples em vez de HTTPS, ou um sistema legado que transmite números de cartão de crédito em texto plano pela rede corporativa. Qualquer um fazendo sniffing de pacotes consegue capturar essas informações.

Cómo mitigar

Use HTTPS/TLS para toda comunicação que envolva dados sensíveis, implemente verificação de certificados válidos no cliente, e nunca transmita senhas ou tokens em parâmetros GET — prefira POST com corpo criptografado. Em APIs, aplique autenticação com tokens seguros e considere criptografia adicional end-to-end para dados ultra-críticos.

CVE-2025-8205MEDIUMComodo Dragon IP DNS Leakage Detector cleartext transmissionEPSS 0.4%CVE-2023-32290HIGHThe myMail app through 14.30 for iOS sends cleartext credentials in a situation where STARTTLS is expected by a server.EPSS 0.4%CVE-2024-27163MEDIUMLeak of admin password and passwordsEPSS 0.4%CVE-2003-5002LOWISS BlackICE PC Protection Update cleartext transmissionEPSS 0.4%CVE-2022-41636CRITICALCommunication traffic involving "Ethernet Q Commands" service of Haas Controller version 100.20.000.1110 is transmitted in cleartext. This aEPSS 0.4%CVE-2026-15806MEDIUM`HTTPPasswordMgr` can send saved HTTPS credentials via HTTP because of incorrect scheme matchingEPSS 0.4%CVE-2022-22385MEDIUMIBM Security Verify Privilege information disclosureEPSS 0.4%CVE-2023-29680MEDIUMCleartext Transmission in set-cookie:ecos_pw: Tenda N301 v6.0, Firmware v12.02.01.61_multi allows an authenticated attacker on the LAN or WLEPSS 0.4%CVE-2023-29681MEDIUMCleartext Transmission in cookie:ecos_pw: in Tenda N301 v6.0, firmware v12.03.01.06_pt allows an authenticated attacker on the LAN or WLAN tEPSS 0.4%CVE-2023-30515HIGHJenkins Thycotic DevOps Secrets Vault Plugin 1.0.0 and earlier does not properly mask (i.e., replace with asterisks) credentials in the builEPSS 0.4%CVE-2023-5461LOWDelta Electronics WPLSoft Modbus cleartext transmissionEPSS 0.4%CVE-2021-21387HIGHPartial secret key disclosure, improper safety number calculation, & inadequate encryption strengthEPSS 0.4%CVE-2024-6515HIGHunauthorized file accessEPSS 0.4%CVE-2022-3929HIGHCommunication between the client and server partially using CORBA over TCP/IPEPSS 0.4%CVE-2022-21951MEDIUMRancher: Weave CNI password is not set if RKE template is used with CNI value overriddenEPSS 0.4%CVE-2020-4497MEDIUMIBM Spectrum Protect Plus information disclosureEPSS 0.4%CVE-2023-0053HIGHSAUTER Controls Nova 200–220 Series Cleartext Transmission of Sensitive InformationEPSS 0.4%CVE-2023-31193HIGH Snap One OvrC Pro versions prior to 7.3 use HTTP connections when downloading a program from their servers. Because they do notEPSS 0.4%CVE-2022-45483MEDIUMLazy Mouse allows an attacker (in a man in the middle position between the server and a connected device) to see all data (including keypresEPSS 0.4%CVE-2022-45480MEDIUMPC Keyboard WiFi & Bluetooth allows an attacker (in a man-in-the-middle position between the server and a connected device) to see all data EPSS 0.4%