Falhas do tipo CWE-300

59 resultados

Ataque Homem no Meio (Man-in-the-Middle)

Fraqueza que permite a um atacante interceptar, ler ou modificar comunicações entre dois pontos (cliente-servidor, serviço-serviço) sem que as partes saibam. Ocorre quando faltam mecanismos de autenticação ou criptografia adequados, deixando a conexão exposta a espionagem e manipulação.

Exemplo

Um app móvel se conecta a um servidor via HTTP simples para sincronizar dados de usuário. Um atacante na mesma rede Wi-Fi pode interceptar as requisições com Wireshark ou ferramentas similares, capturando senhas, tokens ou injetando comandos maliciosos nas respostas antes delas chegarem ao app.

Como mitigar

Use HTTPS/TLS em todas as conexões sensíveis, valide certificados do servidor (nunca ignore avisos de certificado inválido), implemente pinning de certificado em apps móveis críticos e, quando possível, adicione autenticação mútua (cliente valida servidor e vice-versa). Em APIs internas, use VPN ou mTLS.

CVE-2023-38272MEDIUMIBM Cloud Pak System information disclosureEPSS 0.3%CVE-2024-31206HIGHUse of Unencrypted HTTP Request in dectalk-ttsEPSS 0.3%CVE-2021-27768MEDIUMAn SSL certificate host verification vulnerability affects HCL Verse for AndroidEPSS 0.3%CVE-2023-4885MEDIUMMultiple vulnerabilities in Open5GSEPSS 0.3%CVE-2024-36553HIGHForever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h is vulnerable to MITM attack.EPSS 0.3%CVE-2019-19751MEDIUMeasyMINE before 2019-12-05 ships with SSH host keys baked into the installation image, which allows man-in-the-middle attacks and makes idenEPSS 0.3%CVE-2025-63363HIGHA lack of Management Frame Protection in Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1:EPSS 0.3%CVE-2024-27263MEDIUMIBM Sterling B2B Integrator information disclosureEPSS 0.3%CVE-2025-54792CRITICALLocalSend is Vulnerable to Man-in-the-Middle Attacks, Leading to File InterceptionEPSS 0.3%CVE-2024-12602MEDIUMIdentity verification vulnerability in the ParamWatcher module Impact: Successful exploitation of this vulnerability may affect service confEPSS 0.2%CVE-2026-84197CRITICALIn Eclipse Ditto's Node.js JavaScript client, all released versions of @eclipse-ditto/ditto-javascript-client-node from 2.0.0 to 3.9.0 and oEPSS 0.2%CVE-2025-29419HIGHCTFd v3.7.6 was discovered to be vulnerable to a man-in-the-middle attack.EPSS 0.2%CVE-2026-23810MEDIUMCross-BSSID GTK Re-encryption and Traffic InjectionEPSS 0.2%CVE-2026-23811MEDIUMUnauthorized Bi-Directional Traffic Interception via L2/L3 ManipulationEPSS 0.2%CVE-2025-20122HIGHCisco Catalyst SD-WAN Manager Privilege Escalation VulnerabilityEPSS 0.1%CVE-2026-23812MEDIUMSecurity Boundary Bypass via Routing Node ImpersonationEPSS 0.1%CVE-2026-12991HIGHMultiple vulnerabilities in Ghost Robotics' Vision 60EPSS 0.1%CVE-2025-40770HIGHA vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions). The affected application uses a monitorinEPSS 0.1%CVE-2026-76715HIGHUnauthenticated Man-in-the-Middle Attach Leads to Remote Code Execution Vulnerability in HPE Networking Analytics and Location Engine (ALE)EPSS