Falhas do tipo CWE-319

538 resultados

Transmissão de dados sensíveis em texto plano

A aplicação envia informações sensíveis (senhas, tokens, dados pessoais) sem criptografia em um canal de comunicação que pode ser interceptado. Um atacante na rede consegue capturar esses dados facilmente com ferramentas simples como packet sniffers, comprometendo a confidencialidade.

Exemplo

Uma API envia credenciais de usuário via HTTP simples em vez de HTTPS, ou um sistema transmite tokens de autenticação em requisições GET visíveis em logs de proxy. Um atacante na mesma rede Wi-Fi captura os pacotes e acessa as credenciais diretamente.

Como mitigar

Use HTTPS/TLS em todas as comunicações envolvendo dados sensíveis, implemente criptografia end-to-end quando necessário, e nunca transmita credenciais em parâmetros de URL. Valide certificados SSL/TLS do lado cliente e revise protocolos legados (FTP, Telnet) para alternativas seguras.

CVE-2022-46680HIGH A CWE-319: Cleartext transmission of sensitive information vulnerability exists that could cause disclosure of sensitive information, deniaEPSS 0.4%CVE-2023-46447MEDIUMThe POPS! Rebel application 5.0 for Android, in POPS! Rebel Bluetooth Glucose Monitoring System, sends unencrypted glucose measurements overEPSS 0.4%CVE-2024-1657HIGHPlatform: insecure websocket used when interacting with eda serverEPSS 0.4%CVE-2023-51741HIGHCleartext Submission of Password vulnerability in Skyworth RouterEPSS 0.4%CVE-2019-5635MEDIUMHickory Smart Lock Cleartext PasswordEPSS 0.4%CVE-2023-51740HIGHCleartext Submission of Password vulnerability in Skyworth RouterEPSS 0.4%CVE-2022-27619MEDIUMCleartext transmission of sensitive information vulnerability in authentication management in Synology Note Station Client before 2.2.2-609 EPSS 0.4%CVE-2023-50614HIGHAn issue discovereed in EBYTE E880-IR01-V1.1 allows an attacker to obtain sensitive information via crafted POST request to /cgi-bin/luci.EPSS 0.4%CVE-2021-3494A smart proxy that provides a restful API to various sub-systems of the Foreman is affected by the flaw which can cause a Man-in-the-Middle EPSS 0.4%CVE-2025-8741MEDIUMmacrozheng mall login cleartext transmissionEPSS 0.4%CVE-2023-22806HIGHCVE-2023-22806EPSS 0.4%CVE-2024-0220HIGHB&R products use insufficient communication encryptionEPSS 0.4%CVE-2022-22758HIGHWhen clicking on a tel: link, USSD codes, specified after a <code>\*</code> character, would be included in the phone number. On certain phoEPSS 0.4%CVE-2024-31840MEDIUMAn issue was discovered in Italtel Embrace 1.6.4. The web application inserts cleartext passwords in the HTML source code. An authenticated EPSS 0.4%CVE-2023-31300HIGHAn issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitivEPSS 0.4%CVE-2023-38276MEDIUMIBM Cognos Dashboards information disclosureEPSS 0.4%CVE-2023-38275MEDIUMIBM Cognos Dashboards information disclosureEPSS 0.4%CVE-2022-32906MEDIUMThis issue was addressed with using HTTPS when sending information over the network. This issue is fixed in Apple Music 3.9.10 for Android. EPSS 0.4%CVE-2024-47789HIGHCredential Leakage VulnerabilityEPSS 0.4%CVE-2023-22863MEDIUMIBM Robotic Process Automation information disclosureEPSS 0.4%