Falhas do tipo CWE-319

538 resultados

Transmissão de dados sensíveis em texto plano

A aplicação envia informações sensíveis (senhas, tokens, dados pessoais) sem criptografia em um canal de comunicação que pode ser interceptado. Um atacante na rede consegue capturar esses dados facilmente com ferramentas simples como packet sniffers, comprometendo a confidencialidade.

Exemplo

Uma API envia credenciais de usuário via HTTP simples em vez de HTTPS, ou um sistema transmite tokens de autenticação em requisições GET visíveis em logs de proxy. Um atacante na mesma rede Wi-Fi captura os pacotes e acessa as credenciais diretamente.

Como mitigar

Use HTTPS/TLS em todas as comunicações envolvendo dados sensíveis, implemente criptografia end-to-end quando necessário, e nunca transmita credenciais em parâmetros de URL. Valide certificados SSL/TLS do lado cliente e revise protocolos legados (FTP, Telnet) para alternativas seguras.

CVE-2024-32864MEDIUMexacqVison - HTTPS Session EstablishmentEPSS 0.2%CVE-2024-48121MEDIUMThe HI-SCAN 6040i Hitrax HX-03-19-I was discovered to transmit user credentials in cleartext over the GIOP protocol. This allows attackers tEPSS 0.2%CVE-2026-24441HIGHTenda AC7 Transmits Admin Credentials Without HTTPS ProtectionEPSS 0.2%CVE-2026-45179MEDIUMPlack::Middleware::Statsd versions before 0.9.0 for Perl may leak user IP addressesEPSS 0.2%CVE-2026-22271HIGHDell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains a Cleartext Transmission of Sensitive IEPSS 0.2%CVE-2025-11640LOWTomofun Furbo 360/Furbo Mini Bluetooth Low Energy cleartext transmissionEPSS 0.2%CVE-2026-76244CRITICALstigmem-node Insecure Federation Transport ConfigurationEPSS 0.2%CVE-2019-9532The web application portal of the Cobham EXPLORER 710, firmware version 1.07, sends the login password in cleartextEPSS 0.2%CVE-2026-1014MEDIUMIBM InfoSphere Information Server is vulnerable due to disclosure of sensitive informationEPSS 0.2%CVE-2025-36020MEDIUMIBM Guardium Data Protection information disclosureEPSS 0.2%CVE-2021-23884MEDIUMClear text exposure of password in McAfee CSR ePO extensionEPSS 0.2%CVE-2025-25728MEDIUMBosscomm IF740 Firmware versions:11001.7078 & v11001.0000 and System versions: 6.25 & 6.00 were discovered to send communications to the updEPSS 0.2%CVE-2023-0001MEDIUMCortex XDR Agent: Cleartext Exposure of Agent Admin PasswordEPSS 0.2%CVE-2026-53624MEDIUMFiber: HSTS header never set in helmet middleware due to incorrect protocol checkEPSS 0.2%CVE-2026-73756MEDIUMUnauthenticated Sensitive Information Disclosure via Man-in-the-Middle in AOS-CX via API EndpointEPSS 0.2%CVE-2026-85719HIGHAsyncHttpClient: SOCKS proxy credentials sent to the origin server over plaintext HTTPEPSS 0.2%CVE-2022-42454MEDIUMHCL BigFix Insights for Vulnerability Remediation (IVR) is vulnerable to improper certificate validationEPSS 0.2%CVE-2022-47895MEDIUMIn JetBrains IntelliJ IDEA before 2022.3.1 the "Validate JSP File" action used the HTTP protocol to download required JAR files.EPSS 0.2%CVE-2026-50034HIGHApollo Pharmacy Blood Glucose Monitoring System APG-01 BT Cleartext Transmission of Sensitive InformationEPSS 0.2%CVE-2026-25608LOWLack of traffic encryption in STEREPSS 0.2%