Falhas do tipo CWE-319

538 resultados

Transmissão de dados sensíveis em texto plano

A aplicação envia informações sensíveis (senhas, tokens, dados pessoais) sem criptografia em um canal de comunicação que pode ser interceptado. Um atacante na rede consegue capturar esses dados facilmente com ferramentas simples como packet sniffers, comprometendo a confidencialidade.

Exemplo

Uma API envia credenciais de usuário via HTTP simples em vez de HTTPS, ou um sistema transmite tokens de autenticação em requisições GET visíveis em logs de proxy. Um atacante na mesma rede Wi-Fi captura os pacotes e acessa as credenciais diretamente.

Como mitigar

Use HTTPS/TLS em todas as comunicações envolvendo dados sensíveis, implemente criptografia end-to-end quando necessário, e nunca transmita credenciais em parâmetros de URL. Valide certificados SSL/TLS do lado cliente e revise protocolos legados (FTP, Telnet) para alternativas seguras.

CVE-2018-0025MEDIUMJunos OS: SRX Series: Credentials exposed when using HTTP and HTTPS Firewall Pass-through User AuthenticationEPSS 1.4%CVE-2020-1749HIGHA flaw was found in the Linux kernel's implementation of some networking protocols in IPsec, such as VXLAN and GENEVE tunnels over IPv6. WheEPSS 1.2%CVE-2023-6248CRITICALData leakage and arbitrary remote code execution in Syrus cloud devicesEPSS 1.2%CVE-2023-34998HIGHAn authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v18.00.0072. A speciaEPSS 1.2%CVE-2023-33730CRITICALPrivilege Escalation in the "GetUserCurrentPwd" function in Microworld Technologies eScan Management Console 14.0.1400.2281 allows any remotEPSS 1.2%CVE-2015-0987CRITICALOmron CX-One CX-Programmer before 9.6, CJ2M PLC devices before 2.1, and CJ2H PLC devices before 1.5 rely on cleartext password transmission,EPSS 1.2%CVE-2024-0056HIGHMicrosoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass VulnerabilityEPSS 1.2%CVE-2022-26077HIGHA cleartext transmission of sensitive information vulnerability exists in the OAS Engine configuration communications functionality of Open EPSS 1.1%CVE-2018-14627MEDIUMThe IIOP OpenJDK Subsystem in WildFly before version 14.0.0 does not honour configuration when SSL transport is required. Servers before thiEPSS 1.1%CVE-2019-6845A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists in Modicon M580, Modicon M340, Modicon Premium , Modicon QuaEPSS 1.1%CVE-2024-48894MEDIUMA cleartext transmission vulnerability exists in the WEBVIEW-M functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted HTTP EPSS 1.1%CVE-2019-18285A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The RMI communication between tEPSS 1.0%CVE-2012-5562HIGHRhn-proxy: rhn-satellite: rhn-proxy: information disclosure via clear-text credential transmission when accessing rhn satelliteEPSS 1.0%CVE-2020-25169Reolink P2P CamerasEPSS 1.0%CVE-2019-6846A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists in Modicon M580, Modicon M340, Modicon BMxCRA and 140CRA modEPSS 1.0%CVE-2020-7003In Moxa ioLogik 2500 series firmware, Version 3.0 or lower, and IOxpress configuration utility, Version 2.3.0 or lower, sensitive informatioEPSS 1.0%CVE-2020-6997In Moxa EDS-G516E Series firmware, Version 5.2 or lower, sensitive information is transmitted over some web applications in cleartext.EPSS 1.0%CVE-2022-33321CRITICALCleartext Transmission of Sensitive Information vulnerability due to the use of Basic Authentication for HTTP connections in Mitsubishi ElecEPSS 1.0%CVE-2020-25190HIGHMOXA NPort IAW5000A-I/O SeriesEPSS 1.0%CVE-2018-5401CRITICALThe Auto-Maskin DCU 210E, RP-210E, and Marine Pro Observer Android App transmit sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actorsEPSS 1.0%