Falhas do tipo CWE-319

539 resultados

Transmissão de dados sensíveis em texto plano

A aplicação envia informações sensíveis (senhas, tokens, dados pessoais) sem criptografia em um canal de comunicação que pode ser interceptado. Um atacante na rede consegue capturar esses dados facilmente com ferramentas simples como packet sniffers, comprometendo a confidencialidade.

Exemplo

Uma API envia credenciais de usuário via HTTP simples em vez de HTTPS, ou um sistema transmite tokens de autenticação em requisições GET visíveis em logs de proxy. Um atacante na mesma rede Wi-Fi captura os pacotes e acessa as credenciais diretamente.

Como mitigar

Use HTTPS/TLS em todas as comunicações envolvendo dados sensíveis, implemente criptografia end-to-end quando necessário, e nunca transmita credenciais em parâmetros de URL. Valide certificados SSL/TLS do lado cliente e revise protocolos legados (FTP, Telnet) para alternativas seguras.

CVE-2023-46889MEDIUMMeross MSH30Q 4.5.23 is vulnerable to Cleartext Transmission of Sensitive Information. During the device setup phase, the MSH30Q creates an EPSS 0.2%CVE-2024-45361MEDIUMMi Connect Service APP protocol flaws lead to leaking sensitive user informationEPSS 0.2%CVE-2026-31278HIGHAn issue in the /api/v2/setting/adserversetting endpoint of Suprema BioStar 2 before 2.9.12 and and BioStar X before 1.0.2 allows attackers EPSS 0.2%CVE-2026-73809HIGHEbyte NA111-M Cleartext Transmission of Sensitive InformationEPSS 0.2%CVE-2025-69272MEDIUMSpectrum password returned in clearEPSS 0.2%CVE-2025-4227LOWGlobalProtect App: Interception in Endpoint Traffic Policy EnforcementEPSS 0.2%CVE-2026-22306CRITICALCritical flaw impacting OZOLS ERP's automatic update channelEPSS 0.2%CVE-2024-44105HIGHCleartext transmission of sensitive information in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allEPSS 0.2%CVE-2026-4584LOWShenzhen HCC Technology MPOS M6 PLUS Cardholder Data cleartext transmissionEPSS 0.2%CVE-2026-2539MEDIUMMicca KE700 Cleartext transmission of key fob IDEPSS 0.2%CVE-2025-7743CRITICALSensitive Data Exposure in Dolusoft's OmaspotEPSS 0.2%CVE-2025-0136MEDIUMPAN-OS: Unencrypted Data Transfer when using AES-128-CCM on Intel-based hardware devicesEPSS 0.2%CVE-2024-49387MEDIUMCleartext transmission of sensitive information in acep-collector service. The following products are affected: Acronis Cyber Protect 16 (LiEPSS 0.2%CVE-2025-32887HIGHAn issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. A command channel includes the next hop. which can be inteEPSS 0.2%CVE-2026-84366HIGHScrapy: S3DownloadHandler sends signed S3 requests over plaintext HTTP by defaultEPSS 0.2%CVE-2026-5115LOWSession hijacking in PaperCut NG/MF embedded application for Konica Minolta devicesEPSS 0.2%CVE-2025-15619LOWHCL Connections is vulnerable to broken access controlEPSS 0.2%CVE-2026-12556HIGHHP Easy Start for macOS - Security UpdateEPSS 0.2%CVE-2025-36034MEDIUMIBM InfoSphere DataStage Flow Designer information disclosureEPSS 0.2%CVE-2024-9620MEDIUMEvent-driven automation in ansible automation platform (aap): ansible event-driven automation (eda) lacks encryptionEPSS 0.2%