Falhas do tipo CWE-319

539 resultados

Transmissão de dados sensíveis em texto plano

A aplicação envia informações sensíveis (senhas, tokens, dados pessoais) sem criptografia em um canal de comunicação que pode ser interceptado. Um atacante na rede consegue capturar esses dados facilmente com ferramentas simples como packet sniffers, comprometendo a confidencialidade.

Exemplo

Uma API envia credenciais de usuário via HTTP simples em vez de HTTPS, ou um sistema transmite tokens de autenticação em requisições GET visíveis em logs de proxy. Um atacante na mesma rede Wi-Fi captura os pacotes e acessa as credenciais diretamente.

Como mitigar

Use HTTPS/TLS em todas as comunicações envolvendo dados sensíveis, implemente criptografia end-to-end quando necessário, e nunca transmita credenciais em parâmetros de URL. Valide certificados SSL/TLS do lado cliente e revise protocolos legados (FTP, Telnet) para alternativas seguras.

CVE-2024-9620MEDIUMEvent-driven automation in ansible automation platform (aap): ansible event-driven automation (eda) lacks encryptionEPSS 0.2%CVE-2025-32881MEDIUMAn issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. By default, the GID is the user's phone number unless theyEPSS 0.2%CVE-2025-32884MEDIUMAn issue was discovered on goTenna Mesh devices with app 5.5.3 and firmware 1.1.12. By default, a GID is the user's phone number unless theyEPSS 0.2%CVE-2023-0864HIGHConfiguration data is exchanged in plaintext and could be available to a nearby attacker if present during configuration or usage of the device via Bluetooth Low Energy (BLE).EPSS 0.2%CVE-2025-62330MEDIUMHCL DevOps Deploy is susceptible to a cleartext transmission of sensitive informationEPSS 0.2%CVE-2024-36558HIGHForever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h suffers from Cleartext Transmission of Sensitive InformatioEPSS 0.2%CVE-2026-18536HIGHData::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTPEPSS 0.2%CVE-2023-43124MEDIUMBIG-IP APM Clients TunnelCrack vulnerabilityEPSS 0.2%CVE-2024-28786MEDIUMIBM QRadar SIEM information disclosureEPSS 0.2%CVE-2020-3442MEDIUMDuoConnect SSH Connection VulnerabilityEPSS 0.2%CVE-2024-40595MEDIUMAn authentication-bypass issue in the RDP component of One Identity Safeguard for Privileged Sessions (SPS) On Premise before 7.5.1 (and LTSEPSS 0.2%CVE-2026-77131MEDIUMCleartext Transmission of Sensitive Information in extension "SYSSY - TYPO3 Monitoring & Security Checks" (syssy)EPSS 0.2%CVE-2026-55860MEDIUMMariaDB Connector/R2DBC: Cleartext password disclosure to a man-in-the-middle server (clear-text auth plugins not gated on a secure transport)EPSS 0.2%CVE-2024-41927MEDIUMCleartext transmission of sensitive information vulnerability exists in multiple IDEC PLCs. If an attacker sends a specific command to PLC'sEPSS 0.2%CVE-2025-43013MEDIUMIn JetBrains Toolbox App before 2.6 unencrypted credential transmission during SSH authentication was possibleEPSS 0.2%CVE-2026-20115MEDIUMA vulnerability in Cisco IOS XE Software for Cisco Meraki could allow a remote, unauthenticated attacker to view confidential device informaEPSS 0.2%CVE-2024-0098MEDIUMCVEEPSS 0.2%CVE-2026-7666LOWPotential unencrypted email transmission via STARTTLS in the SMTP backendEPSS 0.1%CVE-2026-86689HIGHCleartext Transmission of Sensitive Information in Bransys ELDEPSS 0.1%CVE-2026-29988HIGHA cleartext transmission of sensitive information vulnerability in the NFC interface of multiple Milesight IoT device models running affecteEPSS 0.1%