Falhas do tipo CWE-319

536 resultados

Transmissão de dados sensíveis em texto plano

A aplicação envia informações sensíveis (senhas, tokens, dados pessoais) sem criptografia em um canal de comunicação que pode ser interceptado. Um atacante na rede consegue capturar esses dados facilmente com ferramentas simples como packet sniffers, comprometendo a confidencialidade.

Exemplo

Uma API envia credenciais de usuário via HTTP simples em vez de HTTPS, ou um sistema transmite tokens de autenticação em requisições GET visíveis em logs de proxy. Um atacante na mesma rede Wi-Fi captura os pacotes e acessa as credenciais diretamente.

Como mitigar

Use HTTPS/TLS em todas as comunicações envolvendo dados sensíveis, implemente criptografia end-to-end quando necessário, e nunca transmita credenciais em parâmetros de URL. Valide certificados SSL/TLS do lado cliente e revise protocolos legados (FTP, Telnet) para alternativas seguras.

CVE-2026-25599MEDIUMMissing authentication and clear‑text data transmission affecting Orca heat pumpsEPSS 0.1%CVE-2024-25960HIGHDell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains a cleartext transmission of sensitive information vulnerability. A local lowEPSS 0.1%CVE-2025-2818MEDIUMA vulnerability was reported in version 1.0 of the Bluetooth Transmission Alliance protocol adopted by Motorola Smart Connect Android ApplicEPSS 0.1%CVE-2025-6180HIGHAuthentication HijackEPSS 0.1%CVE-2025-40583MEDIUMA vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V2.1 HF0 with SINEMA Remote Connect Edge ClientEPSS 0.1%CVE-2026-79779MEDIUMrclone before v1.75.0 WebDAV Credential Exposure via HTTPS-to-HTTP RedirectEPSS 0.1%CVE-2023-42144MEDIUMCleartext Transmission during initial setup in Shelly TRV 20220811-15234 v.2.1.8 allows a local attacker to obtain the Wi-Fi password.EPSS 0.1%CVE-2025-22493MEDIUMImproper cookie attributes in Foreseer Reporting Software (FRS)EPSS 0.1%CVE-2023-23371MEDIUMQVPN Device ClientEPSS 0.1%CVE-2025-63292LOWFreebox v5 HD (firmware = 1.7.20), Freebox v5 Crystal (firmware = 1.7.20), Freebox v6 Révolution r1–r3 (firmware = 4.7.x), Freebox Mini 4K (EPSS 0.1%CVE-2026-33472MEDIUMCryptomator Hub OAuth token exchange HTTP downgrade via getAuthority() scheme confusion (CVE-2026-32303 bypass)EPSS 0.1%CVE-2026-79588MEDIUMU-speed WIFI4 N300 T1 Pro v1.0.0 is vulnerable to Cleartext transmission of administration credentials over HTTP.EPSS 0.1%CVE-2025-65855MEDIUMThe OTA firmware update mechanism in Netun Solutions HelpFlash IoT (firmware v18_178_221102_ASCII_PRO_1R5_50) uses hard-coded WiFi credentiaEPSS 0.1%CVE-2026-9741HIGHClient side encryption fails to encrypt values in a $vectorSearchEPSS 0.1%CVE-2025-13454MEDIUMA potential vulnerability was reported in ThinkPlus configuration software that could allow a local authenticated user to gain access to senEPSS 0.1%CVE-2026-20801MEDIUMCleartext Transmission of Sensitive Information (CWE-319) in a component used in the Gallagher Hanwha VMS and Gallagher NxWitness VMS integrEPSS 0.1%CVE-2026-10584HIGHHTTPS Fallback to HTTP in Graph ExplorerEPSS 0.1%CVE-2025-53861LOWAap: sensitive cookie(s) set without security flagsEPSS 0.1%CVE-2026-34126HIGHBluetooth Communication Uses Unencrypted Transmission During Initial Setup on TP-Link's Tapo L535E, P300 and D100CEPSS 0.1%CVE-2024-47124LOWCleartext Transmission of Sensitive Information in goTenna ProEPSS 0.1%