Falhas do tipo CWE-319

538 resultados

Transmissão de dados sensíveis em texto plano

A aplicação envia informações sensíveis (senhas, tokens, dados pessoais) sem criptografia em um canal de comunicação que pode ser interceptado. Um atacante na rede consegue capturar esses dados facilmente com ferramentas simples como packet sniffers, comprometendo a confidencialidade.

Exemplo

Uma API envia credenciais de usuário via HTTP simples em vez de HTTPS, ou um sistema transmite tokens de autenticação em requisições GET visíveis em logs de proxy. Um atacante na mesma rede Wi-Fi captura os pacotes e acessa as credenciais diretamente.

Como mitigar

Use HTTPS/TLS em todas as comunicações envolvendo dados sensíveis, implemente criptografia end-to-end quando necessário, e nunca transmita credenciais em parâmetros de URL. Valide certificados SSL/TLS do lado cliente e revise protocolos legados (FTP, Telnet) para alternativas seguras.

CVE-2018-5471A Cleartext Transmission of Sensitive Information issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, aEPSS 1.0%CVE-2020-12040Sigma Spectrum Infusion System v's6.x (model 35700BAX) and Baxter Spectrum Infusion System Version(s) 8.x (model 35700BAX2) at the applicatiEPSS 0.9%CVE-2020-12008Baxter ExactaMix EM 2400 Versions 1.10, 1.11 and ExactaMix EM1200 Versions 1.1, 1.2 systems use cleartext messages to communicate order infoEPSS 0.9%CVE-2023-2754HIGHPlaintext transmission of DNS requests in Windows 1.1.1.1 WARP clientEPSS 0.9%CVE-2020-7488HIGHA CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists which could leak sensitive information transmitted between tEPSS 0.9%CVE-2023-23915MEDIUMA cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality to behave incorrEPSS 0.9%CVE-2023-23914CRITICALA cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality fail when multipEPSS 0.9%CVE-2024-21406HIGHWindows Printing Service Spoofing VulnerabilityEPSS 0.9%CVE-2018-8929HIGHImproper restriction of communication channel to intended endpoints vulnerability in HTTP daemon in Synology SSL VPN Client before 1.2.4-022EPSS 0.8%CVE-2018-19944Cleartext Transmission of Sensitive Information in SNMPEPSS 0.8%CVE-2018-5402CRITICALThe Auto-Maskin DCU 210E, RP-210E, and Marine Pro Observer Android App use an embedded webserver that uses unencrypted plaintext for the transmission of the administrator PINEPSS 0.8%CVE-2018-8855CRITICALEchelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versionsEPSS 0.8%CVE-2019-18231Advantech Spectre RT ERT351 Versions 5.1.3 and prior logins and passwords are transmitted in clear text form, which may allow an attacker toEPSS 0.8%CVE-2021-39342MEDIUMCredova_Financial <= 1.4.8 Sensitive Information DisclosureEPSS 0.8%CVE-2021-26560CRITICALCleartext transmission of sensitive information vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 6.2.3-25426EPSS 0.8%CVE-2020-10624ControlEdge PLC (R130.2, R140, R150, and R151) and RTU (R101, R110, R140, R150, and R151) exposes a session token on the network.EPSS 0.7%CVE-2020-25155The affected product transmits unencrypted sensitive information, which may allow an attacker to access this information on the NIO 50 (all EPSS 0.7%CVE-2020-10628ControlEdge PLC (R130.2, R140, R150, and R151) and RTU (R101, R110, R140, R150, and R151) exposes unencrypted passwords on the network.EPSS 0.7%CVE-2021-26565HIGHCleartext transmission of sensitive information vulnerability in synorelayd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allowEPSS 0.7%CVE-2022-29874HIGHA vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices do not encrypt web traffic with clients but communicaEPSS 0.7%