Falhas do tipo CWE-319

538 resultados

Transmissão de dados sensíveis em texto plano

A aplicação envia informações sensíveis (senhas, tokens, dados pessoais) sem criptografia em um canal de comunicação que pode ser interceptado. Um atacante na rede consegue capturar esses dados facilmente com ferramentas simples como packet sniffers, comprometendo a confidencialidade.

Exemplo

Uma API envia credenciais de usuário via HTTP simples em vez de HTTPS, ou um sistema transmite tokens de autenticação em requisições GET visíveis em logs de proxy. Um atacante na mesma rede Wi-Fi captura os pacotes e acessa as credenciais diretamente.

Como mitigar

Use HTTPS/TLS em todas as comunicações envolvendo dados sensíveis, implemente criptografia end-to-end quando necessário, e nunca transmita credenciais em parâmetros de URL. Valide certificados SSL/TLS do lado cliente e revise protocolos legados (FTP, Telnet) para alternativas seguras.

CVE-2007-4786MEDIUMCisco Adaptive Security Appliance (ASA) running PIX 7.0 before 7.0.7.1, 7.1 before 7.1.2.61, 7.2 before 7.2.2.34, and 8.0 before 8.0.2.11, wEPSS 0.5%CVE-2020-12036Baxter PrismaFlex all versions, PrisMax all versions prior to 3.x, The affected devices do not implement data-in-transit encryption (e.g., TEPSS 0.5%CVE-2024-28134HIGHPHOENIX CONTACT: MitM attack gains privileges of the current logged in user in CHARX Series EPSS 0.5%CVE-2023-30602HIGHHitron Technologies Inc. CODA-5310 - Insecure service TelnetEPSS 0.5%CVE-2023-30513HIGHJenkins Kubernetes Plugin 3909.v1f2c633e8590 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log EPSS 0.5%CVE-2021-3792MEDIUMSome device communications in some Motorola-branded Binatone Hubble Cameras with backend Hubble services are not encrypted which could lead EPSS 0.5%CVE-2023-3761LOWIntergard SGS Password Change cleartext transmissionEPSS 0.5%CVE-2026-1777HIGHCleartext transmission of sensitive materials in aws/sagemaker-python-sdkEPSS 0.5%CVE-2023-0922MEDIUMThe Samba AD DC administration tool, when operating against a remote LDAP server, will by default send new or reset passwords over a signed-EPSS 0.5%CVE-2025-0784MEDIUMIntelbras InControl Registered User usuario cleartext transmissionEPSS 0.5%CVE-2023-30514HIGHJenkins Azure Key Vault Plugin 187.va_cd5fecd198a_ and earlier does not properly mask (i.e., replace with asterisks) credentials in the builEPSS 0.5%CVE-2021-3473MEDIUMAn internal product security audit of Lenovo XClarity Controller (XCC) discovered that the XCC configuration backup/restore password may be EPSS 0.5%CVE-2018-10634MEDIUMMedtronic MiniMed MMT-500/MMT-503 Remote Controllers Cleartext Transmission of Sensitive InformationEPSS 0.5%CVE-2024-4161HIGHSyslog traffic sent in clear-textEPSS 0.5%CVE-2021-23846HIGHB426 Credential DisclosureEPSS 0.5%CVE-2020-9420MEDIUMThe login password of the web administrative dashboard in Arcadyan Wifi routers VRV9506JAC23 is sent in cleartext, allowing an attacker to sEPSS 0.5%CVE-2024-35060HIGHAn issue in the YAML Python library of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary commands via supplying a crafted YAML fileEPSS 0.5%CVE-2022-43691MEDIUMConcrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 inadvertently disclose server-side sensitive information (secretsEPSS 0.5%CVE-2025-69969CRITICALA lack of authentication and authorization mechanisms in the Bluetooth Low Energy (BLE) communication protocol of SRK Powertech Pvt Ltd PebbEPSS 0.5%CVE-2022-21184MEDIUMAn information disclosure vulnerability exists in the License registration functionality of Bachmann Visutec GmbH Atvise 3.5.4, 3.6 and 3.7.EPSS 0.5%