Falhas do tipo CWE-319

538 resultados

Transmissão de dados sensíveis em texto plano

A aplicação envia informações sensíveis (senhas, tokens, dados pessoais) sem criptografia em um canal de comunicação que pode ser interceptado. Um atacante na rede consegue capturar esses dados facilmente com ferramentas simples como packet sniffers, comprometendo a confidencialidade.

Exemplo

Uma API envia credenciais de usuário via HTTP simples em vez de HTTPS, ou um sistema transmite tokens de autenticação em requisições GET visíveis em logs de proxy. Um atacante na mesma rede Wi-Fi captura os pacotes e acessa as credenciais diretamente.

Como mitigar

Use HTTPS/TLS em todas as comunicações envolvendo dados sensíveis, implemente criptografia end-to-end quando necessário, e nunca transmita credenciais em parâmetros de URL. Valide certificados SSL/TLS do lado cliente e revise protocolos legados (FTP, Telnet) para alternativas seguras.

CVE-2021-32966LOWPhilips Interoperability Solution XDS - Clear Text Transmission of Sensitive InformationEPSS 0.5%CVE-2019-14942MEDIUMAn issue was discovered in GitLab Community and Enterprise Edition before 11.11.8, 12 before 12.0.6, and 12.1 before 12.1.6. Cookies for GitEPSS 0.5%CVE-2023-23841HIGHSolarWinds Serv-U Exposure of Sensitive Information VulnerabilityEPSS 0.5%CVE-2024-35059HIGHAn issue in the Pickle Python library of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary commands.EPSS 0.5%CVE-2020-12048Phoenix Hemodialysis Delivery System SW 3.36 and 3.40, The Phoenix Hemodialysis device does not support data-in-transit encryption (e.g., TLEPSS 0.5%CVE-2025-32880CRITICALAn issue was discovered on COROS PACE 3 devices through 3.0808.0. It implements a function to connect the watch to a WLAN. With WLAN access,EPSS 0.5%CVE-2022-40939MEDIUMIn certain Secustation products the administrator account password can be read. This affects V2.5.5.3116-S50-SMA-B20171107A, V2.3.4.1301-M20EPSS 0.4%CVE-2022-44411HIGHWeb Based Quiz System v1.0 transmits user passwords in plaintext during the authentication process, allowing attackers to obtain users' passEPSS 0.4%CVE-2023-25016HIGHCouchbase Server before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2 exposes Sensitive Information to an Unauthorized Actor.EPSS 0.4%CVE-2023-53875HIGHGOM Player 2.3.90.5360 Remote Code Execution via Insecure IE ComponentEPSS 0.4%CVE-2023-30354CRITICALShenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 does not defend against physical access to U-Boot via the UART: the Wi-Fi passwoEPSS 0.4%CVE-2025-27594HIGHUnencrypted transmission of password hashEPSS 0.4%CVE-2024-35058HIGHAn issue in the API wait function of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary code via supplying a crafted string.EPSS 0.4%CVE-2023-28348HIGHAn issue was discovered in Faronics Insight 10.0.19045 on Windows. A suitably positioned attacker could perform a man-in-the-middle attack oEPSS 0.4%CVE-2026-49486HIGHApache Airflow FTP provider: FTP Provider does not protect FTPS data channel (missing PROT_P)EPSS 0.4%CVE-2024-50634HIGHA vulnerability in a weak JWT token in Watcharr v1.43.0 and below allows attackers to perform privilege escalation using a crafted JWT tokenEPSS 0.4%CVE-2024-38891CRITICALAn issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker tEPSS 0.4%CVE-2022-39287HIGHPlaintext transmission of CSRF tokens in tiny-csrfEPSS 0.4%CVE-2022-39339MEDIUMCleartext Transmission of Sensitive Information in user_oidcEPSS 0.4%CVE-2024-35057HIGHAn issue in NASA AIT-Core v2.5.2 allows attackers to execute arbitrary code via a crafted packet.EPSS 0.4%