Falhas do tipo CWE-319

538 resultados

Transmissão de dados sensíveis em texto plano

A aplicação envia informações sensíveis (senhas, tokens, dados pessoais) sem criptografia em um canal de comunicação que pode ser interceptado. Um atacante na rede consegue capturar esses dados facilmente com ferramentas simples como packet sniffers, comprometendo a confidencialidade.

Exemplo

Uma API envia credenciais de usuário via HTTP simples em vez de HTTPS, ou um sistema transmite tokens de autenticação em requisições GET visíveis em logs de proxy. Um atacante na mesma rede Wi-Fi captura os pacotes e acessa as credenciais diretamente.

Como mitigar

Use HTTPS/TLS em todas as comunicações envolvendo dados sensíveis, implemente criptografia end-to-end quando necessário, e nunca transmita credenciais em parâmetros de URL. Valide certificados SSL/TLS do lado cliente e revise protocolos legados (FTP, Telnet) para alternativas seguras.

CVE-2025-8205MEDIUMComodo Dragon IP DNS Leakage Detector cleartext transmissionEPSS 0.4%CVE-2023-32290HIGHThe myMail app through 14.30 for iOS sends cleartext credentials in a situation where STARTTLS is expected by a server.EPSS 0.4%CVE-2024-27163MEDIUMLeak of admin password and passwordsEPSS 0.4%CVE-2003-5002LOWISS BlackICE PC Protection Update cleartext transmissionEPSS 0.4%CVE-2022-41636CRITICALCommunication traffic involving "Ethernet Q Commands" service of Haas Controller version 100.20.000.1110 is transmitted in cleartext. This aEPSS 0.4%CVE-2026-15806MEDIUM`HTTPPasswordMgr` can send saved HTTPS credentials via HTTP because of incorrect scheme matchingEPSS 0.4%CVE-2022-22385MEDIUMIBM Security Verify Privilege information disclosureEPSS 0.4%CVE-2023-29680MEDIUMCleartext Transmission in set-cookie:ecos_pw: Tenda N301 v6.0, Firmware v12.02.01.61_multi allows an authenticated attacker on the LAN or WLEPSS 0.4%CVE-2023-29681MEDIUMCleartext Transmission in cookie:ecos_pw: in Tenda N301 v6.0, firmware v12.03.01.06_pt allows an authenticated attacker on the LAN or WLAN tEPSS 0.4%CVE-2023-30515HIGHJenkins Thycotic DevOps Secrets Vault Plugin 1.0.0 and earlier does not properly mask (i.e., replace with asterisks) credentials in the builEPSS 0.4%CVE-2023-5461LOWDelta Electronics WPLSoft Modbus cleartext transmissionEPSS 0.4%CVE-2021-21387HIGHPartial secret key disclosure, improper safety number calculation, & inadequate encryption strengthEPSS 0.4%CVE-2024-6515HIGHunauthorized file accessEPSS 0.4%CVE-2022-3929HIGHCommunication between the client and server partially using CORBA over TCP/IPEPSS 0.4%CVE-2022-21951MEDIUMRancher: Weave CNI password is not set if RKE template is used with CNI value overriddenEPSS 0.4%CVE-2020-4497MEDIUMIBM Spectrum Protect Plus information disclosureEPSS 0.4%CVE-2023-0053HIGHSAUTER Controls Nova 200–220 Series Cleartext Transmission of Sensitive InformationEPSS 0.4%CVE-2023-31193HIGH Snap One OvrC Pro versions prior to 7.3 use HTTP connections when downloading a program from their servers. Because they do notEPSS 0.4%CVE-2022-45483MEDIUMLazy Mouse allows an attacker (in a man in the middle position between the server and a connected device) to see all data (including keypresEPSS 0.4%CVE-2022-45480MEDIUMPC Keyboard WiFi & Bluetooth allows an attacker (in a man-in-the-middle position between the server and a connected device) to see all data EPSS 0.4%