Weaknesses of type CWE-319

501 results

Transmissão de dados sensíveis em texto plano

A aplicação envia informações críticas (senhas, tokens, dados pessoais) sem criptografia em canais de comunicação que podem ser interceptados. Um atacante na rede consegue capturar esses dados diretamente, comprometendo a confidencialidade da informação e permitindo roubo de credenciais ou dados sensíveis.

Example

Um app mobile envia login e senha via HTTP (não HTTPS), ou um sistema transmite números de cartão de crédito em requisições não criptografadas. Ferramentas simples como Wireshark permitem capturar esse tráfego em redes abertas ou mesmo corporativas.

How to mitigate

Sempre usar HTTPS/TLS para qualquer transmissão de dados sensíveis, implementar pinning de certificado em apps mobile, validar certificados no lado cliente, e nunca transmitir segredos em URLs ou headers sem criptografia. Na prática: configure HTTPS em produção, force redirecionamento HTTP → HTTPS, e audite logs de requisições para detectar canais desprotegidos.

CVE-2024-48894MEDIUMA cleartext transmission vulnerability exists in the WEBVIEW-M functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted HTTP EPSS 0.9%CVE-2023-2754HIGHPlaintext transmission of DNS requests in Windows 1.1.1.1 WARP clientEPSS 0.9%CVE-2022-33321CRITICALCleartext Transmission of Sensitive Information vulnerability due to the use of Basic Authentication for HTTP connections in Mitsubishi ElecEPSS 0.9%CVE-2018-5402CRITICALThe Auto-Maskin DCU 210E, RP-210E, and Marine Pro Observer Android App use an embedded webserver that uses unencrypted plaintext for the transmission of the administrator PINEPSS 0.9%CVE-2018-5401CRITICALThe Auto-Maskin DCU 210E, RP-210E, and Marine Pro Observer Android App transmit sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actorsEPSS 0.9%CVE-2023-23915MEDIUMA cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality to behave incorrEPSS 0.9%CVE-2023-23914CRITICALA cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality fail when multipEPSS 0.9%CVE-2024-21406HIGHWindows Printing Service Spoofing VulnerabilityEPSS 0.9%CVE-2020-7488HIGHA CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists which could leak sensitive information transmitted between tEPSS 0.9%CVE-2018-8855CRITICALEchelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versionsEPSS 0.8%CVE-2018-19944Cleartext Transmission of Sensitive Information in SNMPEPSS 0.8%CVE-2019-18231Advantech Spectre RT ERT351 Versions 5.1.3 and prior logins and passwords are transmitted in clear text form, which may allow an attacker toEPSS 0.8%CVE-2021-39342MEDIUMCredova_Financial <= 1.4.8 Sensitive Information DisclosureEPSS 0.8%CVE-2018-8929HIGHImproper restriction of communication channel to intended endpoints vulnerability in HTTP daemon in Synology SSL VPN Client before 1.2.4-022EPSS 0.8%CVE-2021-26560CRITICALCleartext transmission of sensitive information vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 6.2.3-25426EPSS 0.7%CVE-2020-10628ControlEdge PLC (R130.2, R140, R150, and R151) and RTU (R101, R110, R140, R150, and R151) exposes unencrypted passwords on the network.EPSS 0.7%CVE-2020-10624ControlEdge PLC (R130.2, R140, R150, and R151) and RTU (R101, R110, R140, R150, and R151) exposes a session token on the network.EPSS 0.7%CVE-2020-25155The affected product transmits unencrypted sensitive information, which may allow an attacker to access this information on the NIO 50 (all EPSS 0.7%CVE-2021-27251HIGHThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR Nighthawk R7800. AuthentEPSS 0.7%CVE-2022-29874HIGHA vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices do not encrypt web traffic with clients but communicaEPSS 0.7%