VYPR

CWE-319

Cleartext Transmission of Sensitive Information

BaseDraftLikelihood: High

Description

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-117 · CAPEC-383 · CAPEC-477 · CAPEC-65

CVEs mapped to this weakness (914)

page 1 of 46
  • CVE-2024-25735CriMar 27, 2024
    risk 0.66cvss 9.1epss 0.51

    An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can discover cleartext passwords via a SoftAP /device/config GET request.

  • CVE-2016-5649CriJul 24, 2018
    risk 0.66cvss 9.8epss 0.27

    A vulnerability is in the 'BSW_cxttongr.htm' page of the Netgear DGN2200, version DGN2200-V1.0.0.50_7.0.50, and DGND3700, version DGND3700-V1.0.0.17_1.0.17, which can allow a remote attacker to access this page without any authentication. When processed, it exposes the admin…

  • CVE-2025-61481CriOct 27, 2025
    risk 0.65cvss 10.0epss 0.00

    An issue in MikroTik RouterOS v.7.14.2 and SwOS v.2.18 exposes the WebFig management interface over cleartext HTTP by default, allowing an on-path attacker to execute injected JavaScript in the administrator’s browser and intercept credentials.

  • CVE-2025-4378CriJun 24, 2025
    risk 0.65cvss 10.0epss 0.00

    Cleartext Transmission of Sensitive Information, Use of Hard-coded Credentials vulnerability in Ataturk University ATA-AOF Mobile Application allows Authentication Abuse, Authentication Bypass. This issue affects ATA-AOF Mobile Application: before 20.06.2025.

  • CVE-2025-47419CriMay 6, 2025
    risk 0.65cvss epss 0.00

    Cleartext Transmission of Sensitive Information vulnerability in Crestron Automate VX allows Sniffing Network Traffic. The device allows Web UI and API access over non-secure network ports which exposes sensitive information such as user passwords. This issue affects Automate…

  • CVE-2023-6248CriNov 21, 2023
    risk 0.65cvss 10.0epss 0.01

    The Syrus4 IoT gateway utilizes an unsecured MQTT server to download and execute arbitrary commands, allowing a remote unauthenticated attacker to execute code on any Syrus4 device connected to the cloud service. The MQTT server also leaks the location, video and diagnostic data…

  • CVE-2018-1297CriFeb 13, 2018
    risk 0.65cvss 9.8epss 0.10

    When using Distributed Test only (RMI based), Apache JMeter 2.x and 3.x uses an unsecured RMI connection. This could allow an attacker to get Access to JMeterEngine and send unauthorized code.

  • CVE-2015-0987CriOct 6, 2015
    risk 0.65cvss 10.0epss 0.01

    Omron CX-One CX-Programmer before 9.6, CJ2M PLC devices before 2.1, and CJ2H PLC devices before 1.5 rely on cleartext password transmission, which allows remote attackers to obtain sensitive information by sniffing the network during a PLC unlock request.

  • CVE-2026-48902CriMay 26, 2026
    risk 0.64cvss 9.8epss 0.00

    The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.

  • CVE-2025-34271CriOct 30, 2025
    risk 0.64cvss 9.8epss 0.01

    Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the cluster manager component when requesting sensitive credentials from peer nodes over an unencrypted channel even when SSL/TLS is enabled in the product configuration. As a result, an attacker…

  • CVE-2025-56447CriOct 22, 2025
    risk 0.64cvss 9.8epss 0.00

    TM2 Monitoring v3.04 contains an authentication bypass and plaintext credential disclosure.

  • CVE-2025-32880CriJun 20, 2025
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered on COROS PACE 3 devices through 3.0808.0. It implements a function to connect the watch to a WLAN. With WLAN access, the COROS Pace 3 downloads firmware files via HTTP. However, the communication is not encrypted and allows sniffing and…

  • CVE-2025-26199CriJun 18, 2025
    risk 0.64cvss 9.8epss 0.00

    CloudClassroom-PHP-Project v1.0 is affected by an insecure credential transmission vulnerability. The application transmits passwords over unencrypted HTTP during the login process, exposing sensitive credentials to potential interception by network-based attackers. A remote…

  • CVE-2023-39245CriFeb 15, 2024
    risk 0.64cvss 9.8epss 0.00

    DELL ESI (Enterprise Storage Integrator) for SAP LAMA, version 10.0, contains an information disclosure vulnerability in EHAC component. An remote unauthenticated attacker could potentially exploit this vulnerability by eavesdropping the network traffic to gain admin level…

  • CVE-2023-31410CriJun 19, 2023
    risk 0.64cvss 9.8epss 0.00

    A remote unprivileged attacker can intercept the communication via e.g. Man-In-The-Middle, due to the absence of Transport Layer Security (TLS) in the SICK EventCam App. This lack of encryption in the communication channel can lead to the unauthorized disclosure of sensitive…

  • CVE-2023-33730CriMay 31, 2023
    risk 0.64cvss 9.8epss 0.01

    Privilege Escalation in the "GetUserCurrentPwd" function in Microworld Technologies eScan Management Console 14.0.1400.2281 allows any remote attacker to retrieve password of any admin or normal user in plain text format.

  • CVE-2023-30354CriMay 10, 2023
    risk 0.64cvss 9.8epss 0.00

    Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 does not defend against physical access to U-Boot via the UART: the Wi-Fi password is shown, and the hardcoded boot password can be inserted for console access.

  • CVE-2022-47714CriFeb 1, 2023
    risk 0.64cvss 9.8epss 0.01

    Last Yard 22.09.8-1 does not enforce HSTS headers

  • CVE-2022-43724CriDec 13, 2022
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been identified in SICAM PAS/PQS (All versions < V7.0). Affected software transmits the database credentials for the inbuilt SQL server in cleartext. In combination with the by default enabled xp_cmdshell feature unauthenticated remote attackers could execute…

  • CVE-2022-33321CriNov 8, 2022
    risk 0.64cvss 9.8epss 0.01

    Cleartext Transmission of Sensitive Information vulnerability due to the use of Basic Authentication for HTTP connections in Mitsubishi Electric consumer electronics products (PHOTOVOLTAIC COLOR MONITOR ECO-GUIDE, HEMS adapter, Wi-Fi Interface, Air Conditioning, Induction hob,…