VYPR

CWE-319

Cleartext Transmission of Sensitive Information

BaseDraftLikelihood: High

Description

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-117 · CAPEC-383 · CAPEC-477 · CAPEC-65

CVEs mapped to this weakness (914)

page 10 of 46
  • CVE-2023-3361HigOct 4, 2023
    risk 0.50cvss 7.7epss 0.00

    A flaw was found in Red Hat OpenShift Data Science. When exporting a pipeline from the Elyra notebook pipeline editor as Python DSL or YAML, it reads S3 credentials from the cluster (ds pipeline server) and saves them in plain text in the generated output instead of an ID for a…

  • CVE-2022-43551HigDec 23, 2022
    risk 0.50cvss 7.5epss 0.17

    A vulnerability exists in curl <7.87.0 HSTS check that could be bypassed to trick it to keep using HTTP. Using its HSTS support, curl can be instructed to use HTTPS instead of using an insecure clear-text HTTP step even when HTTP is provided in the URL. However, the HSTS…

  • CVE-2021-45447HigNov 2, 2022
    risk 0.50cvss 7.7epss 0.00

    Hitachi Vantara Pentaho Business Analytics Server versions before 9.3.0.0, 9.2.0.2 and 8.3.0.25 with the Data Lineage feature enabled transmits database passwords in clear text.   The transmission of sensitive data in clear text allows unauthorized actors with access to the…

  • CVE-2022-2003HigAug 31, 2022
    risk 0.50cvss 7.7epss 0.01

    AutomationDirect DirectLOGIC is vulnerable to a specifically crafted serial message to the CPU serial port that will cause the PLC to respond with the PLC password in cleartext. This could allow an attacker to access and make unauthorized changes. This issue affects:…

  • CVE-2026-34126HigMay 28, 2026
    risk 0.49cvss 7.5epss 0.00

    TP-Link has identified a vulnerability in Tapo L535E v1.0 and v3.0, Tapo P300 v1.0, and Tapo D100C v1.0, where Bluetooth communication during the initial setup phase is transmitted in cleartext without encryption. Bluetooth is only used during initialization. An attacker…

  • CVE-2026-24212HigMay 26, 2026
    risk 0.49cvss 7.5epss 0.01

    NVIDIA Isaac Launchable for Linux contains a vulnerability where sensitive information is transmitted in clear text. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.

  • CVE-2026-41275HigApr 23, 2026
    risk 0.49cvss 7.5epss 0.00

    Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the password reset functionality on cloud.flowiseai.com sends a reset password link over the unsecured HTTP protocol instead of HTTPS. This behavior introduces the risk of a…

  • CVE-2026-5115HigMar 31, 2026
    risk 0.49cvss 7.5epss 0.00

    The PaperCut NG/MF (specifically, the embedded application for Konica Minolta devices) is vulnerable to session hijacking. The PaperCut NG/MF Embedded application is a software interface that runs directly on the touch screen of a multi-function device. It was internally…

  • CVE-2026-32838HigMar 17, 2026
    risk 0.49cvss 7.5epss 0.00

    Edimax GS-5008PL firmware version 1.00.54 and prior use cleartext HTTP for the web management interface without implementing TLS or SSL encryption. Attackers on the same network can intercept management traffic to capture administrator credentials and sensitive configuration…

  • CVE-2026-23662HigMar 10, 2026
    risk 0.49cvss 7.5epss 0.01

    Missing authentication for critical function in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-23661HigMar 10, 2026
    risk 0.49cvss 7.5epss 0.01

    Cleartext transmission of sensitive information in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.

  • CVE-2025-70048HigMar 9, 2026
    risk 0.49cvss 7.5epss 0.00

    An issue pertaining to CWE-319: Cleartext Transmission of Sensitive Information was discovered in Nexusoft NexusInterface v3.2.0-beta.2.

  • CVE-2026-30795HigMar 5, 2026
    risk 0.49cvss 7.5epss 0.00

    Cleartext Transmission of Sensitive Information vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Heartbeat sync loop modules) allows Sniffing Attacks. This vulnerability is associated with program files…

  • CVE-2025-58107HigMar 2, 2026
    risk 0.49cvss 7.5epss 0.00

    In Microsoft Exchange through 2019, Exchange ActiveSync (EAS) configurations on on-premises servers may transmit sensitive data from Samsung mobile devices in cleartext, including the user's name, e-mail address, device ID, bearer token, and base64-encoded password.

  • CVE-2026-24455HigFeb 20, 2026
    risk 0.49cvss 7.5epss 0.00

    The embedded web interface of the device does not support HTTPS/TLS for authentication and uses HTTP Basic Authentication. Traffic is encoded but not encrypted, exposing user credentials to passive interception by attackers on the same network.

  • CVE-2026-22271HigJan 23, 2026
    risk 0.49cvss 7.5epss 0.00

    Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains a Cleartext Transmission of Sensitive Information vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to…

  • CVE-2025-69272HigJan 12, 2026
    risk 0.49cvss 7.5epss 0.00

    Cleartext Transmission of Sensitive Information vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Sniffing Attacks.This issue affects DX NetOps Spectrum: 21.2.1 and earlier.

  • CVE-2020-36917HigJan 6, 2026
    risk 0.49cvss 7.5epss 0.00

    iDS6 DSSPro Digital Signage System 6.2 contains a sensitive information disclosure vulnerability that allows remote attackers to intercept authentication credentials through cleartext cookie transmission. Attackers can exploit the autoSave feature to capture user passwords…

  • CVE-2020-36914HigJan 6, 2026
    risk 0.49cvss 7.5epss 0.00

    QiHang Media Web Digital Signage 3.0.9 contains a sensitive information disclosure vulnerability that allows remote attackers to intercept user authentication credentials through cleartext cookie transmission. Attackers can perform man-in-the-middle attacks to capture and…

  • CVE-2025-67159HigJan 2, 2026
    risk 0.49cvss 7.5epss 0.00

    Vatilon v1.12.37-20240124 was discovered to transmit user credentials in plaintext.