CWE-319
Cleartext Transmission of Sensitive Information
Description
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-102 · CAPEC-117 · CAPEC-383 · CAPEC-477 · CAPEC-65
CVEs mapped to this weakness (950)
page 11 of 48| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-70048 | Hig | 0.49 | 7.5 | 0.00 | Mar 9, 2026 | An issue pertaining to CWE-319: Cleartext Transmission of Sensitive Information was discovered in Nexusoft NexusInterface v3.2.0-beta.2. | ||
| CVE-2026-30795 | Hig | 0.49 | 7.5 | 0.00 | Mar 5, 2026 | Cleartext Transmission of Sensitive Information vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Heartbeat sync loop modules) allows Sniffing Attacks. This vulnerability is associated with program files… | ||
| CVE-2025-58107 | Hig | 0.49 | 7.5 | 0.00 | Mar 2, 2026 | In Microsoft Exchange through 2019, Exchange ActiveSync (EAS) configurations on on-premises servers may transmit sensitive data from Samsung mobile devices in cleartext, including the user's name, e-mail address, device ID, bearer token, and base64-encoded password. | ||
| CVE-2026-24455 | Hig | 0.49 | 7.5 | 0.00 | Feb 20, 2026 | The embedded web interface of the device does not support HTTPS/TLS for authentication and uses HTTP Basic Authentication. Traffic is encoded but not encrypted, exposing user credentials to passive interception by attackers on the same network. | ||
| CVE-2026-22271 | Hig | 0.49 | 7.5 | 0.00 | Jan 23, 2026 | Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains a Cleartext Transmission of Sensitive Information vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to… | ||
| CVE-2025-69272 | Hig | 0.49 | 7.5 | 0.00 | Jan 12, 2026 | Cleartext Transmission of Sensitive Information vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Sniffing Attacks.This issue affects DX NetOps Spectrum: 21.2.1 and earlier. | ||
| CVE-2020-36917 | — | Hig | 0.49 | 7.5 | 0.00 | Jan 6, 2026 | iDS6 DSSPro Digital Signage System 6.2 contains a sensitive information disclosure vulnerability that allows remote attackers to intercept authentication credentials through cleartext cookie transmission. Attackers can exploit the autoSave feature to capture user passwords… | |
| CVE-2020-36914 | Hig | 0.49 | 7.5 | 0.00 | Jan 6, 2026 | QiHang Media Web Digital Signage 3.0.9 contains a sensitive information disclosure vulnerability that allows remote attackers to intercept user authentication credentials through cleartext cookie transmission. Attackers can perform man-in-the-middle attacks to capture and… | ||
| CVE-2025-67159 | Hig | 0.49 | 7.5 | 0.00 | Jan 2, 2026 | Vatilon v1.12.37-20240124 was discovered to transmit user credentials in plaintext. | ||
| CVE-2025-62578 | Hig | 0.49 | 7.5 | 0.00 | Dec 26, 2025 | DVP-12SE - Modbus/TCP Cleartext Transmission of Sensitive Information | ||
| CVE-2025-66573 | Hig | 0.49 | 7.5 | 0.00 | Dec 4, 2025 | Solstice Pod API (version 5.5, 6.2) contains an unauthenticated API endpoint (`/api/config`) that exposes sensitive information such as the session key, server version, product details, and display name. Unauthorized users can extract live session information by accessing this… | ||
| CVE-2025-63364 | Hig | 0.49 | 7.5 | 0.00 | Dec 4, 2025 | Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.002880.0301 was discovered to transmit Administrator credentials in plaintext. | ||
| CVE-2025-62765 | Hig | 0.49 | 7.5 | 0.00 | Nov 15, 2025 | General Industrial Controls Lynx+ Gateway is vulnerable to a cleartext transmission vulnerability that could allow an attacker to observe network traffic to obtain sensitive information, including plaintext credentials. | ||
| CVE-2025-41718 | Hig | 0.49 | 7.5 | 0.00 | Oct 14, 2025 | A cleartext transmission of sensitive information vulnerability in the affected products allows an unauthorized remote attacker to gain login credentials and access the Web-UI. | ||
| CVE-2025-36274 | Hig | 0.49 | 7.5 | 0.00 | Sep 26, 2025 | IBM Aspera HTTP Gateway 2.0.0 through 2.3.1 stores sensitive information in clear text in easily obtainable files which can be read by an unauthenticated user. | ||
| CVE-2025-7731 | Hig | 0.49 | 7.5 | 0.00 | Sep 1, 2025 | Cleartext Transmission of Sensitive Information vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series CPU module allows a remote unauthenticated attacker to obtain credential information by intercepting SLMP communication messages, and read or write the device… | ||
| CVE-2025-53703 | Hig | 0.49 | 7.5 | 0.00 | Jul 22, 2025 | DuraComm SPM-500 DP-10iN-100-MU transmits sensitive data without encryption over a channel that could be intercepted by attackers. | ||
| CVE-2025-44251 | Hig | 0.49 | 7.5 | 0.00 | Jul 10, 2025 | Ecovacs Deebot T10 1.7.2 transmits Wi-Fi credentials in cleartext during the pairing process. | ||
| CVE-2025-49194 | Hig | 0.49 | 7.5 | 0.00 | Jun 12, 2025 | The server supports authentication methods in which credentials are sent in plaintext over unencrypted channels. If an attacker were to intercept traffic between a client and this server, the credentials would be exposed. | ||
| CVE-2025-49183 | Hig | 0.49 | 7.5 | 0.00 | Jun 12, 2025 | All communication with the REST API is unencrypted (HTTP), allowing an attacker to intercept traffic between an actor and the webserver. This leads to the possibility of information gathering and downloading media files. |
- risk 0.49cvss 7.5epss 0.00
An issue pertaining to CWE-319: Cleartext Transmission of Sensitive Information was discovered in Nexusoft NexusInterface v3.2.0-beta.2.
- risk 0.49cvss 7.5epss 0.00
Cleartext Transmission of Sensitive Information vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Heartbeat sync loop modules) allows Sniffing Attacks. This vulnerability is associated with program files…
- risk 0.49cvss 7.5epss 0.00
In Microsoft Exchange through 2019, Exchange ActiveSync (EAS) configurations on on-premises servers may transmit sensitive data from Samsung mobile devices in cleartext, including the user's name, e-mail address, device ID, bearer token, and base64-encoded password.
- risk 0.49cvss 7.5epss 0.00
The embedded web interface of the device does not support HTTPS/TLS for authentication and uses HTTP Basic Authentication. Traffic is encoded but not encrypted, exposing user credentials to passive interception by attackers on the same network.
- risk 0.49cvss 7.5epss 0.00
Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains a Cleartext Transmission of Sensitive Information vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to…
- risk 0.49cvss 7.5epss 0.00
Cleartext Transmission of Sensitive Information vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Sniffing Attacks.This issue affects DX NetOps Spectrum: 21.2.1 and earlier.
- risk 0.49cvss 7.5epss 0.00
iDS6 DSSPro Digital Signage System 6.2 contains a sensitive information disclosure vulnerability that allows remote attackers to intercept authentication credentials through cleartext cookie transmission. Attackers can exploit the autoSave feature to capture user passwords…
- risk 0.49cvss 7.5epss 0.00
QiHang Media Web Digital Signage 3.0.9 contains a sensitive information disclosure vulnerability that allows remote attackers to intercept user authentication credentials through cleartext cookie transmission. Attackers can perform man-in-the-middle attacks to capture and…
- risk 0.49cvss 7.5epss 0.00
Vatilon v1.12.37-20240124 was discovered to transmit user credentials in plaintext.
- risk 0.49cvss 7.5epss 0.00
DVP-12SE - Modbus/TCP Cleartext Transmission of Sensitive Information
- risk 0.49cvss 7.5epss 0.00
Solstice Pod API (version 5.5, 6.2) contains an unauthenticated API endpoint (`/api/config`) that exposes sensitive information such as the session key, server version, product details, and display name. Unauthorized users can extract live session information by accessing this…
- risk 0.49cvss 7.5epss 0.00
Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.002880.0301 was discovered to transmit Administrator credentials in plaintext.
- risk 0.49cvss 7.5epss 0.00
General Industrial Controls Lynx+ Gateway is vulnerable to a cleartext transmission vulnerability that could allow an attacker to observe network traffic to obtain sensitive information, including plaintext credentials.
- risk 0.49cvss 7.5epss 0.00
A cleartext transmission of sensitive information vulnerability in the affected products allows an unauthorized remote attacker to gain login credentials and access the Web-UI.
- risk 0.49cvss 7.5epss 0.00
IBM Aspera HTTP Gateway 2.0.0 through 2.3.1 stores sensitive information in clear text in easily obtainable files which can be read by an unauthenticated user.
- risk 0.49cvss 7.5epss 0.00
Cleartext Transmission of Sensitive Information vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series CPU module allows a remote unauthenticated attacker to obtain credential information by intercepting SLMP communication messages, and read or write the device…
- risk 0.49cvss 7.5epss 0.00
DuraComm SPM-500 DP-10iN-100-MU transmits sensitive data without encryption over a channel that could be intercepted by attackers.
- risk 0.49cvss 7.5epss 0.00
Ecovacs Deebot T10 1.7.2 transmits Wi-Fi credentials in cleartext during the pairing process.
- risk 0.49cvss 7.5epss 0.00
The server supports authentication methods in which credentials are sent in plaintext over unencrypted channels. If an attacker were to intercept traffic between a client and this server, the credentials would be exposed.
- risk 0.49cvss 7.5epss 0.00
All communication with the REST API is unencrypted (HTTP), allowing an attacker to intercept traffic between an actor and the webserver. This leads to the possibility of information gathering and downloading media files.