VYPR

CWE-319

Cleartext Transmission of Sensitive Information

BaseDraftLikelihood: High

Description

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-117 · CAPEC-383 · CAPEC-477 · CAPEC-65

CVEs mapped to this weakness (914)

page 11 of 46
  • CVE-2025-62578HigDec 26, 2025
    risk 0.49cvss 7.5epss 0.00

    DVP-12SE - Modbus/TCP Cleartext Transmission of Sensitive Information

  • CVE-2025-66573HigDec 4, 2025
    risk 0.49cvss 7.5epss 0.00

    Solstice Pod API (version 5.5, 6.2) contains an unauthenticated API endpoint (`/api/config`) that exposes sensitive information such as the session key, server version, product details, and display name. Unauthorized users can extract live session information by accessing this…

  • CVE-2025-63364HigDec 4, 2025
    risk 0.49cvss 7.5epss 0.00

    Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.002880.0301 was discovered to transmit Administrator credentials in plaintext.

  • CVE-2025-62765HigNov 15, 2025
    risk 0.49cvss 7.5epss 0.00

    General Industrial Controls Lynx+ Gateway is vulnerable to a cleartext transmission vulnerability that could allow an attacker to observe network traffic to obtain sensitive information, including plaintext credentials.

  • CVE-2025-41718HigOct 14, 2025
    risk 0.49cvss 7.5epss 0.00

    A cleartext transmission of sensitive information vulnerability in the affected products allows an unauthorized remote attacker to gain login credentials and access the Web-UI.

  • CVE-2025-36274HigSep 26, 2025
    risk 0.49cvss 7.5epss 0.00

    IBM Aspera HTTP Gateway 2.0.0 through 2.3.1 stores sensitive information in clear text in easily obtainable files which can be read by an unauthenticated user.

  • CVE-2025-7731HigSep 1, 2025
    risk 0.49cvss 7.5epss 0.00

    Cleartext Transmission of Sensitive Information vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series CPU module allows a remote unauthenticated attacker to obtain credential information by intercepting SLMP communication messages, and read or write the device…

  • CVE-2025-53703HigJul 22, 2025
    risk 0.49cvss 7.5epss 0.00

    DuraComm SPM-500 DP-10iN-100-MU transmits sensitive data without encryption over a channel that could be intercepted by attackers.

  • CVE-2025-44251HigJul 10, 2025
    risk 0.49cvss 7.5epss 0.00

    Ecovacs Deebot T10 1.7.2 transmits Wi-Fi credentials in cleartext during the pairing process.

  • CVE-2025-49194HigJun 12, 2025
    risk 0.49cvss 7.5epss 0.00

    The server supports authentication methods in which credentials are sent in plaintext over unencrypted channels. If an attacker were to intercept traffic between a client and this server, the credentials would be exposed.

  • CVE-2025-49183HigJun 12, 2025
    risk 0.49cvss 7.5epss 0.00

    All communication with the REST API is unencrypted (HTTP), allowing an attacker to intercept traffic between an actor and the webserver. This leads to the possibility of information gathering and downloading media files.

  • CVE-2025-5270HigMay 27, 2025
    risk 0.49cvss 7.5epss 0.00

    In certain cases, SNI could have been sent unencrypted even when encrypted DNS was enabled. This vulnerability was fixed in Firefox 139 and Thunderbird 139.

  • CVE-2025-2861HigMar 28, 2025
    risk 0.49cvss 7.5epss 0.00

    SaTECH BCU in its firmware version 2.1.3 uses the HTTP protocol. The use of the HTTP protocol for web browsing has the problem that information is exchanged in unencrypted text. Since sensitive data such as credentials are exchanged, an attacker could obtain them and log in…

  • CVE-2025-27594HigMar 14, 2025
    risk 0.49cvss 7.5epss 0.00

    The device uses an unencrypted, proprietary protocol for communication. Through this protocol, configuration data is transmitted and device authentication is performed. An attacker can thereby intercept the authentication hash and use it to log into the device using a…

  • CVE-2024-13872HigMar 12, 2025
    risk 0.49cvss 7.5epss 0.00

    Bitdefender Box, versions 1.3.11.490 through 1.3.11.505, uses the insecure HTTP protocol to download assets over the Internet to update and restart daemons and detection rules on the devices. Updates can be remotely triggered through the /set_temp_token API method. Then, an…

  • CVE-2024-5462HigFeb 15, 2025
    risk 0.49cvss 7.5epss 0.00

    If Brocade Fabric OS before Fabric OS 9.2.0 configuration settings are not set to encrypt SNMP passwords, then the SNMP privsecret / authsecret fields can be exposed in plaintext. The plaintext passwords can be exposed in a configupload capture or a supportsave capture if…

  • CVE-2025-1060HigFeb 13, 2025
    risk 0.49cvss 7.5epss 0.00

    CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists that could result in the exposure of data when network traffic is being sniffed by an attacker.

  • CVE-2024-36558HigFeb 6, 2025
    risk 0.49cvss 7.5epss 0.00

    Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h suffers from Cleartext Transmission of Sensitive Information due to lack of encryption in device-server communication.

  • CVE-2024-49387HigOct 15, 2024
    risk 0.49cvss 7.5epss 0.00

    Cleartext transmission of sensitive information in acep-collector service. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690.

  • CVE-2024-48788HigOct 11, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue in YESCAM (com.yescom.YesCam.zwave) 1.0.2 allows a remote attacker to obtain sensitive information via the firmware update process.