CWE-319
Cleartext Transmission of Sensitive Information
Description
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-102 · CAPEC-117 · CAPEC-383 · CAPEC-477 · CAPEC-65
CVEs mapped to this weakness (914)
page 12 of 46| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-7713 | Hig | 0.49 | 7.5 | 0.00 | Sep 27, 2024 | The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 discloses the Open AI API Key, allowing unauthenticated users to obtain it | ||
| CVE-2024-38891 | Hig | 0.49 | 7.5 | 0.00 | Aug 2, 2024 | An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Sniffing Network Traffic attack due to the cleartext transmission of sensitive information. | ||
| CVE-2024-41687 | Hig | 0.49 | 7.5 | 0.00 | Jul 26, 2024 | This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to transmission of password in plain text. A remote attacker could exploit this vulnerability by intercepting transmission within an HTTP session on the vulnerable system. Successful exploitation of this… | ||
| CVE-2024-37393 | Hig | 0.49 | 7.5 | 0.03 | Jun 10, 2024 | Multiple LDAP injections vulnerabilities exist in SecurEnvoy MFA before 9.4.514 due to improper validation of user-supplied input. An unauthenticated remote attacker could exfiltrate data from Active Directory through blind LDAP injection attacks against the DESKTOP service… | ||
| CVE-2024-36426 | Hig | 0.49 | 7.5 | 0.00 | May 27, 2024 | In TARGIT Decision Suite 23.2.15007.0 before Autumn 2023, the session token is part of the URL and may be sent in a cleartext HTTP session. | ||
| CVE-2024-35060 | Hig | 0.49 | 7.5 | 0.00 | May 21, 2024 | An issue in the YAML Python library of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary commands via supplying a crafted YAML file. | ||
| CVE-2024-35059 | Hig | 0.49 | 7.5 | 0.00 | May 21, 2024 | An issue in the Pickle Python library of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary commands. | ||
| CVE-2024-35058 | Hig | 0.49 | 7.5 | 0.00 | May 21, 2024 | An issue in the API wait function of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary code via supplying a crafted string. | ||
| CVE-2024-35057 | Hig | 0.49 | 7.5 | 0.00 | May 21, 2024 | An issue in NASA AIT-Core v2.5.2 allows attackers to execute arbitrary code via a crafted packet. | ||
| CVE-2024-21406 | Hig | 0.49 | 7.5 | 0.01 | Feb 13, 2024 | Windows Printing Service Spoofing Vulnerability | ||
| CVE-2023-32328 | Hig | 0.49 | 7.5 | 0.01 | Feb 7, 2024 | IBM Security Verify Access 10.0.0.0 through 10.0.6.1 uses insecure protocols in some instances that could allow an attacker on the network to take control of the server. IBM X-Force Id: 254957. | ||
| CVE-2023-50614 | Hig | 0.49 | 7.5 | 0.00 | Jan 18, 2024 | An issue discovereed in EBYTE E880-IR01-V1.1 allows an attacker to obtain sensitive information via crafted POST request to /cgi-bin/luci. | ||
| CVE-2023-51741 | Hig | 0.49 | 7.5 | 0.00 | Jan 17, 2024 | This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to transmission of authentication credentials in plaintext over the network. A remote attacker could exploit this vulnerability by eavesdropping on the victim’s network traffic to extract username and… | ||
| CVE-2023-51740 | Hig | 0.49 | 7.5 | 0.00 | Jan 17, 2024 | This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to transmission of authentication credentials in plaintext over the network. A remote attacker could exploit this vulnerability by eavesdropping on the victim’s network traffic to extract username and… | ||
| CVE-2023-31300 | Hig | 0.49 | 7.5 | 0.00 | Dec 29, 2023 | An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive information via transmission of unencrypted, cleartext credentials during Password Reset feature. | ||
| CVE-2023-28616 | Hig | 0.49 | 7.5 | 0.00 | Dec 26, 2023 | An issue was discovered in Stormshield Network Security (SNS) before 4.3.17, 4.4.x through 4.6.x before 4.6.4, and 4.7.x before 4.7.1. It affects user accounts for which the password has an equals sign or space character. The serverd process logs such passwords in cleartext, and… | ||
| CVE-2023-46385 | Hig | 0.49 | 7.5 | 0.01 | Nov 30, 2023 | LOYTEC electronics GmbH LINX Configurator (all versions) is vulnerable to Insecure Permissions. An admin credential is passed as a value of URL parameters without encryption, so it allows remote attackers to steal the password and gain full control of Loytec device configuration. | ||
| CVE-2023-46383 | Hig | 0.49 | 7.5 | 0.01 | Nov 30, 2023 | LOYTEC electronics GmbH LINX Configurator (all versions) uses HTTP Basic Authentication, which transmits usernames and passwords in base64-encoded cleartext and allows remote attackers to steal the password and gain full control of Loytec device configuration. | ||
| CVE-2023-46382 | Hig | 0.49 | 7.5 | 0.03 | Nov 4, 2023 | LOYTEC LINX-151, LINX-212, LVIS-3ME12-A1, LIOB-586, LIOB-580 V2, LIOB-588, L-INX Configurator devices (all versions) use cleartext HTTP for login. | ||
| CVE-2023-46380 | Hig | 0.49 | 7.5 | 0.03 | Nov 4, 2023 | LOYTEC LINX-151, LINX-212, LVIS-3ME12-A1, LIOB-586, LIOB-580 V2, LIOB-588, L-INX Configurator devices (all versions) send password-change requests via cleartext HTTP. |
- risk 0.49cvss 7.5epss 0.00
The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 discloses the Open AI API Key, allowing unauthenticated users to obtain it
- risk 0.49cvss 7.5epss 0.00
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Sniffing Network Traffic attack due to the cleartext transmission of sensitive information.
- risk 0.49cvss 7.5epss 0.00
This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to transmission of password in plain text. A remote attacker could exploit this vulnerability by intercepting transmission within an HTTP session on the vulnerable system. Successful exploitation of this…
- risk 0.49cvss 7.5epss 0.03
Multiple LDAP injections vulnerabilities exist in SecurEnvoy MFA before 9.4.514 due to improper validation of user-supplied input. An unauthenticated remote attacker could exfiltrate data from Active Directory through blind LDAP injection attacks against the DESKTOP service…
- risk 0.49cvss 7.5epss 0.00
In TARGIT Decision Suite 23.2.15007.0 before Autumn 2023, the session token is part of the URL and may be sent in a cleartext HTTP session.
- risk 0.49cvss 7.5epss 0.00
An issue in the YAML Python library of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary commands via supplying a crafted YAML file.
- risk 0.49cvss 7.5epss 0.00
An issue in the Pickle Python library of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary commands.
- risk 0.49cvss 7.5epss 0.00
An issue in the API wait function of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary code via supplying a crafted string.
- risk 0.49cvss 7.5epss 0.00
An issue in NASA AIT-Core v2.5.2 allows attackers to execute arbitrary code via a crafted packet.
- risk 0.49cvss 7.5epss 0.01
Windows Printing Service Spoofing Vulnerability
- risk 0.49cvss 7.5epss 0.01
IBM Security Verify Access 10.0.0.0 through 10.0.6.1 uses insecure protocols in some instances that could allow an attacker on the network to take control of the server. IBM X-Force Id: 254957.
- risk 0.49cvss 7.5epss 0.00
An issue discovereed in EBYTE E880-IR01-V1.1 allows an attacker to obtain sensitive information via crafted POST request to /cgi-bin/luci.
- risk 0.49cvss 7.5epss 0.00
This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to transmission of authentication credentials in plaintext over the network. A remote attacker could exploit this vulnerability by eavesdropping on the victim’s network traffic to extract username and…
- risk 0.49cvss 7.5epss 0.00
This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to transmission of authentication credentials in plaintext over the network. A remote attacker could exploit this vulnerability by eavesdropping on the victim’s network traffic to extract username and…
- risk 0.49cvss 7.5epss 0.00
An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive information via transmission of unencrypted, cleartext credentials during Password Reset feature.
- risk 0.49cvss 7.5epss 0.00
An issue was discovered in Stormshield Network Security (SNS) before 4.3.17, 4.4.x through 4.6.x before 4.6.4, and 4.7.x before 4.7.1. It affects user accounts for which the password has an equals sign or space character. The serverd process logs such passwords in cleartext, and…
- risk 0.49cvss 7.5epss 0.01
LOYTEC electronics GmbH LINX Configurator (all versions) is vulnerable to Insecure Permissions. An admin credential is passed as a value of URL parameters without encryption, so it allows remote attackers to steal the password and gain full control of Loytec device configuration.
- risk 0.49cvss 7.5epss 0.01
LOYTEC electronics GmbH LINX Configurator (all versions) uses HTTP Basic Authentication, which transmits usernames and passwords in base64-encoded cleartext and allows remote attackers to steal the password and gain full control of Loytec device configuration.
- risk 0.49cvss 7.5epss 0.03
LOYTEC LINX-151, LINX-212, LVIS-3ME12-A1, LIOB-586, LIOB-580 V2, LIOB-588, L-INX Configurator devices (all versions) use cleartext HTTP for login.
- risk 0.49cvss 7.5epss 0.03
LOYTEC LINX-151, LINX-212, LVIS-3ME12-A1, LIOB-586, LIOB-580 V2, LIOB-588, L-INX Configurator devices (all versions) send password-change requests via cleartext HTTP.