CWE-319
Cleartext Transmission of Sensitive Information
Description
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-102 · CAPEC-117 · CAPEC-383 · CAPEC-477 · CAPEC-65
CVEs mapped to this weakness (950)
page 12 of 48| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-5270 | Hig | 0.49 | 7.5 | 0.00 | May 27, 2025 | In certain cases, SNI could have been sent unencrypted even when encrypted DNS was enabled. This vulnerability was fixed in Firefox 139 and Thunderbird 139. | ||
| CVE-2025-2861 | Hig | 0.49 | 7.5 | 0.00 | Mar 28, 2025 | SaTECH BCU in its firmware version 2.1.3 uses the HTTP protocol. The use of the HTTP protocol for web browsing has the problem that information is exchanged in unencrypted text. Since sensitive data such as credentials are exchanged, an attacker could obtain them and log in… | ||
| CVE-2025-27594 | Hig | 0.49 | 7.5 | 0.00 | Mar 14, 2025 | The device uses an unencrypted, proprietary protocol for communication. Through this protocol, configuration data is transmitted and device authentication is performed. An attacker can thereby intercept the authentication hash and use it to log into the device using a… | ||
| CVE-2024-13872 | Hig | 0.49 | 7.5 | 0.00 | Mar 12, 2025 | Bitdefender Box, versions 1.3.11.490 through 1.3.11.505, uses the insecure HTTP protocol to download assets over the Internet to update and restart daemons and detection rules on the devices. Updates can be remotely triggered through the /set_temp_token API method. Then, an… | ||
| CVE-2024-5462 | Hig | 0.49 | 7.5 | 0.00 | Feb 15, 2025 | If Brocade Fabric OS before Fabric OS 9.2.0 configuration settings are not set to encrypt SNMP passwords, then the SNMP privsecret / authsecret fields can be exposed in plaintext. The plaintext passwords can be exposed in a configupload capture or a supportsave capture if… | ||
| CVE-2025-1060 | Hig | 0.49 | 7.5 | 0.00 | Feb 13, 2025 | CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists that could result in the exposure of data when network traffic is being sniffed by an attacker. | ||
| CVE-2024-36558 | Hig | 0.49 | 7.5 | 0.00 | Feb 6, 2025 | Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h suffers from Cleartext Transmission of Sensitive Information due to lack of encryption in device-server communication. | ||
| CVE-2024-49387 | Hig | 0.49 | 7.5 | 0.00 | Oct 15, 2024 | Cleartext transmission of sensitive information in acep-collector service. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690. | ||
| CVE-2024-48788 | Hig | 0.49 | 7.5 | 0.01 | Oct 11, 2024 | An issue in YESCAM (com.yescom.YesCam.zwave) 1.0.2 allows a remote attacker to obtain sensitive information via the firmware update process. | ||
| CVE-2024-7713 | Hig | 0.49 | 7.5 | 0.00 | Sep 27, 2024 | The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 discloses the Open AI API Key, allowing unauthenticated users to obtain it | ||
| CVE-2024-38891 | Hig | 0.49 | 7.5 | 0.00 | Aug 2, 2024 | An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Sniffing Network Traffic attack due to the cleartext transmission of sensitive information. | ||
| CVE-2024-41687 | Hig | 0.49 | 7.5 | 0.00 | Jul 26, 2024 | This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to transmission of password in plain text. A remote attacker could exploit this vulnerability by intercepting transmission within an HTTP session on the vulnerable system. Successful exploitation of this… | ||
| CVE-2024-37393 | Hig | 0.49 | 7.5 | 0.03 | Jun 10, 2024 | Multiple LDAP injections vulnerabilities exist in SecurEnvoy MFA before 9.4.514 due to improper validation of user-supplied input. An unauthenticated remote attacker could exfiltrate data from Active Directory through blind LDAP injection attacks against the DESKTOP service… | ||
| CVE-2024-36426 | Hig | 0.49 | 7.5 | 0.00 | May 27, 2024 | In TARGIT Decision Suite 23.2.15007.0 before Autumn 2023, the session token is part of the URL and may be sent in a cleartext HTTP session. | ||
| CVE-2024-35060 | Hig | 0.49 | 7.5 | 0.00 | May 21, 2024 | An issue in the YAML Python library of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary commands via supplying a crafted YAML file. | ||
| CVE-2024-35059 | Hig | 0.49 | 7.5 | 0.00 | May 21, 2024 | An issue in the Pickle Python library of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary commands. | ||
| CVE-2024-35058 | Hig | 0.49 | 7.5 | 0.00 | May 21, 2024 | An issue in the API wait function of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary code via supplying a crafted string. | ||
| CVE-2024-35057 | Hig | 0.49 | 7.5 | 0.00 | May 21, 2024 | An issue in NASA AIT-Core v2.5.2 allows attackers to execute arbitrary code via a crafted packet. | ||
| CVE-2024-21406 | Hig | 0.49 | 7.5 | 0.01 | Feb 13, 2024 | Windows Printing Service Spoofing Vulnerability | ||
| CVE-2023-32328 | Hig | 0.49 | 7.5 | 0.01 | Feb 7, 2024 | IBM Security Verify Access 10.0.0.0 through 10.0.6.1 uses insecure protocols in some instances that could allow an attacker on the network to take control of the server. IBM X-Force Id: 254957. |
- risk 0.49cvss 7.5epss 0.00
In certain cases, SNI could have been sent unencrypted even when encrypted DNS was enabled. This vulnerability was fixed in Firefox 139 and Thunderbird 139.
- risk 0.49cvss 7.5epss 0.00
SaTECH BCU in its firmware version 2.1.3 uses the HTTP protocol. The use of the HTTP protocol for web browsing has the problem that information is exchanged in unencrypted text. Since sensitive data such as credentials are exchanged, an attacker could obtain them and log in…
- risk 0.49cvss 7.5epss 0.00
The device uses an unencrypted, proprietary protocol for communication. Through this protocol, configuration data is transmitted and device authentication is performed. An attacker can thereby intercept the authentication hash and use it to log into the device using a…
- risk 0.49cvss 7.5epss 0.00
Bitdefender Box, versions 1.3.11.490 through 1.3.11.505, uses the insecure HTTP protocol to download assets over the Internet to update and restart daemons and detection rules on the devices. Updates can be remotely triggered through the /set_temp_token API method. Then, an…
- risk 0.49cvss 7.5epss 0.00
If Brocade Fabric OS before Fabric OS 9.2.0 configuration settings are not set to encrypt SNMP passwords, then the SNMP privsecret / authsecret fields can be exposed in plaintext. The plaintext passwords can be exposed in a configupload capture or a supportsave capture if…
- risk 0.49cvss 7.5epss 0.00
CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists that could result in the exposure of data when network traffic is being sniffed by an attacker.
- risk 0.49cvss 7.5epss 0.00
Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h suffers from Cleartext Transmission of Sensitive Information due to lack of encryption in device-server communication.
- risk 0.49cvss 7.5epss 0.00
Cleartext transmission of sensitive information in acep-collector service. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690.
- risk 0.49cvss 7.5epss 0.01
An issue in YESCAM (com.yescom.YesCam.zwave) 1.0.2 allows a remote attacker to obtain sensitive information via the firmware update process.
- risk 0.49cvss 7.5epss 0.00
The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 discloses the Open AI API Key, allowing unauthenticated users to obtain it
- risk 0.49cvss 7.5epss 0.00
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Sniffing Network Traffic attack due to the cleartext transmission of sensitive information.
- risk 0.49cvss 7.5epss 0.00
This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to transmission of password in plain text. A remote attacker could exploit this vulnerability by intercepting transmission within an HTTP session on the vulnerable system. Successful exploitation of this…
- risk 0.49cvss 7.5epss 0.03
Multiple LDAP injections vulnerabilities exist in SecurEnvoy MFA before 9.4.514 due to improper validation of user-supplied input. An unauthenticated remote attacker could exfiltrate data from Active Directory through blind LDAP injection attacks against the DESKTOP service…
- risk 0.49cvss 7.5epss 0.00
In TARGIT Decision Suite 23.2.15007.0 before Autumn 2023, the session token is part of the URL and may be sent in a cleartext HTTP session.
- risk 0.49cvss 7.5epss 0.00
An issue in the YAML Python library of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary commands via supplying a crafted YAML file.
- risk 0.49cvss 7.5epss 0.00
An issue in the Pickle Python library of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary commands.
- risk 0.49cvss 7.5epss 0.00
An issue in the API wait function of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary code via supplying a crafted string.
- risk 0.49cvss 7.5epss 0.00
An issue in NASA AIT-Core v2.5.2 allows attackers to execute arbitrary code via a crafted packet.
- risk 0.49cvss 7.5epss 0.01
Windows Printing Service Spoofing Vulnerability
- risk 0.49cvss 7.5epss 0.01
IBM Security Verify Access 10.0.0.0 through 10.0.6.1 uses insecure protocols in some instances that could allow an attacker on the network to take control of the server. IBM X-Force Id: 254957.