VYPR

CWE-319

Cleartext Transmission of Sensitive Information

BaseDraftLikelihood: High

Description

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-117 · CAPEC-383 · CAPEC-477 · CAPEC-65

CVEs mapped to this weakness (914)

page 12 of 46
  • CVE-2024-7713HigSep 27, 2024
    risk 0.49cvss 7.5epss 0.00

    The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 discloses the Open AI API Key, allowing unauthenticated users to obtain it

  • CVE-2024-38891HigAug 2, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Sniffing Network Traffic attack due to the cleartext transmission of sensitive information.

  • CVE-2024-41687HigJul 26, 2024
    risk 0.49cvss 7.5epss 0.00

    This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to transmission of password in plain text. A remote attacker could exploit this vulnerability by intercepting transmission within an HTTP session on the vulnerable system. Successful exploitation of this…

  • CVE-2024-37393HigJun 10, 2024
    risk 0.49cvss 7.5epss 0.03

    Multiple LDAP injections vulnerabilities exist in SecurEnvoy MFA before 9.4.514 due to improper validation of user-supplied input. An unauthenticated remote attacker could exfiltrate data from Active Directory through blind LDAP injection attacks against the DESKTOP service…

  • CVE-2024-36426HigMay 27, 2024
    risk 0.49cvss 7.5epss 0.00

    In TARGIT Decision Suite 23.2.15007.0 before Autumn 2023, the session token is part of the URL and may be sent in a cleartext HTTP session.

  • CVE-2024-35060HigMay 21, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue in the YAML Python library of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary commands via supplying a crafted YAML file.

  • CVE-2024-35059HigMay 21, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue in the Pickle Python library of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary commands.

  • CVE-2024-35058HigMay 21, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue in the API wait function of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary code via supplying a crafted string.

  • CVE-2024-35057HigMay 21, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue in NASA AIT-Core v2.5.2 allows attackers to execute arbitrary code via a crafted packet.

  • CVE-2024-21406HigFeb 13, 2024
    risk 0.49cvss 7.5epss 0.01

    Windows Printing Service Spoofing Vulnerability

  • CVE-2023-32328HigFeb 7, 2024
    risk 0.49cvss 7.5epss 0.01

    IBM Security Verify Access 10.0.0.0 through 10.0.6.1 uses insecure protocols in some instances that could allow an attacker on the network to take control of the server. IBM X-Force Id: 254957.

  • CVE-2023-50614HigJan 18, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue discovereed in EBYTE E880-IR01-V1.1 allows an attacker to obtain sensitive information via crafted POST request to /cgi-bin/luci.

  • CVE-2023-51741HigJan 17, 2024
    risk 0.49cvss 7.5epss 0.00

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to transmission of authentication credentials in plaintext over the network. A remote attacker could exploit this vulnerability by eavesdropping on the victim’s network traffic to extract username and…

  • CVE-2023-51740HigJan 17, 2024
    risk 0.49cvss 7.5epss 0.00

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to transmission of authentication credentials in plaintext over the network. A remote attacker could exploit this vulnerability by eavesdropping on the victim’s network traffic to extract username and…

  • CVE-2023-31300HigDec 29, 2023
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive information via transmission of unencrypted, cleartext credentials during Password Reset feature.

  • CVE-2023-28616HigDec 26, 2023
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in Stormshield Network Security (SNS) before 4.3.17, 4.4.x through 4.6.x before 4.6.4, and 4.7.x before 4.7.1. It affects user accounts for which the password has an equals sign or space character. The serverd process logs such passwords in cleartext, and…

  • CVE-2023-46385HigNov 30, 2023
    risk 0.49cvss 7.5epss 0.01

    LOYTEC electronics GmbH LINX Configurator (all versions) is vulnerable to Insecure Permissions. An admin credential is passed as a value of URL parameters without encryption, so it allows remote attackers to steal the password and gain full control of Loytec device configuration.

  • CVE-2023-46383HigNov 30, 2023
    risk 0.49cvss 7.5epss 0.01

    LOYTEC electronics GmbH LINX Configurator (all versions) uses HTTP Basic Authentication, which transmits usernames and passwords in base64-encoded cleartext and allows remote attackers to steal the password and gain full control of Loytec device configuration.

  • CVE-2023-46382HigNov 4, 2023
    risk 0.49cvss 7.5epss 0.03

    LOYTEC LINX-151, LINX-212, LVIS-3ME12-A1, LIOB-586, LIOB-580 V2, LIOB-588, L-INX Configurator devices (all versions) use cleartext HTTP for login.

  • CVE-2023-46380HigNov 4, 2023
    risk 0.49cvss 7.5epss 0.03

    LOYTEC LINX-151, LINX-212, LVIS-3ME12-A1, LIOB-586, LIOB-580 V2, LIOB-588, L-INX Configurator devices (all versions) send password-change requests via cleartext HTTP.