VYPR

CWE-319

Cleartext Transmission of Sensitive Information

BaseDraftLikelihood: High

Description

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-117 · CAPEC-383 · CAPEC-477 · CAPEC-65

CVEs mapped to this weakness (950)

page 12 of 48
  • CVE-2025-5270HigMay 27, 2025
    risk 0.49cvss 7.5epss 0.00

    In certain cases, SNI could have been sent unencrypted even when encrypted DNS was enabled. This vulnerability was fixed in Firefox 139 and Thunderbird 139.

  • CVE-2025-2861HigMar 28, 2025
    risk 0.49cvss 7.5epss 0.00

    SaTECH BCU in its firmware version 2.1.3 uses the HTTP protocol. The use of the HTTP protocol for web browsing has the problem that information is exchanged in unencrypted text. Since sensitive data such as credentials are exchanged, an attacker could obtain them and log in…

  • CVE-2025-27594HigMar 14, 2025
    risk 0.49cvss 7.5epss 0.00

    The device uses an unencrypted, proprietary protocol for communication. Through this protocol, configuration data is transmitted and device authentication is performed. An attacker can thereby intercept the authentication hash and use it to log into the device using a…

  • CVE-2024-13872HigMar 12, 2025
    risk 0.49cvss 7.5epss 0.00

    Bitdefender Box, versions 1.3.11.490 through 1.3.11.505, uses the insecure HTTP protocol to download assets over the Internet to update and restart daemons and detection rules on the devices. Updates can be remotely triggered through the /set_temp_token API method. Then, an…

  • CVE-2024-5462HigFeb 15, 2025
    risk 0.49cvss 7.5epss 0.00

    If Brocade Fabric OS before Fabric OS 9.2.0 configuration settings are not set to encrypt SNMP passwords, then the SNMP privsecret / authsecret fields can be exposed in plaintext. The plaintext passwords can be exposed in a configupload capture or a supportsave capture if…

  • CVE-2025-1060HigFeb 13, 2025
    risk 0.49cvss 7.5epss 0.00

    CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists that could result in the exposure of data when network traffic is being sniffed by an attacker.

  • CVE-2024-36558HigFeb 6, 2025
    risk 0.49cvss 7.5epss 0.00

    Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h suffers from Cleartext Transmission of Sensitive Information due to lack of encryption in device-server communication.

  • CVE-2024-49387HigOct 15, 2024
    risk 0.49cvss 7.5epss 0.00

    Cleartext transmission of sensitive information in acep-collector service. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690.

  • CVE-2024-48788HigOct 11, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue in YESCAM (com.yescom.YesCam.zwave) 1.0.2 allows a remote attacker to obtain sensitive information via the firmware update process.

  • CVE-2024-7713HigSep 27, 2024
    risk 0.49cvss 7.5epss 0.00

    The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 discloses the Open AI API Key, allowing unauthenticated users to obtain it

  • CVE-2024-38891HigAug 2, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Sniffing Network Traffic attack due to the cleartext transmission of sensitive information.

  • CVE-2024-41687HigJul 26, 2024
    risk 0.49cvss 7.5epss 0.00

    This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to transmission of password in plain text. A remote attacker could exploit this vulnerability by intercepting transmission within an HTTP session on the vulnerable system. Successful exploitation of this…

  • CVE-2024-37393HigJun 10, 2024
    risk 0.49cvss 7.5epss 0.03

    Multiple LDAP injections vulnerabilities exist in SecurEnvoy MFA before 9.4.514 due to improper validation of user-supplied input. An unauthenticated remote attacker could exfiltrate data from Active Directory through blind LDAP injection attacks against the DESKTOP service…

  • CVE-2024-36426HigMay 27, 2024
    risk 0.49cvss 7.5epss 0.00

    In TARGIT Decision Suite 23.2.15007.0 before Autumn 2023, the session token is part of the URL and may be sent in a cleartext HTTP session.

  • CVE-2024-35060HigMay 21, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue in the YAML Python library of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary commands via supplying a crafted YAML file.

  • CVE-2024-35059HigMay 21, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue in the Pickle Python library of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary commands.

  • CVE-2024-35058HigMay 21, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue in the API wait function of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary code via supplying a crafted string.

  • CVE-2024-35057HigMay 21, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue in NASA AIT-Core v2.5.2 allows attackers to execute arbitrary code via a crafted packet.

  • CVE-2024-21406HigFeb 13, 2024
    risk 0.49cvss 7.5epss 0.01

    Windows Printing Service Spoofing Vulnerability

  • CVE-2023-32328HigFeb 7, 2024
    risk 0.49cvss 7.5epss 0.01

    IBM Security Verify Access 10.0.0.0 through 10.0.6.1 uses insecure protocols in some instances that could allow an attacker on the network to take control of the server. IBM X-Force Id: 254957.