VYPR

CWE-319

Cleartext Transmission of Sensitive Information

BaseDraftLikelihood: High

Description

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-117 · CAPEC-383 · CAPEC-477 · CAPEC-65

CVEs mapped to this weakness (950)

page 13 of 48
  • CVE-2023-50614HigJan 18, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue discovereed in EBYTE E880-IR01-V1.1 allows an attacker to obtain sensitive information via crafted POST request to /cgi-bin/luci.

  • CVE-2023-51741HigJan 17, 2024
    risk 0.49cvss 7.5epss 0.00

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to transmission of authentication credentials in plaintext over the network. A remote attacker could exploit this vulnerability by eavesdropping on the victim’s network traffic to extract username and…

  • CVE-2023-51740HigJan 17, 2024
    risk 0.49cvss 7.5epss 0.00

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to transmission of authentication credentials in plaintext over the network. A remote attacker could exploit this vulnerability by eavesdropping on the victim’s network traffic to extract username and…

  • CVE-2023-31300HigDec 29, 2023
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive information via transmission of unencrypted, cleartext credentials during Password Reset feature.

  • CVE-2023-28616HigDec 26, 2023
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in Stormshield Network Security (SNS) before 4.3.17, 4.4.x through 4.6.x before 4.6.4, and 4.7.x before 4.7.1. It affects user accounts for which the password has an equals sign or space character. The serverd process logs such passwords in cleartext, and…

  • CVE-2023-46385HigNov 30, 2023
    risk 0.49cvss 7.5epss 0.01

    LOYTEC electronics GmbH LINX Configurator (all versions) is vulnerable to Insecure Permissions. An admin credential is passed as a value of URL parameters without encryption, so it allows remote attackers to steal the password and gain full control of Loytec device configuration.

  • CVE-2023-46383HigNov 30, 2023
    risk 0.49cvss 7.5epss 0.01

    LOYTEC electronics GmbH LINX Configurator (all versions) uses HTTP Basic Authentication, which transmits usernames and passwords in base64-encoded cleartext and allows remote attackers to steal the password and gain full control of Loytec device configuration.

  • CVE-2023-46382HigNov 4, 2023
    risk 0.49cvss 7.5epss 0.03

    LOYTEC LINX-151, LINX-212, LVIS-3ME12-A1, LIOB-586, LIOB-580 V2, LIOB-588, L-INX Configurator devices (all versions) use cleartext HTTP for login.

  • CVE-2023-46380HigNov 4, 2023
    risk 0.49cvss 7.5epss 0.03

    LOYTEC LINX-151, LINX-212, LVIS-3ME12-A1, LIOB-586, LIOB-580 V2, LIOB-588, L-INX Configurator devices (all versions) send password-change requests via cleartext HTTP.

  • CVE-2017-7252HigNov 3, 2023
    risk 0.49cvss 7.5epss 0.00

    bcrypt password hashing in Botan before 2.1.0 does not correctly handle passwords with a length between 57 and 72 characters, which makes it easier for attackers to determine the cleartext password.

  • CVE-2023-42147HigSep 20, 2023
    risk 0.49cvss 7.5epss 0.00

    An issue in CloudExplorer Lite 1.3.1 allows an attacker to obtain sensitive information via the login key component.

  • CVE-2023-39086HigAug 8, 2023
    risk 0.49cvss 7.5epss 0.00

    ASUS RT-AC66U B1 3.0.0.4.286_51665 was discovered to transmit sensitive information in cleartext.

  • CVE-2023-31823HigJul 13, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue found in Marui Co Marui Official app v.13.6.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp Marui Official Store function.

  • CVE-2023-3272HigJul 10, 2023
    risk 0.49cvss 7.5epss 0.01

    Cleartext Transmission of Sensitive Information in the SICK ICR890-4 could allow a remote attacker to gather sensitive information by intercepting network traffic that is not encrypted.

  • CVE-2023-21220HigJun 28, 2023
    risk 0.49cvss 7.5epss 0.00

    there is a possible use of unencrypted transport over cellular networks due to an insecure default value. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2023-21219HigJun 28, 2023
    risk 0.49cvss 7.5epss 0.00

    there is a possible use of unencrypted transport over cellular networks due to an insecure default value. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2023-23841HigJun 15, 2023
    risk 0.49cvss 7.5epss 0.00

    SolarWinds Serv-U is submitting an HTTP request when changing or updating the attributes for File Share or File request.  Part of the URL of the request discloses sensitive data.

  • CVE-2023-30602HigJun 2, 2023
    risk 0.49cvss 7.5epss 0.00

    Hitron Technologies CODA-5310’s Telnet function transfers sensitive data in plaintext. An unauthenticated remote attacker can exploit this vulnerability to access credentials of normal users and administrator.

  • CVE-2023-31193HigMay 22, 2023
    risk 0.49cvss 7.5epss 0.00

    Snap One OvrC Pro versions prior to 7.3 use HTTP connections when downloading a program from their servers. Because they do not use HTTPS, OvrC Pro devices are susceptible to exploitation.

  • CVE-2023-32784HigMay 15, 2023
    risk 0.49cvss 7.5epss 0.04

    In KeePass 2.x before 2.54, it is possible to recover the cleartext master password from a memory dump, even when a workspace is locked or no longer running. The memory dump can be a KeePass process dump, swap file (pagefile.sys), hibernation file (hiberfil.sys), or RAM dump of…