VYPR

CWE-319

Cleartext Transmission of Sensitive Information

BaseDraftLikelihood: High

Description

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-117 · CAPEC-383 · CAPEC-477 · CAPEC-65

CVEs mapped to this weakness (914)

page 13 of 46
  • CVE-2017-7252HigNov 3, 2023
    risk 0.49cvss 7.5epss 0.00

    bcrypt password hashing in Botan before 2.1.0 does not correctly handle passwords with a length between 57 and 72 characters, which makes it easier for attackers to determine the cleartext password.

  • CVE-2023-42147HigSep 20, 2023
    risk 0.49cvss 7.5epss 0.00

    An issue in CloudExplorer Lite 1.3.1 allows an attacker to obtain sensitive information via the login key component.

  • CVE-2023-39086HigAug 8, 2023
    risk 0.49cvss 7.5epss 0.00

    ASUS RT-AC66U B1 3.0.0.4.286_51665 was discovered to transmit sensitive information in cleartext.

  • CVE-2023-31823HigJul 13, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue found in Marui Co Marui Official app v.13.6.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp Marui Official Store function.

  • CVE-2023-3272HigJul 10, 2023
    risk 0.49cvss 7.5epss 0.01

    Cleartext Transmission of Sensitive Information in the SICK ICR890-4 could allow a remote attacker to gather sensitive information by intercepting network traffic that is not encrypted.

  • CVE-2023-21220HigJun 28, 2023
    risk 0.49cvss 7.5epss 0.00

    there is a possible use of unencrypted transport over cellular networks due to an insecure default value. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2023-21219HigJun 28, 2023
    risk 0.49cvss 7.5epss 0.00

    there is a possible use of unencrypted transport over cellular networks due to an insecure default value. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2023-23841HigJun 15, 2023
    risk 0.49cvss 7.5epss 0.00

    SolarWinds Serv-U is submitting an HTTP request when changing or updating the attributes for File Share or File request.  Part of the URL of the request discloses sensitive data.

  • CVE-2023-30602HigJun 2, 2023
    risk 0.49cvss 7.5epss 0.00

    Hitron Technologies CODA-5310’s Telnet function transfers sensitive data in plaintext. An unauthenticated remote attacker can exploit this vulnerability to access credentials of normal users and administrator.

  • CVE-2023-31193HigMay 22, 2023
    risk 0.49cvss 7.5epss 0.00

    Snap One OvrC Pro versions prior to 7.3 use HTTP connections when downloading a program from their servers. Because they do not use HTTPS, OvrC Pro devices are susceptible to exploitation.

  • CVE-2023-32784HigMay 15, 2023
    risk 0.49cvss 7.5epss 0.04

    In KeePass 2.x before 2.54, it is possible to recover the cleartext master password from a memory dump, even when a workspace is locked or no longer running. The memory dump can be a KeePass process dump, swap file (pagefile.sys), hibernation file (hiberfil.sys), or RAM dump of…

  • CVE-2023-32290HigMay 7, 2023
    risk 0.49cvss 7.5epss 0.00

    The myMail app through 14.30 for iOS sends cleartext credentials in a situation where STARTTLS is expected by a server.

  • CVE-2023-30515HigApr 12, 2023
    risk 0.49cvss 7.5epss 0.00

    Jenkins Thycotic DevOps Secrets Vault Plugin 1.0.0 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled.

  • CVE-2023-30514HigApr 12, 2023
    risk 0.49cvss 7.5epss 0.00

    Jenkins Azure Key Vault Plugin 187.va_cd5fecd198a_ and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled.

  • CVE-2023-30513HigApr 12, 2023
    risk 0.49cvss 7.5epss 0.00

    Jenkins Kubernetes Plugin 3909.v1f2c633e8590 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled.

  • CVE-2023-1656HigMar 29, 2023
    risk 0.49cvss 7.5epss 0.00

    Cleartext Transmission of Sensitive Information vulnerability in ForgeRock Inc. OpenIDM and Java Remote Connector Server (RCS) LDAP Connector on Windows, MacOS, Linux allows Remote Services with Stolen Credentials.This issue affects OpenIDM and Java Remote Connector Server…

  • CVE-2023-0053HigMar 2, 2023
    risk 0.49cvss 7.5epss 0.00

    SAUTER Controls Nova 200–220 Series with firmware version 3.3-006 and prior and BACnetstac version 4.2.1 and prior have only FTP and Telnet available for device management. Any sensitive information communicated through these protocols, such as credentials, is sent in…

  • CVE-2022-45546HigFeb 15, 2023
    risk 0.49cvss 7.5epss 0.01

    Information Disclosure in Authentication Component of ScreenCheck BadgeMaker 2.6.2.0 application allows internal attacker to obtain credentials for authentication via network sniffing.

  • CVE-2023-22806HigFeb 15, 2023
    risk 0.49cvss 7.5epss 0.00

    LS ELECTRIC XBC-DN32U with operating system version 01.80 transmits sensitive information in cleartext when communicating over its XGT protocol. This could allow an attacker to gain sensitive information such as user credentials.

  • CVE-2022-40693HigFeb 7, 2023
    risk 0.49cvss 7.5epss 0.01

    A cleartext transmission vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted network sniffing can lead to a disclosure of sensitive information. An attacker can sniff network traffic to trigger…