VYPR

CWE-319

Cleartext Transmission of Sensitive Information

BaseDraftLikelihood: High

Description

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-117 · CAPEC-383 · CAPEC-477 · CAPEC-65

CVEs mapped to this weakness (950)

page 14 of 48
  • CVE-2023-32290HigMay 7, 2023
    risk 0.49cvss 7.5epss 0.00

    The myMail app through 14.30 for iOS sends cleartext credentials in a situation where STARTTLS is expected by a server.

  • CVE-2023-30515HigApr 12, 2023
    risk 0.49cvss 7.5epss 0.00

    Jenkins Thycotic DevOps Secrets Vault Plugin 1.0.0 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled.

  • CVE-2023-30514HigApr 12, 2023
    risk 0.49cvss 7.5epss 0.00

    Jenkins Azure Key Vault Plugin 187.va_cd5fecd198a_ and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled.

  • CVE-2023-30513HigApr 12, 2023
    risk 0.49cvss 7.5epss 0.00

    Jenkins Kubernetes Plugin 3909.v1f2c633e8590 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled.

  • CVE-2023-1656HigMar 29, 2023
    risk 0.49cvss 7.5epss 0.00

    Cleartext Transmission of Sensitive Information vulnerability in ForgeRock Inc. OpenIDM and Java Remote Connector Server (RCS) LDAP Connector on Windows, MacOS, Linux allows Remote Services with Stolen Credentials.This issue affects OpenIDM and Java Remote Connector Server…

  • CVE-2023-0053HigMar 2, 2023
    risk 0.49cvss 7.5epss 0.00

    SAUTER Controls Nova 200–220 Series with firmware version 3.3-006 and prior and BACnetstac version 4.2.1 and prior have only FTP and Telnet available for device management. Any sensitive information communicated through these protocols, such as credentials, is sent in…

  • CVE-2022-45546HigFeb 15, 2023
    risk 0.49cvss 7.5epss 0.01

    Information Disclosure in Authentication Component of ScreenCheck BadgeMaker 2.6.2.0 application allows internal attacker to obtain credentials for authentication via network sniffing.

  • CVE-2023-22806HigFeb 15, 2023
    risk 0.49cvss 7.5epss 0.00

    LS ELECTRIC XBC-DN32U with operating system version 01.80 transmits sensitive information in cleartext when communicating over its XGT protocol. This could allow an attacker to gain sensitive information such as user credentials.

  • CVE-2022-40693HigFeb 7, 2023
    risk 0.49cvss 7.5epss 0.01

    A cleartext transmission vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted network sniffing can lead to a disclosure of sensitive information. An attacker can sniff network traffic to trigger…

  • CVE-2023-25016HigFeb 6, 2023
    risk 0.49cvss 7.5epss 0.00

    Couchbase Server before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2 exposes Sensitive Information to an Unauthorized Actor.

  • CVE-2022-44411HigNov 25, 2022
    risk 0.49cvss 7.5epss 0.00

    Web Based Quiz System v1.0 transmits user passwords in plaintext during the authentication process, allowing attackers to obtain users' passwords via a bruteforce attack.

  • CVE-2022-38122HigNov 10, 2022
    risk 0.49cvss 7.5epss 0.01

    UPSMON PRO transmits sensitive data in cleartext over HTTP protocol. An unauthenticated remote attacker can exploit this vulnerability to access sensitive data.

  • CVE-2022-42916HigOct 29, 2022
    risk 0.49cvss 7.5epss 0.02

    In curl before 7.86.0, the HSTS check could be bypassed to trick it into staying with HTTP. Using its HSTS support, curl can be instructed to use HTTPS directly (instead of using an insecure cleartext HTTP step) even when HTTP is provided in the URL. This mechanism could be…

  • CVE-2022-2083HigSep 5, 2022
    risk 0.49cvss 7.5epss 0.01

    The Simple Single Sign On WordPress plugin through 4.1.0 leaks its OAuth client_secret, which could be used by attackers to gain unauthorized access to the site.

  • CVE-2022-2005HigAug 31, 2022
    risk 0.49cvss 7.5epss 0.01

    AutomationDirect C-more EA9 HTTP webserver uses an insecure mechanism to transport credentials from client to web server, which may allow an attacker to obtain the login credentials and login as a valid user. This issue affects: AutomationDirect C-more EA9 EA9-T6CL versions…

  • CVE-2022-36200HigAug 29, 2022
    risk 0.49cvss 7.5epss 0.02

    In FiberHome VDSL2 Modem HG150-Ub_V3.0, Credentials of Admin are submitted in URL, which can be logged/sniffed.

  • CVE-2022-31204HigJul 26, 2022
    risk 0.49cvss 7.5epss 0.01

    Omron CS series, CJ series, and CP series PLCs through 2022-05-18 use cleartext passwords. They feature a UM Protection setting that allows users or system integrators to configure a password in order to restrict sensitive engineering operations (such as project/logic uploads…

  • CVE-2022-29519HigJun 28, 2022
    risk 0.49cvss 7.5epss 0.00

    Cleartext transmission of sensitive information vulnerability exists in STARDOM FCN Controller and FCJ Controller R1.01 to R4.31, which may allow an adjacent attacker to login the affected products and alter device configuration settings or tamper with device firmware.

  • CVE-2022-26077HigMay 25, 2022
    risk 0.49cvss 7.5epss 0.01

    A cleartext transmission of sensitive information vulnerability exists in the OAS Engine configuration communications functionality of Open Automation Software OAS Platform V16.00.0112. A targeted network sniffing attack can lead to a disclosure of sensitive information. An…

  • CVE-2022-30994HigMay 18, 2022
    risk 0.49cvss 7.5epss 0.01

    Cleartext transmission of sensitive information. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 29240