VYPR

CWE-319

Cleartext Transmission of Sensitive Information

BaseDraftLikelihood: High

Description

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-117 · CAPEC-383 · CAPEC-477 · CAPEC-65

CVEs mapped to this weakness (914)

page 14 of 46
  • CVE-2023-25016HigFeb 6, 2023
    risk 0.49cvss 7.5epss 0.00

    Couchbase Server before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2 exposes Sensitive Information to an Unauthorized Actor.

  • CVE-2022-44411HigNov 25, 2022
    risk 0.49cvss 7.5epss 0.00

    Web Based Quiz System v1.0 transmits user passwords in plaintext during the authentication process, allowing attackers to obtain users' passwords via a bruteforce attack.

  • CVE-2022-38122HigNov 10, 2022
    risk 0.49cvss 7.5epss 0.01

    UPSMON PRO transmits sensitive data in cleartext over HTTP protocol. An unauthenticated remote attacker can exploit this vulnerability to access sensitive data.

  • CVE-2022-42916HigOct 29, 2022
    risk 0.49cvss 7.5epss 0.02

    In curl before 7.86.0, the HSTS check could be bypassed to trick it into staying with HTTP. Using its HSTS support, curl can be instructed to use HTTPS directly (instead of using an insecure cleartext HTTP step) even when HTTP is provided in the URL. This mechanism could be…

  • CVE-2022-2083HigSep 5, 2022
    risk 0.49cvss 7.5epss 0.01

    The Simple Single Sign On WordPress plugin through 4.1.0 leaks its OAuth client_secret, which could be used by attackers to gain unauthorized access to the site.

  • CVE-2022-2005HigAug 31, 2022
    risk 0.49cvss 7.5epss 0.00

    AutomationDirect C-more EA9 HTTP webserver uses an insecure mechanism to transport credentials from client to web server, which may allow an attacker to obtain the login credentials and login as a valid user. This issue affects: AutomationDirect C-more EA9 EA9-T6CL versions…

  • CVE-2022-36200HigAug 29, 2022
    risk 0.49cvss 7.5epss 0.02

    In FiberHome VDSL2 Modem HG150-Ub_V3.0, Credentials of Admin are submitted in URL, which can be logged/sniffed.

  • CVE-2022-31204HigJul 26, 2022
    risk 0.49cvss 7.5epss 0.01

    Omron CS series, CJ series, and CP series PLCs through 2022-05-18 use cleartext passwords. They feature a UM Protection setting that allows users or system integrators to configure a password in order to restrict sensitive engineering operations (such as project/logic uploads…

  • CVE-2022-29519HigJun 28, 2022
    risk 0.49cvss 7.5epss 0.00

    Cleartext transmission of sensitive information vulnerability exists in STARDOM FCN Controller and FCJ Controller R1.01 to R4.31, which may allow an adjacent attacker to login the affected products and alter device configuration settings or tamper with device firmware.

  • CVE-2022-26077HigMay 25, 2022
    risk 0.49cvss 7.5epss 0.01

    A cleartext transmission of sensitive information vulnerability exists in the OAS Engine configuration communications functionality of Open Automation Software OAS Platform V16.00.0112. A targeted network sniffing attack can lead to a disclosure of sensitive information. An…

  • CVE-2022-30994HigMay 18, 2022
    risk 0.49cvss 7.5epss 0.01

    Cleartext transmission of sensitive information. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 29240

  • CVE-2022-30993HigMay 18, 2022
    risk 0.49cvss 7.5epss 0.01

    Cleartext transmission of sensitive information. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 29240

  • CVE-2021-40392HigApr 14, 2022
    risk 0.49cvss 7.5epss 0.01

    An information disclosure vulnerability exists in the Web Application functionality of Moxa MXView Series 3.2.4. Network sniffing can lead to a disclosure of sensitive information. An attacker can sniff network traffic to exploit this vulnerability.

  • CVE-2021-32982HigApr 4, 2022
    risk 0.49cvss 7.5epss 0.01

    Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 passwords are sent as plaintext during unlocking and project transfers. An attacker who has network visibility can observe the password exchange.

  • CVE-2021-33022HigApr 1, 2022
    risk 0.49cvss 7.5epss 0.01

    Philips Vue PACS versions 12.2.x.x and prior transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

  • CVE-2021-27422HigMar 23, 2022
    risk 0.49cvss 7.5epss 0.01

    GE UR firmware versions prior to version 8.1x web server interface is supported on UR over HTTP protocol. It allows sensitive information exposure without authentication.

  • CVE-2020-25178HigMar 18, 2022
    risk 0.49cvss 7.5epss 0.02

    ISaGRAF Workbench communicates with Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x using TCP/IP. This communication protocol provides various file system operations, as well as the uploading of applications. Data is transferred over this protocol unencrypted, which…

  • CVE-2021-40846HigMar 4, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Rhinode Trading Paints through 2.0.36. TP Updater.exe uses cleartext HTTP to check, and request, updates. Thus, attackers can man-in-the-middle a victim to download a malicious binary in place of the real update, with no SSL errors or warnings.

  • CVE-2022-21798HigFeb 25, 2022
    risk 0.49cvss 7.5epss 0.01

    The affected product is vulnerable due to cleartext transmission of credentials seen in the CIMPLICITY network, which can be easily spoofed and used to log in to make operational changes to the system.

  • CVE-2021-29397HigFeb 4, 2022
    risk 0.49cvss 7.5epss 0.01

    Cleartext Transmission of Sensitive Information in /northstar/Admin/login.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote local user to intercept users credentials transmitted in cleartext over HTTP.