VYPR

CWE-319

Cleartext Transmission of Sensitive Information

BaseDraftLikelihood: High

Description

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-117 · CAPEC-383 · CAPEC-477 · CAPEC-65

CVEs mapped to this weakness (914)

page 15 of 46
  • CVE-2021-45735HigFeb 4, 2022
    risk 0.49cvss 7.5epss 0.04

    TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to use the HTTP protocol for authentication into the admin interface, allowing attackers to intercept user credentials via packet capture software.

  • CVE-2021-40148HigJan 4, 2022
    risk 0.49cvss 7.5epss 0.01

    In Modem EMM, there is a possible information disclosure due to a missing data encryption. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00716585; Issue ID:…

  • CVE-2021-20175HigDec 30, 2021
    risk 0.49cvss 7.5epss 0.01

    Netgear Nighthawk R6700 version 1.0.4.120 does not utilize secure communication methods to the SOAP interface. By default, all communication to/from the device's SOAP Interface (port 5000) is sent via HTTP, which causes potentially sensitive information (such as usernames and…

  • CVE-2021-20174HigDec 30, 2021
    risk 0.49cvss 7.5epss 0.01

    Netgear Nighthawk R6700 version 1.0.4.120 does not utilize secure communication methods to the web interface. By default, all communication to/from the device's web interface is sent via HTTP, which causes potentially sensitive information (such as usernames and passwords) to be…

  • CVE-2021-20154HigDec 30, 2021
    risk 0.49cvss 7.5epss 0.01

    Trendnet AC2600 TEW-827DRU version 2.08B01 contains an security flaw in the web interface. HTTPS is not enabled on the device by default. This results in cleartext transmission of sensitive information such as passwords.

  • CVE-2020-20128HigSep 29, 2021
    risk 0.49cvss 7.5epss 0.01

    LaraCMS v1.0.1 transmits sensitive information in cleartext which can be intercepted by attackers.

  • CVE-2021-33900HigJul 26, 2021
    risk 0.49cvss 7.5epss 0.01

    While investigating DIRSTUDIO-1219 it was noticed that configured StartTLS encryption was not applied when any SASL authentication mechanism (DIGEST-MD5, GSSAPI) was used. While investigating DIRSTUDIO-1220 it was noticed that any configured SASL confidentiality layer was not…

  • CVE-2020-27185HigMay 14, 2021
    risk 0.49cvss 7.5epss 0.01

    Cleartext transmission of sensitive information via Moxa Service in NPort IA5000A series serial devices. Successfully exploiting the vulnerability could enable attackers to read authentication data, device configuration, and other sensitive data transmitted over Moxa Service.

  • CVE-2021-31898HigMay 11, 2021
    risk 0.49cvss 7.5epss 0.01

    In JetBrains WebStorm before 2021.1, HTTP requests were used instead of HTTPS.

  • CVE-2020-26197HigApr 20, 2021
    risk 0.49cvss 7.5epss 0.01

    Dell PowerScale OneFS 8.1.0 - 9.1.0 contains an LDAP Provider inability to connect over TLSv1.2 vulnerability. It may make it easier to eavesdrop and decrypt such traffic for a malicious actor. Note: This does not affect clusters which are not relying on an LDAP server for the…

  • CVE-2019-18231HigMar 17, 2021
    risk 0.49cvss 7.5epss 0.01

    Advantech Spectre RT ERT351 Versions 5.1.3 and prior logins and passwords are transmitted in clear text form, which may allow an attacker to intercept the request.

  • CVE-2020-4695HigMar 8, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM API Connect V10 is impacted by insecure communications during database replication. As the data replication happens over insecure communication channels, an attacker can view unencrypted data leading to a loss of confidentiality.

  • CVE-2021-22703HigFeb 19, 2021
    risk 0.49cvss 7.5epss 0.01

    A CWE-319: Cleartext transmission of sensitive information vulnerability exists in PowerLogic ION7400, ION7650, ION83xx/84xx/85xx/8600, ION8650, ION8800, ION9000 and PM800 (see notification for affected versions), that could cause disclosure of user credentials when a malicious…

  • CVE-2021-22702HigFeb 19, 2021
    risk 0.49cvss 7.5epss 0.01

    A CWE-319: Cleartext transmission of sensitive information vulnerability exists in PowerLogic ION7400, ION7650, ION7700/73xx, ION83xx/84xx/85xx/8600, ION8650, ION8800, ION9000 and PM800 (see notification for affected versions), that could cause disclosure of user credentials…

  • CVE-2020-29005HigJan 29, 2021
    risk 0.49cvss 7.5epss 0.01

    The API in the Push extension for MediaWiki through 1.35 used cleartext for ApiPush credentials, allowing for potential information disclosure.

  • CVE-2020-25169HigJan 26, 2021
    risk 0.49cvss 7.5epss 0.01

    The affected Reolink P2P products do not sufficiently protect data transferred between the local device and Reolink servers. This can allow an attacker to access sensitive information, such as camera feeds.

  • CVE-2018-19944HigDec 31, 2020
    risk 0.49cvss 7.5epss 0.01

    A cleartext transmission of sensitive information vulnerability has been reported to affect certain QTS devices. If exploited, this vulnerability allows a remote attacker to gain access to sensitive information. QNAP have already fixed this vulnerability in the following…

  • CVE-2020-25190HigDec 23, 2020
    risk 0.49cvss 7.5epss 0.01

    The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower stores and transmits the credentials of third-party services in cleartext.

  • CVE-2020-27554HigNov 17, 2020
    risk 0.49cvss 7.5epss 0.01

    Cleartext Transmission of Sensitive Information vulnerability in BASETech GE-131 BT-1837836 firmware 20180921 exists which could leak sensitive information transmitted between the mobile app and the camera device.

  • CVE-2020-25155HigNov 13, 2020
    risk 0.49cvss 7.5epss 0.01

    The affected product transmits unencrypted sensitive information, which may allow an attacker to access this information on the NIO 50 (all versions).