VYPR

CWE-319

Cleartext Transmission of Sensitive Information

BaseDraftLikelihood: High

Description

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-117 · CAPEC-383 · CAPEC-477 · CAPEC-65

CVEs mapped to this weakness (950)

page 15 of 48
  • CVE-2022-30993HigMay 18, 2022
    risk 0.49cvss 7.5epss 0.01

    Cleartext transmission of sensitive information. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 29240

  • CVE-2021-40392HigApr 14, 2022
    risk 0.49cvss 7.5epss 0.01

    An information disclosure vulnerability exists in the Web Application functionality of Moxa MXView Series 3.2.4. Network sniffing can lead to a disclosure of sensitive information. An attacker can sniff network traffic to exploit this vulnerability.

  • CVE-2021-32982HigApr 4, 2022
    risk 0.49cvss 7.5epss 0.01

    Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 passwords are sent as plaintext during unlocking and project transfers. An attacker who has network visibility can observe the password exchange.

  • CVE-2021-33022HigApr 1, 2022
    risk 0.49cvss 7.5epss 0.01

    Philips Vue PACS versions 12.2.x.x and prior transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

  • CVE-2021-27422HigMar 23, 2022
    risk 0.49cvss 7.5epss 0.01

    GE UR firmware versions prior to version 8.1x web server interface is supported on UR over HTTP protocol. It allows sensitive information exposure without authentication.

  • CVE-2020-25178HigMar 18, 2022
    risk 0.49cvss 7.5epss 0.02

    ISaGRAF Workbench communicates with Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x using TCP/IP. This communication protocol provides various file system operations, as well as the uploading of applications. Data is transferred over this protocol unencrypted, which…

  • CVE-2021-40846HigMar 4, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Rhinode Trading Paints through 2.0.36. TP Updater.exe uses cleartext HTTP to check, and request, updates. Thus, attackers can man-in-the-middle a victim to download a malicious binary in place of the real update, with no SSL errors or warnings.

  • CVE-2022-21798HigFeb 25, 2022
    risk 0.49cvss 7.5epss 0.01

    The affected product is vulnerable due to cleartext transmission of credentials seen in the CIMPLICITY network, which can be easily spoofed and used to log in to make operational changes to the system.

  • CVE-2021-29397HigFeb 4, 2022
    risk 0.49cvss 7.5epss 0.01

    Cleartext Transmission of Sensitive Information in /northstar/Admin/login.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote local user to intercept users credentials transmitted in cleartext over HTTP.

  • CVE-2021-45735HigFeb 4, 2022
    risk 0.49cvss 7.5epss 0.04

    TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to use the HTTP protocol for authentication into the admin interface, allowing attackers to intercept user credentials via packet capture software.

  • CVE-2021-40148HigJan 4, 2022
    risk 0.49cvss 7.5epss 0.01

    In Modem EMM, there is a possible information disclosure due to a missing data encryption. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00716585; Issue ID:…

  • CVE-2021-20175HigDec 30, 2021
    risk 0.49cvss 7.5epss 0.01

    Netgear Nighthawk R6700 version 1.0.4.120 does not utilize secure communication methods to the SOAP interface. By default, all communication to/from the device's SOAP Interface (port 5000) is sent via HTTP, which causes potentially sensitive information (such as usernames and…

  • CVE-2021-20174HigDec 30, 2021
    risk 0.49cvss 7.5epss 0.01

    Netgear Nighthawk R6700 version 1.0.4.120 does not utilize secure communication methods to the web interface. By default, all communication to/from the device's web interface is sent via HTTP, which causes potentially sensitive information (such as usernames and passwords) to be…

  • CVE-2021-20154HigDec 30, 2021
    risk 0.49cvss 7.5epss 0.01

    Trendnet AC2600 TEW-827DRU version 2.08B01 contains an security flaw in the web interface. HTTPS is not enabled on the device by default. This results in cleartext transmission of sensitive information such as passwords.

  • CVE-2020-20128HigSep 29, 2021
    risk 0.49cvss 7.5epss 0.01

    LaraCMS v1.0.1 transmits sensitive information in cleartext which can be intercepted by attackers.

  • CVE-2021-33900HigJul 26, 2021
    risk 0.49cvss 7.5epss 0.01

    While investigating DIRSTUDIO-1219 it was noticed that configured StartTLS encryption was not applied when any SASL authentication mechanism (DIGEST-MD5, GSSAPI) was used. While investigating DIRSTUDIO-1220 it was noticed that any configured SASL confidentiality layer was not…

  • CVE-2020-27185HigMay 14, 2021
    risk 0.49cvss 7.5epss 0.01

    Cleartext transmission of sensitive information via Moxa Service in NPort IA5000A series serial devices. Successfully exploiting the vulnerability could enable attackers to read authentication data, device configuration, and other sensitive data transmitted over Moxa Service.

  • CVE-2021-31898HigMay 11, 2021
    risk 0.49cvss 7.5epss 0.01

    In JetBrains WebStorm before 2021.1, HTTP requests were used instead of HTTPS.

  • CVE-2020-26197HigApr 20, 2021
    risk 0.49cvss 7.5epss 0.01

    Dell PowerScale OneFS 8.1.0 - 9.1.0 contains an LDAP Provider inability to connect over TLSv1.2 vulnerability. It may make it easier to eavesdrop and decrypt such traffic for a malicious actor. Note: This does not affect clusters which are not relying on an LDAP server for the…

  • CVE-2019-18231HigMar 17, 2021
    risk 0.49cvss 7.5epss 0.01

    Advantech Spectre RT ERT351 Versions 5.1.3 and prior logins and passwords are transmitted in clear text form, which may allow an attacker to intercept the request.