CWE-319
Cleartext Transmission of Sensitive Information
Description
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-102 · CAPEC-117 · CAPEC-383 · CAPEC-477 · CAPEC-65
CVEs mapped to this weakness (950)
page 15 of 48| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-30993 | Hig | 0.49 | 7.5 | 0.01 | May 18, 2022 | Cleartext transmission of sensitive information. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 29240 | ||
| CVE-2021-40392 | Hig | 0.49 | 7.5 | 0.01 | Apr 14, 2022 | An information disclosure vulnerability exists in the Web Application functionality of Moxa MXView Series 3.2.4. Network sniffing can lead to a disclosure of sensitive information. An attacker can sniff network traffic to exploit this vulnerability. | ||
| CVE-2021-32982 | Hig | 0.49 | 7.5 | 0.01 | Apr 4, 2022 | Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 passwords are sent as plaintext during unlocking and project transfers. An attacker who has network visibility can observe the password exchange. | ||
| CVE-2021-33022 | Hig | 0.49 | 7.5 | 0.01 | Apr 1, 2022 | Philips Vue PACS versions 12.2.x.x and prior transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors. | ||
| CVE-2021-27422 | Hig | 0.49 | 7.5 | 0.01 | Mar 23, 2022 | GE UR firmware versions prior to version 8.1x web server interface is supported on UR over HTTP protocol. It allows sensitive information exposure without authentication. | ||
| CVE-2020-25178 | Hig | 0.49 | 7.5 | 0.02 | Mar 18, 2022 | ISaGRAF Workbench communicates with Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x using TCP/IP. This communication protocol provides various file system operations, as well as the uploading of applications. Data is transferred over this protocol unencrypted, which… | ||
| CVE-2021-40846 | Hig | 0.49 | 7.5 | 0.01 | Mar 4, 2022 | An issue was discovered in Rhinode Trading Paints through 2.0.36. TP Updater.exe uses cleartext HTTP to check, and request, updates. Thus, attackers can man-in-the-middle a victim to download a malicious binary in place of the real update, with no SSL errors or warnings. | ||
| CVE-2022-21798 | Hig | 0.49 | 7.5 | 0.01 | Feb 25, 2022 | The affected product is vulnerable due to cleartext transmission of credentials seen in the CIMPLICITY network, which can be easily spoofed and used to log in to make operational changes to the system. | ||
| CVE-2021-29397 | Hig | 0.49 | 7.5 | 0.01 | Feb 4, 2022 | Cleartext Transmission of Sensitive Information in /northstar/Admin/login.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote local user to intercept users credentials transmitted in cleartext over HTTP. | ||
| CVE-2021-45735 | Hig | 0.49 | 7.5 | 0.04 | Feb 4, 2022 | TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to use the HTTP protocol for authentication into the admin interface, allowing attackers to intercept user credentials via packet capture software. | ||
| CVE-2021-40148 | Hig | 0.49 | 7.5 | 0.01 | Jan 4, 2022 | In Modem EMM, there is a possible information disclosure due to a missing data encryption. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00716585; Issue ID:… | ||
| CVE-2021-20175 | Hig | 0.49 | 7.5 | 0.01 | Dec 30, 2021 | Netgear Nighthawk R6700 version 1.0.4.120 does not utilize secure communication methods to the SOAP interface. By default, all communication to/from the device's SOAP Interface (port 5000) is sent via HTTP, which causes potentially sensitive information (such as usernames and… | ||
| CVE-2021-20174 | Hig | 0.49 | 7.5 | 0.01 | Dec 30, 2021 | Netgear Nighthawk R6700 version 1.0.4.120 does not utilize secure communication methods to the web interface. By default, all communication to/from the device's web interface is sent via HTTP, which causes potentially sensitive information (such as usernames and passwords) to be… | ||
| CVE-2021-20154 | Hig | 0.49 | 7.5 | 0.01 | Dec 30, 2021 | Trendnet AC2600 TEW-827DRU version 2.08B01 contains an security flaw in the web interface. HTTPS is not enabled on the device by default. This results in cleartext transmission of sensitive information such as passwords. | ||
| CVE-2020-20128 | Hig | 0.49 | 7.5 | 0.01 | Sep 29, 2021 | LaraCMS v1.0.1 transmits sensitive information in cleartext which can be intercepted by attackers. | ||
| CVE-2021-33900 | Hig | 0.49 | 7.5 | 0.01 | Jul 26, 2021 | While investigating DIRSTUDIO-1219 it was noticed that configured StartTLS encryption was not applied when any SASL authentication mechanism (DIGEST-MD5, GSSAPI) was used. While investigating DIRSTUDIO-1220 it was noticed that any configured SASL confidentiality layer was not… | ||
| CVE-2020-27185 | Hig | 0.49 | 7.5 | 0.01 | May 14, 2021 | Cleartext transmission of sensitive information via Moxa Service in NPort IA5000A series serial devices. Successfully exploiting the vulnerability could enable attackers to read authentication data, device configuration, and other sensitive data transmitted over Moxa Service. | ||
| CVE-2021-31898 | Hig | 0.49 | 7.5 | 0.01 | May 11, 2021 | In JetBrains WebStorm before 2021.1, HTTP requests were used instead of HTTPS. | ||
| CVE-2020-26197 | Hig | 0.49 | 7.5 | 0.01 | Apr 20, 2021 | Dell PowerScale OneFS 8.1.0 - 9.1.0 contains an LDAP Provider inability to connect over TLSv1.2 vulnerability. It may make it easier to eavesdrop and decrypt such traffic for a malicious actor. Note: This does not affect clusters which are not relying on an LDAP server for the… | ||
| CVE-2019-18231 | Hig | 0.49 | 7.5 | 0.01 | Mar 17, 2021 | Advantech Spectre RT ERT351 Versions 5.1.3 and prior logins and passwords are transmitted in clear text form, which may allow an attacker to intercept the request. |
- risk 0.49cvss 7.5epss 0.01
Cleartext transmission of sensitive information. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 29240
- risk 0.49cvss 7.5epss 0.01
An information disclosure vulnerability exists in the Web Application functionality of Moxa MXView Series 3.2.4. Network sniffing can lead to a disclosure of sensitive information. An attacker can sniff network traffic to exploit this vulnerability.
- risk 0.49cvss 7.5epss 0.01
Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 passwords are sent as plaintext during unlocking and project transfers. An attacker who has network visibility can observe the password exchange.
- risk 0.49cvss 7.5epss 0.01
Philips Vue PACS versions 12.2.x.x and prior transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
- risk 0.49cvss 7.5epss 0.01
GE UR firmware versions prior to version 8.1x web server interface is supported on UR over HTTP protocol. It allows sensitive information exposure without authentication.
- risk 0.49cvss 7.5epss 0.02
ISaGRAF Workbench communicates with Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x using TCP/IP. This communication protocol provides various file system operations, as well as the uploading of applications. Data is transferred over this protocol unencrypted, which…
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in Rhinode Trading Paints through 2.0.36. TP Updater.exe uses cleartext HTTP to check, and request, updates. Thus, attackers can man-in-the-middle a victim to download a malicious binary in place of the real update, with no SSL errors or warnings.
- risk 0.49cvss 7.5epss 0.01
The affected product is vulnerable due to cleartext transmission of credentials seen in the CIMPLICITY network, which can be easily spoofed and used to log in to make operational changes to the system.
- risk 0.49cvss 7.5epss 0.01
Cleartext Transmission of Sensitive Information in /northstar/Admin/login.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote local user to intercept users credentials transmitted in cleartext over HTTP.
- risk 0.49cvss 7.5epss 0.04
TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to use the HTTP protocol for authentication into the admin interface, allowing attackers to intercept user credentials via packet capture software.
- risk 0.49cvss 7.5epss 0.01
In Modem EMM, there is a possible information disclosure due to a missing data encryption. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00716585; Issue ID:…
- risk 0.49cvss 7.5epss 0.01
Netgear Nighthawk R6700 version 1.0.4.120 does not utilize secure communication methods to the SOAP interface. By default, all communication to/from the device's SOAP Interface (port 5000) is sent via HTTP, which causes potentially sensitive information (such as usernames and…
- risk 0.49cvss 7.5epss 0.01
Netgear Nighthawk R6700 version 1.0.4.120 does not utilize secure communication methods to the web interface. By default, all communication to/from the device's web interface is sent via HTTP, which causes potentially sensitive information (such as usernames and passwords) to be…
- risk 0.49cvss 7.5epss 0.01
Trendnet AC2600 TEW-827DRU version 2.08B01 contains an security flaw in the web interface. HTTPS is not enabled on the device by default. This results in cleartext transmission of sensitive information such as passwords.
- risk 0.49cvss 7.5epss 0.01
LaraCMS v1.0.1 transmits sensitive information in cleartext which can be intercepted by attackers.
- risk 0.49cvss 7.5epss 0.01
While investigating DIRSTUDIO-1219 it was noticed that configured StartTLS encryption was not applied when any SASL authentication mechanism (DIGEST-MD5, GSSAPI) was used. While investigating DIRSTUDIO-1220 it was noticed that any configured SASL confidentiality layer was not…
- risk 0.49cvss 7.5epss 0.01
Cleartext transmission of sensitive information via Moxa Service in NPort IA5000A series serial devices. Successfully exploiting the vulnerability could enable attackers to read authentication data, device configuration, and other sensitive data transmitted over Moxa Service.
- risk 0.49cvss 7.5epss 0.01
In JetBrains WebStorm before 2021.1, HTTP requests were used instead of HTTPS.
- risk 0.49cvss 7.5epss 0.01
Dell PowerScale OneFS 8.1.0 - 9.1.0 contains an LDAP Provider inability to connect over TLSv1.2 vulnerability. It may make it easier to eavesdrop and decrypt such traffic for a malicious actor. Note: This does not affect clusters which are not relying on an LDAP server for the…
- risk 0.49cvss 7.5epss 0.01
Advantech Spectre RT ERT351 Versions 5.1.3 and prior logins and passwords are transmitted in clear text form, which may allow an attacker to intercept the request.