CWE-319
Cleartext Transmission of Sensitive Information
Description
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-102 · CAPEC-117 · CAPEC-383 · CAPEC-477 · CAPEC-65
CVEs mapped to this weakness (914)
page 17 of 46| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-7003 | Hig | 0.49 | 7.5 | 0.01 | Mar 24, 2020 | In Moxa ioLogik 2500 series firmware, Version 3.0 or lower, and IOxpress configuration utility, Version 2.3.0 or lower, sensitive information is transmitted over some web applications in clear text. | ||
| CVE-2019-16063 | Hig | 0.49 | 7.5 | 0.01 | Mar 19, 2020 | NETSAS Enigma NMS 65.0.0 and prior does not encrypt sensitive data rendered within web pages. It is possible for an attacker to expose unencrypted sensitive data. | ||
| CVE-2019-16067 | Hig | 0.49 | 7.5 | 0.01 | Mar 19, 2020 | NETSAS Enigma NMS 65.0.0 and prior utilises basic authentication over HTTP for enforcing access control to the web application. The use of weak authentication transmitted over cleartext protocols can allow an attacker to steal username and password combinations by intercepting… | ||
| CVE-2019-5107 | Hig | 0.49 | 7.5 | 0.01 | Mar 11, 2020 | A cleartext transmission vulnerability exists in the network communication functionality of WAGO e!Cockpit version 1.5.1.1. An attacker with access to network traffic can easily intercept, interpret, and manipulate data coming from, or destined for e!Cockpit. This includes… | ||
| CVE-2019-9101 | Hig | 0.49 | 7.5 | 0.01 | Mar 11, 2020 | An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. Sensitive information is sent to the web server in cleartext, which may allow an attacker to discover the… | ||
| CVE-2020-7907 | Hig | 0.49 | 7.5 | 0.01 | Feb 21, 2020 | In the JetBrains Scala plugin before 2019.2.1, some artefact dependencies were resolved over unencrypted connections. | ||
| CVE-2019-20061 | Hig | 0.49 | 7.5 | 0.01 | Feb 10, 2020 | The user-introduction email in MFScripts YetiShare v3.5.2 through v4.5.4 may leak the (system-picked) password if this email is sent in cleartext. In other words, the user is not allowed to choose their own initial password. | ||
| CVE-2020-8507 | Hig | 0.49 | 7.5 | 0.01 | Feb 5, 2020 | The Citytv Video application 4.08.0 for Android and 3.35 for iOS sends Unencrypted Analytics. | ||
| CVE-2020-7984 | Hig | 0.49 | 7.5 | 0.02 | Jan 26, 2020 | SolarWinds N-central before 12.1 SP1 HF5 and 12.2 before SP1 HF2 allows remote attackers to retrieve cleartext domain admin credentials from the Agent & Probe settings, and obtain other sensitive information. The attacker can use a customer ID to self register and read any… | ||
| CVE-2019-19898 | Hig | 0.49 | 7.5 | 0.01 | Jan 23, 2020 | In IXP EasyInstall 6.2.13723, there are cleartext credentials in network communication on TCP port 20050 when using the Administrator console remotely. | ||
| CVE-2019-12399 | Hig | 0.49 | 7.5 | 0.04 | Jan 14, 2020 | When Connect workers in Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, or 2.3.0 are configured with one or more config providers, and a connector is created/updated on that Connect cluster to use an externalized secret variable in a substring of a connector configuration… | ||
| CVE-2019-16274 | Hig | 0.49 | 7.5 | 0.01 | Jan 6, 2020 | DTEN D5 before 1.3 and D7 before 1.3 devices transfer customer data files via unencrypted HTTP. | ||
| CVE-2019-19967 | Hig | 0.49 | 7.5 | 0.01 | Dec 25, 2019 | The Administration page on Connect Box EuroDOCSIS 3.0 Voice Gateway CH7465LG-NCIP-6.12.18.25-2p6-NOSH devices accepts a cleartext password in a POST request on port 80, as demonstrated by the Password field to the xml/setter.xml URI. | ||
| CVE-2019-19890 | Hig | 0.49 | 7.5 | 0.01 | Dec 18, 2019 | An issue was discovered on Humax Wireless Voice Gateway HGB10R-2 20160817_1855 devices. Admin credentials are sent over cleartext HTTP. | ||
| CVE-2019-19889 | Hig | 0.49 | 7.5 | 0.01 | Dec 18, 2019 | An issue was discovered on Humax Wireless Voice Gateway HGB10R-2 20160817_1855 devices. The attacker can discover admin credentials in the backup file, aka backupsettings.conf. | ||
| CVE-2019-3992 | Hig | 0.49 | 7.5 | 0.01 | Dec 17, 2019 | ELOG 3.1.4-57bea22 and below is affected by an information disclosure vulnerability. A remote unauthenticated attacker can access the server's configuration file by sending an HTTP GET request. Amongst the configuration data, the attacker may gain access to valid admin usernames… | ||
| CVE-2019-12388 | Hig | 0.49 | 7.5 | 0.01 | Dec 2, 2019 | Anviz access control devices perform cleartext transmission of sensitive information (passwords/pins and names) when replying to query on port tcp/5010. | ||
| CVE-2019-6845 | Hig | 0.49 | 7.5 | 0.01 | Oct 29, 2019 | A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists in Modicon M580, Modicon M340, Modicon Premium , Modicon Quantum (all firmware versions), which could cause the disclosure of information when transferring applications to the controller using Modbus… | ||
| CVE-2019-18201 | Hig | 0.49 | 7.5 | 0.01 | Oct 24, 2019 | An issue was discovered on Fujitsu Wireless Keyboard Set LX390 GK381 devices. Because of the lack of proper encryption of 2.4 GHz communication, an attacker is able to eavesdrop on sensitive data such as passwords. | ||
| CVE-2019-15626 | Hig | 0.49 | 7.5 | 0.02 | Oct 17, 2019 | The Deep Security Manager application (Versions 10.0, 11.0 and 12.0), when configured in a certain way, may transmit initial LDAP communication in clear text. This may result in confidentiality impact but does not impact integrity or availability. |
- risk 0.49cvss 7.5epss 0.01
In Moxa ioLogik 2500 series firmware, Version 3.0 or lower, and IOxpress configuration utility, Version 2.3.0 or lower, sensitive information is transmitted over some web applications in clear text.
- risk 0.49cvss 7.5epss 0.01
NETSAS Enigma NMS 65.0.0 and prior does not encrypt sensitive data rendered within web pages. It is possible for an attacker to expose unencrypted sensitive data.
- risk 0.49cvss 7.5epss 0.01
NETSAS Enigma NMS 65.0.0 and prior utilises basic authentication over HTTP for enforcing access control to the web application. The use of weak authentication transmitted over cleartext protocols can allow an attacker to steal username and password combinations by intercepting…
- risk 0.49cvss 7.5epss 0.01
A cleartext transmission vulnerability exists in the network communication functionality of WAGO e!Cockpit version 1.5.1.1. An attacker with access to network traffic can easily intercept, interpret, and manipulate data coming from, or destined for e!Cockpit. This includes…
- risk 0.49cvss 7.5epss 0.01
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. Sensitive information is sent to the web server in cleartext, which may allow an attacker to discover the…
- risk 0.49cvss 7.5epss 0.01
In the JetBrains Scala plugin before 2019.2.1, some artefact dependencies were resolved over unencrypted connections.
- risk 0.49cvss 7.5epss 0.01
The user-introduction email in MFScripts YetiShare v3.5.2 through v4.5.4 may leak the (system-picked) password if this email is sent in cleartext. In other words, the user is not allowed to choose their own initial password.
- risk 0.49cvss 7.5epss 0.01
The Citytv Video application 4.08.0 for Android and 3.35 for iOS sends Unencrypted Analytics.
- risk 0.49cvss 7.5epss 0.02
SolarWinds N-central before 12.1 SP1 HF5 and 12.2 before SP1 HF2 allows remote attackers to retrieve cleartext domain admin credentials from the Agent & Probe settings, and obtain other sensitive information. The attacker can use a customer ID to self register and read any…
- risk 0.49cvss 7.5epss 0.01
In IXP EasyInstall 6.2.13723, there are cleartext credentials in network communication on TCP port 20050 when using the Administrator console remotely.
- risk 0.49cvss 7.5epss 0.04
When Connect workers in Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, or 2.3.0 are configured with one or more config providers, and a connector is created/updated on that Connect cluster to use an externalized secret variable in a substring of a connector configuration…
- risk 0.49cvss 7.5epss 0.01
DTEN D5 before 1.3 and D7 before 1.3 devices transfer customer data files via unencrypted HTTP.
- risk 0.49cvss 7.5epss 0.01
The Administration page on Connect Box EuroDOCSIS 3.0 Voice Gateway CH7465LG-NCIP-6.12.18.25-2p6-NOSH devices accepts a cleartext password in a POST request on port 80, as demonstrated by the Password field to the xml/setter.xml URI.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered on Humax Wireless Voice Gateway HGB10R-2 20160817_1855 devices. Admin credentials are sent over cleartext HTTP.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered on Humax Wireless Voice Gateway HGB10R-2 20160817_1855 devices. The attacker can discover admin credentials in the backup file, aka backupsettings.conf.
- risk 0.49cvss 7.5epss 0.01
ELOG 3.1.4-57bea22 and below is affected by an information disclosure vulnerability. A remote unauthenticated attacker can access the server's configuration file by sending an HTTP GET request. Amongst the configuration data, the attacker may gain access to valid admin usernames…
- risk 0.49cvss 7.5epss 0.01
Anviz access control devices perform cleartext transmission of sensitive information (passwords/pins and names) when replying to query on port tcp/5010.
- risk 0.49cvss 7.5epss 0.01
A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists in Modicon M580, Modicon M340, Modicon Premium , Modicon Quantum (all firmware versions), which could cause the disclosure of information when transferring applications to the controller using Modbus…
- risk 0.49cvss 7.5epss 0.01
An issue was discovered on Fujitsu Wireless Keyboard Set LX390 GK381 devices. Because of the lack of proper encryption of 2.4 GHz communication, an attacker is able to eavesdrop on sensitive data such as passwords.
- risk 0.49cvss 7.5epss 0.02
The Deep Security Manager application (Versions 10.0, 11.0 and 12.0), when configured in a certain way, may transmit initial LDAP communication in clear text. This may result in confidentiality impact but does not impact integrity or availability.