VYPR

CWE-319

Cleartext Transmission of Sensitive Information

BaseDraftLikelihood: High

Description

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-117 · CAPEC-383 · CAPEC-477 · CAPEC-65

CVEs mapped to this weakness (954)

page 17 of 48
  • CVE-2020-12048HigJun 29, 2020
    risk 0.49cvss 7.5epss 0.00

    Phoenix Hemodialysis Delivery System SW 3.36 and 3.40, The Phoenix Hemodialysis device does not support data-in-transit encryption (e.g., TLS/SSL) when transmitting treatment and prescription data on the network between the Phoenix system and the Exalis dialysis data management…

  • CVE-2020-12037HigJun 29, 2020
    risk 0.49cvss 7.5epss 0.00

    Baxter PrismaFlex all versions, PrisMax all versions prior to 3.x, The affected devices do not implement data-in-transit encryption (e.g., TLS/SSL) when configured to send treatment data to a PDMS (Patient Data Management System) or an EMR (Electronic Medical Record) system. An…

  • CVE-2020-12036HigJun 29, 2020
    risk 0.49cvss 7.5epss 0.01

    Baxter PrismaFlex all versions, PrisMax all versions prior to 3.x, The affected devices do not implement data-in-transit encryption (e.g., TLS/SSL) when configured to send treatment data to a PDMS (Patient Data Management System) or an EMR (Electronic Medical Record) system. An…

  • CVE-2020-12008HigJun 29, 2020
    risk 0.49cvss 7.5epss 0.01

    Baxter ExactaMix EM 2400 Versions 1.10, 1.11 and ExactaMix EM1200 Versions 1.1, 1.2 systems use cleartext messages to communicate order information with an order entry system. This could allow an attacker with network access to view sensitive data including PHI.

  • CVE-2020-10628HigJun 26, 2020
    risk 0.49cvss 7.5epss 0.01

    ControlEdge PLC (R130.2, R140, R150, and R151) and RTU (R101, R110, R140, R150, and R151) exposes unencrypted passwords on the network.

  • CVE-2020-10624HigJun 26, 2020
    risk 0.49cvss 7.5epss 0.01

    ControlEdge PLC (R130.2, R140, R150, and R151) and RTU (R101, R110, R140, R150, and R151) exposes a session token on the network.

  • CVE-2020-13787HigJun 3, 2020
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-865L Ax 1.20B01 Beta devices have Cleartext Transmission of Sensitive Information.

  • CVE-2020-5879HigApr 30, 2020
    risk 0.49cvss 7.5epss 0.01

    On BIG-IP ASM 11.6.1-11.6.5.1, under certain configurations, the BIG-IP system sends data plane traffic to back-end servers unencrypted, even when a Server SSL profile is applied.

  • CVE-2020-7488HigApr 22, 2020
    risk 0.49cvss 7.5epss 0.01

    A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists which could leak sensitive information transmitted between the software and the Modicon M218, M241, M251, and M258 controllers.

  • CVE-2020-11685HigApr 22, 2020
    risk 0.49cvss 7.5epss 0.01

    In JetBrains GoLand before 2019.3.2, the plugin repository was accessed via HTTP instead of HTTPS.

  • CVE-2020-7483HigApr 16, 2020
    risk 0.49cvss 7.5epss 0.01

    **VERSION NOT SUPPORTED WHEN ASSIGNED** A vulnerability could cause certain data to be visible on the network when the 'password' feature is enabled. This vulnerability was discovered in and remediated in versions v4.9.1 and v4.10.1 on May 30, 2013. The 'password' feature is an…

  • CVE-2020-11557HigApr 9, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. It includes the username and password values in cleartext within each request's cookie value.

  • CVE-2020-2165HigMar 25, 2020
    risk 0.49cvss 7.5epss 0.01

    Jenkins Artifactory Plugin 3.6.0 and earlier transmits configured passwords in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.

  • CVE-2020-6997HigMar 24, 2020
    risk 0.49cvss 7.5epss 0.01

    In Moxa EDS-G516E Series firmware, Version 5.2 or lower, sensitive information is transmitted over some web applications in cleartext.

  • CVE-2020-7003HigMar 24, 2020
    risk 0.49cvss 7.5epss 0.01

    In Moxa ioLogik 2500 series firmware, Version 3.0 or lower, and IOxpress configuration utility, Version 2.3.0 or lower, sensitive information is transmitted over some web applications in clear text.

  • CVE-2019-16063HigMar 19, 2020
    risk 0.49cvss 7.5epss 0.01

    NETSAS Enigma NMS 65.0.0 and prior does not encrypt sensitive data rendered within web pages. It is possible for an attacker to expose unencrypted sensitive data.

  • CVE-2019-16067HigMar 19, 2020
    risk 0.49cvss 7.5epss 0.01

    NETSAS Enigma NMS 65.0.0 and prior utilises basic authentication over HTTP for enforcing access control to the web application. The use of weak authentication transmitted over cleartext protocols can allow an attacker to steal username and password combinations by intercepting…

  • CVE-2019-5107HigMar 11, 2020
    risk 0.49cvss 7.5epss 0.01

    A cleartext transmission vulnerability exists in the network communication functionality of WAGO e!Cockpit version 1.5.1.1. An attacker with access to network traffic can easily intercept, interpret, and manipulate data coming from, or destined for e!Cockpit. This includes…

  • CVE-2019-9101HigMar 11, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. Sensitive information is sent to the web server in cleartext, which may allow an attacker to discover the…

  • CVE-2020-7907HigFeb 21, 2020
    risk 0.49cvss 7.5epss 0.01

    In the JetBrains Scala plugin before 2019.2.1, some artefact dependencies were resolved over unencrypted connections.