VYPR

CWE-319

Cleartext Transmission of Sensitive Information

BaseDraftLikelihood: High

Description

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-117 · CAPEC-383 · CAPEC-477 · CAPEC-65

CVEs mapped to this weakness (914)

page 17 of 46
  • CVE-2020-7003HigMar 24, 2020
    risk 0.49cvss 7.5epss 0.01

    In Moxa ioLogik 2500 series firmware, Version 3.0 or lower, and IOxpress configuration utility, Version 2.3.0 or lower, sensitive information is transmitted over some web applications in clear text.

  • CVE-2019-16063HigMar 19, 2020
    risk 0.49cvss 7.5epss 0.01

    NETSAS Enigma NMS 65.0.0 and prior does not encrypt sensitive data rendered within web pages. It is possible for an attacker to expose unencrypted sensitive data.

  • CVE-2019-16067HigMar 19, 2020
    risk 0.49cvss 7.5epss 0.01

    NETSAS Enigma NMS 65.0.0 and prior utilises basic authentication over HTTP for enforcing access control to the web application. The use of weak authentication transmitted over cleartext protocols can allow an attacker to steal username and password combinations by intercepting…

  • CVE-2019-5107HigMar 11, 2020
    risk 0.49cvss 7.5epss 0.01

    A cleartext transmission vulnerability exists in the network communication functionality of WAGO e!Cockpit version 1.5.1.1. An attacker with access to network traffic can easily intercept, interpret, and manipulate data coming from, or destined for e!Cockpit. This includes…

  • CVE-2019-9101HigMar 11, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. Sensitive information is sent to the web server in cleartext, which may allow an attacker to discover the…

  • CVE-2020-7907HigFeb 21, 2020
    risk 0.49cvss 7.5epss 0.01

    In the JetBrains Scala plugin before 2019.2.1, some artefact dependencies were resolved over unencrypted connections.

  • CVE-2019-20061HigFeb 10, 2020
    risk 0.49cvss 7.5epss 0.01

    The user-introduction email in MFScripts YetiShare v3.5.2 through v4.5.4 may leak the (system-picked) password if this email is sent in cleartext. In other words, the user is not allowed to choose their own initial password.

  • CVE-2020-8507HigFeb 5, 2020
    risk 0.49cvss 7.5epss 0.01

    The Citytv Video application 4.08.0 for Android and 3.35 for iOS sends Unencrypted Analytics.

  • CVE-2020-7984HigJan 26, 2020
    risk 0.49cvss 7.5epss 0.02

    SolarWinds N-central before 12.1 SP1 HF5 and 12.2 before SP1 HF2 allows remote attackers to retrieve cleartext domain admin credentials from the Agent & Probe settings, and obtain other sensitive information. The attacker can use a customer ID to self register and read any…

  • CVE-2019-19898HigJan 23, 2020
    risk 0.49cvss 7.5epss 0.01

    In IXP EasyInstall 6.2.13723, there are cleartext credentials in network communication on TCP port 20050 when using the Administrator console remotely.

  • CVE-2019-12399HigJan 14, 2020
    risk 0.49cvss 7.5epss 0.04

    When Connect workers in Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, or 2.3.0 are configured with one or more config providers, and a connector is created/updated on that Connect cluster to use an externalized secret variable in a substring of a connector configuration…

  • CVE-2019-16274HigJan 6, 2020
    risk 0.49cvss 7.5epss 0.01

    DTEN D5 before 1.3 and D7 before 1.3 devices transfer customer data files via unencrypted HTTP.

  • CVE-2019-19967HigDec 25, 2019
    risk 0.49cvss 7.5epss 0.01

    The Administration page on Connect Box EuroDOCSIS 3.0 Voice Gateway CH7465LG-NCIP-6.12.18.25-2p6-NOSH devices accepts a cleartext password in a POST request on port 80, as demonstrated by the Password field to the xml/setter.xml URI.

  • CVE-2019-19890HigDec 18, 2019
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered on Humax Wireless Voice Gateway HGB10R-2 20160817_1855 devices. Admin credentials are sent over cleartext HTTP.

  • CVE-2019-19889HigDec 18, 2019
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered on Humax Wireless Voice Gateway HGB10R-2 20160817_1855 devices. The attacker can discover admin credentials in the backup file, aka backupsettings.conf.

  • CVE-2019-3992HigDec 17, 2019
    risk 0.49cvss 7.5epss 0.01

    ELOG 3.1.4-57bea22 and below is affected by an information disclosure vulnerability. A remote unauthenticated attacker can access the server's configuration file by sending an HTTP GET request. Amongst the configuration data, the attacker may gain access to valid admin usernames…

  • CVE-2019-12388HigDec 2, 2019
    risk 0.49cvss 7.5epss 0.01

    Anviz access control devices perform cleartext transmission of sensitive information (passwords/pins and names) when replying to query on port tcp/5010.

  • CVE-2019-6845HigOct 29, 2019
    risk 0.49cvss 7.5epss 0.01

    A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists in Modicon M580, Modicon M340, Modicon Premium , Modicon Quantum (all firmware versions), which could cause the disclosure of information when transferring applications to the controller using Modbus…

  • CVE-2019-18201HigOct 24, 2019
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered on Fujitsu Wireless Keyboard Set LX390 GK381 devices. Because of the lack of proper encryption of 2.4 GHz communication, an attacker is able to eavesdrop on sensitive data such as passwords.

  • CVE-2019-15626HigOct 17, 2019
    risk 0.49cvss 7.5epss 0.02

    The Deep Security Manager application (Versions 10.0, 11.0 and 12.0), when configured in a certain way, may transmit initial LDAP communication in clear text. This may result in confidentiality impact but does not impact integrity or availability.