VYPR

CWE-319

Cleartext Transmission of Sensitive Information

BaseDraftLikelihood: High

Description

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-117 · CAPEC-383 · CAPEC-477 · CAPEC-65

CVEs mapped to this weakness (950)

page 18 of 48
  • CVE-2020-8507HigFeb 5, 2020
    risk 0.49cvss 7.5epss 0.01

    The Citytv Video application 4.08.0 for Android and 3.35 for iOS sends Unencrypted Analytics.

  • CVE-2020-7984HigJan 26, 2020
    risk 0.49cvss 7.5epss 0.02

    SolarWinds N-central before 12.1 SP1 HF5 and 12.2 before SP1 HF2 allows remote attackers to retrieve cleartext domain admin credentials from the Agent & Probe settings, and obtain other sensitive information. The attacker can use a customer ID to self register and read any…

  • CVE-2019-19898HigJan 23, 2020
    risk 0.49cvss 7.5epss 0.01

    In IXP EasyInstall 6.2.13723, there are cleartext credentials in network communication on TCP port 20050 when using the Administrator console remotely.

  • CVE-2019-12399HigJan 14, 2020
    risk 0.49cvss 7.5epss 0.04

    When Connect workers in Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, or 2.3.0 are configured with one or more config providers, and a connector is created/updated on that Connect cluster to use an externalized secret variable in a substring of a connector configuration…

  • CVE-2019-16274HigJan 6, 2020
    risk 0.49cvss 7.5epss 0.01

    DTEN D5 before 1.3 and D7 before 1.3 devices transfer customer data files via unencrypted HTTP.

  • CVE-2019-19967HigDec 25, 2019
    risk 0.49cvss 7.5epss 0.01

    The Administration page on Connect Box EuroDOCSIS 3.0 Voice Gateway CH7465LG-NCIP-6.12.18.25-2p6-NOSH devices accepts a cleartext password in a POST request on port 80, as demonstrated by the Password field to the xml/setter.xml URI.

  • CVE-2019-19890HigDec 18, 2019
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered on Humax Wireless Voice Gateway HGB10R-2 20160817_1855 devices. Admin credentials are sent over cleartext HTTP.

  • CVE-2019-19889HigDec 18, 2019
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered on Humax Wireless Voice Gateway HGB10R-2 20160817_1855 devices. The attacker can discover admin credentials in the backup file, aka backupsettings.conf.

  • CVE-2019-3992HigDec 17, 2019
    risk 0.49cvss 7.5epss 0.01

    ELOG 3.1.4-57bea22 and below is affected by an information disclosure vulnerability. A remote unauthenticated attacker can access the server's configuration file by sending an HTTP GET request. Amongst the configuration data, the attacker may gain access to valid admin usernames…

  • CVE-2019-12388HigDec 2, 2019
    risk 0.49cvss 7.5epss 0.01

    Anviz access control devices perform cleartext transmission of sensitive information (passwords/pins and names) when replying to query on port tcp/5010.

  • CVE-2019-6845HigOct 29, 2019
    risk 0.49cvss 7.5epss 0.01

    A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists in Modicon M580, Modicon M340, Modicon Premium , Modicon Quantum (all firmware versions), which could cause the disclosure of information when transferring applications to the controller using Modbus…

  • CVE-2019-18201HigOct 24, 2019
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered on Fujitsu Wireless Keyboard Set LX390 GK381 devices. Because of the lack of proper encryption of 2.4 GHz communication, an attacker is able to eavesdrop on sensitive data such as passwords.

  • CVE-2019-15626HigOct 17, 2019
    risk 0.49cvss 7.5epss 0.02

    The Deep Security Manager application (Versions 10.0, 11.0 and 12.0), when configured in a certain way, may transmit initial LDAP communication in clear text. This may result in confidentiality impact but does not impact integrity or availability.

  • CVE-2019-0231HigOct 1, 2019
    risk 0.49cvss 7.5epss 0.02

    Handling of the close_notify SSL/TLS message does not lead to a connection closure, leading the server to retain the socket opened and to have the client potentially receive clear text messages afterward. Mitigation: 2.0.20 users should migrate to 2.0.21, 2.1.0 users should…

  • CVE-2019-10435HigOct 1, 2019
    risk 0.49cvss 7.5epss 0.01

    Jenkins SourceGear Vault Plugin transmits configured credentials in plain text as part of job configuration forms, potentially resulting in their exposure.

  • CVE-2019-10434HigOct 1, 2019
    risk 0.49cvss 7.5epss 0.01

    Jenkins LDAP Email Plugin transmits configured credentials in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure.

  • CVE-2019-10428HigSep 25, 2019
    risk 0.49cvss 7.5epss 0.01

    Jenkins Aqua Security Scanner Plugin 3.0.17 and earlier transmitted configured credentials in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure.

  • CVE-2019-5635HigAug 22, 2019
    risk 0.49cvss 7.5epss 0.00

    A cleartext transmission of sensitive information vulnerability is present in Hickory Smart Ethernet Bridge from Belwith Products, LLC. Captured data reveals that the Hickory Smart Ethernet Bridge device communicates over the network to an MQTT broker without using encryption.…

  • CVE-2019-15135HigAug 18, 2019
    risk 0.49cvss 7.5epss 0.02

    The handshake protocol in Object Management Group (OMG) DDS Security 1.1 sends cleartext information about all of the capabilities of a participant (including capabilities inapplicable to the current session), which makes it easier for attackers to discover potentially sensitive…

  • CVE-2019-4162HigJun 6, 2019
    risk 0.49cvss 7.5epss 0.01

    IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, and 1.0.2 is missing the HTTP Strict Transport Security header. Users can navigate by mistake to the unencrypted version of the web application or accept invalid certificates. This leads to sensitive data being sent unencrypted…