VYPR

CWE-319

Cleartext Transmission of Sensitive Information

BaseDraftLikelihood: High

Description

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-117 · CAPEC-383 · CAPEC-477 · CAPEC-65

CVEs mapped to this weakness (914)

page 20 of 46
  • CVE-2020-11718HigDec 23, 2020
    risk 0.48cvss 7.4epss 0.01

    An issue was discovered in Programi Bilanc build 007 release 014 31.01.2020 and below. Its software-update packages are downloaded via cleartext HTTP.

  • CVE-2020-5399HigFeb 12, 2020
    risk 0.48cvss 7.4epss 0.01

    Cloud Foundry CredHub, versions prior to 2.5.10, connects to a MySQL database without TLS even when configured to use TLS. A malicious user with access to the network between CredHub and its MySQL database may eavesdrop on database connections and thereby gain unauthorized…

  • CVE-2019-13498HigJul 29, 2019
    risk 0.48cvss 7.4epss 0.01

    One Identity Cloud Access Manager 8.1.3 does not use HTTP Strict Transport Security (HSTS), which may allow man-in-the-middle (MITM) attacks. This issue is fixed in version 8.1.4.

  • CVE-2018-7960HigNov 27, 2018
    risk 0.48cvss 7.4epss 0.01

    There is a SRTP icon display vulnerability in Huawei eSpace product. An unauthenticated, remote attacker launches man-in-the-middle attack to intercept the packets in non-secure transmission mode. Successful exploitation may intercept and tamper with the call information,…

  • CVE-2018-8929HigJul 6, 2018
    risk 0.48cvss 7.3epss 0.01

    Improper restriction of communication channel to intended endpoints vulnerability in HTTP daemon in Synology SSL VPN Client before 1.2.4-0224 allows remote attackers to conduct man-in-the-middle attacks via a crafted payload.

  • CVE-2017-9035HigMay 26, 2017
    risk 0.48cvss 7.4epss 0.04

    Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows attackers to eavesdrop and tamper with updates by leveraging unencrypted communications with update servers.

  • CVE-2024-44276HigMar 17, 2025
    risk 0.47cvss 7.3epss 0.00

    This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in iOS 18.2 and iPadOS 18.2. A user in a privileged network position may be able to leak sensitive information.

  • CVE-2024-25960HigMar 28, 2024
    risk 0.47cvss 7.3epss 0.00

    Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains a cleartext transmission of sensitive information vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to escalation of privileges.

  • CVE-2023-40729HigSep 12, 2023
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected application lacks security control to prevent unencrypted communication without HTTPS. An attacker who managed to gain machine-in-the-middle position could manipulate, or steal…

  • CVE-2023-36673HigAug 9, 2023
    risk 0.47cvss 7.3epss 0.01

    An issue was discovered in Avira Phantom VPN through 2.23.1 for macOS. The VPN client insecurely configures the operating system such that all IP traffic to the VPN server's IP address is sent in plaintext outside the VPN tunnel, even if this traffic is not generated by the VPN…

  • CVE-2023-1831HigApr 17, 2023
    risk 0.47cvss 7.2epss 0.00

    Mattermost fails to redact from audit logs the user password during user creation and the user password hash in other operations if the experimental audit logging configuration was enabled (ExperimentalAuditSettings section in config).

  • CVE-2021-41835HigJan 21, 2022
    risk 0.47cvss 7.3epss 0.00

    Fresenius Kabi Agilia Link + version 3.0 does not enforce transport layer encryption. Therefore, transmitted data may be sent in cleartext. Transport layer encryption is offered on Port TCP/443, but the affected service does not perform an automated redirect from the unencrypted…

  • CVE-2017-0925HigMar 21, 2018
    risk 0.47cvss 7.2epss 0.01

    Gitlab Enterprise Edition version 10.1.0 is vulnerable to an insufficiently protected credential issue in the project service integration API endpoint resulting in an information disclosure of plaintext password.

  • CVE-2026-47255HigJul 20, 2026
    risk 0.46cvss 8.2epss 0.00

    AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenticmail/core prior to version 0.9.10 had weakness related to validation and and binding of inactive-agent hour filtering; storage SQL identifier validation;…

  • CVE-2026-8874HigJun 3, 2026
    risk 0.46cvss 7.1epss 0.00

    Version 3.0.7 of the Securly Chrome Extension downloads JSON files containing crisis alert keywords and filtering rules over unencrypted HTTP via the Fetch API. Other endpoints in the same extension correctly fetch IWF and CIPA data over HTTPS, demonstrating an inconsistent…

  • CVE-2026-6066HigApr 20, 2026
    risk 0.46cvss 7.1epss 0.00

    ConnectWise has released a security update for ConnectWise Automate™ that addresses a behavior in the ConnectWise Automate Solution Center where certain client-to-server communications could occur without transport-layer encryption. This could allow network‑based…

  • CVE-2026-32034HigMar 19, 2026
    risk 0.46cvss 8.1epss 0.00

    OpenClaw versions prior to 2026.2.21 contain an authentication bypass vulnerability in the Control UI when allowInsecureAuth is explicitly enabled and the gateway is exposed over plaintext HTTP, allowing attackers to bypass device identity and pairing verification. An attacker…

  • CVE-2025-64769HigJan 16, 2026
    risk 0.46cvss 7.1epss 0.00

    The Process Optimization application suite leverages connection channels/protocols that by-default are not encrypted and could become subject to hijacking or data leakage in certain man-in-the-middle or passive inspection scenarios.

  • CVE-2025-10641HigOct 21, 2025
    risk 0.46cvss 7.1epss 0.00

    All WorkExaminer Professional traffic between monitoring client, console and server is transmitted as plain text. This allows an attacker with access to the network to read the transmitted sensitive data. An attacker can also freely modify the data on the wire. The monitoring…

  • CVE-2025-8863HigAug 11, 2025
    risk 0.46cvss epss 0.00

    YugabyteDB diagnostic information was transmitted over HTTP, which could expose sensitive data during transmission