VYPR

CWE-319

Cleartext Transmission of Sensitive Information

BaseDraftLikelihood: High

Description

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-117 · CAPEC-383 · CAPEC-477 · CAPEC-65

CVEs mapped to this weakness (950)

page 20 of 48
  • CVE-2024-41262HigJul 31, 2024
    risk 0.48cvss 7.4epss 0.00

    mmudb v1.9.3 was discovered to use the HTTP protocol in the ShowMetricsRaw and ShowMetricsAsText functions, possibly allowing attackers to intercept communications via a man-in-the-middle attack.

  • CVE-2024-27166HigJun 14, 2024
    risk 0.48cvss 7.4epss 0.00

    Coredump binaries in Toshiba printers have incorrect permissions. A local attacker can steal confidential information. As for the affected products/models/versions, see the reference URL.

  • CVE-2023-2754HigAug 3, 2023
    risk 0.48cvss 7.4epss 0.01

    The Cloudflare WARP client for Windows assigns loopback IPv4 addresses for the DNS Servers, since WARP acts as local DNS server that performs DNS queries in a secure manner, however, if a user is connected to WARP over an IPv6-capable network, te WARP client did not assign…

  • CVE-2023-28348HigMay 31, 2023
    risk 0.48cvss 7.4epss 0.00

    An issue was discovered in Faronics Insight 10.0.19045 on Windows. A suitably positioned attacker could perform a man-in-the-middle attack on either a connected student or teacher, enabling them to intercept student keystrokes or modify executable files being sent from teachers…

  • CVE-2022-1524HigJun 24, 2022
    risk 0.48cvss 7.4epss 0.00

    LRM version 2.4 and lower does not implement TLS encryption. A malicious actor can MITM attack sensitive data in-transit, including credentials.

  • CVE-2021-45104HigApr 6, 2022
    risk 0.48cvss 7.4epss 0.01

    An issue was discovered in HTCondor 9.0.x before 9.0.10 and 9.1.x before 9.5.1. An attacker who can capture HTCondor network data can interfere with users' jobs and data.

  • CVE-2021-40366HigNov 9, 2021
    risk 0.48cvss 7.4epss 0.00

    A vulnerability has been identified in Climatix POL909 (AWB module) (All versions < V11.42), Climatix POL909 (AWM module) (All versions < V11.34). The web server of affected devices transmits data without TLS encryption. This could allow an unauthenticated remote attacker in a…

  • CVE-2021-3774HigNov 5, 2021
    risk 0.48cvss 7.4epss 0.01

    Meross Smart Wi-Fi 2 Way Wall Switch (MSS550X), on its 3.1.3 version and before, creates an open Wi-Fi Access Point without the required security measures in its initial setup. This could allow a remote attacker to obtain the Wi-Fi SSID as well as the password configured by the…

  • CVE-2021-0296HigOct 19, 2021
    risk 0.48cvss 7.4epss 0.01

    The Juniper Networks CTPView server is not enforcing HTTP Strict Transport Security (HSTS). HSTS is an optional response header which allows servers to indicate that content from the requested domain will only be served over HTTPS. The lack of HSTS may leave the system…

  • CVE-2021-23018HigJun 1, 2021
    risk 0.48cvss 7.4epss 0.01

    Intra-cluster communication does not use TLS. The services within the NGINX Controller 3.x before 3.4.0 namespace are using cleartext protocols inside the cluster.

  • CVE-2020-11718HigDec 23, 2020
    risk 0.48cvss 7.4epss 0.01

    An issue was discovered in Programi Bilanc build 007 release 014 31.01.2020 and below. Its software-update packages are downloaded via cleartext HTTP.

  • CVE-2020-5399HigFeb 12, 2020
    risk 0.48cvss 7.4epss 0.01

    Cloud Foundry CredHub, versions prior to 2.5.10, connects to a MySQL database without TLS even when configured to use TLS. A malicious user with access to the network between CredHub and its MySQL database may eavesdrop on database connections and thereby gain unauthorized…

  • CVE-2019-13498HigJul 29, 2019
    risk 0.48cvss 7.4epss 0.01

    One Identity Cloud Access Manager 8.1.3 does not use HTTP Strict Transport Security (HSTS), which may allow man-in-the-middle (MITM) attacks. This issue is fixed in version 8.1.4.

  • CVE-2018-7960HigNov 27, 2018
    risk 0.48cvss 7.4epss 0.01

    There is a SRTP icon display vulnerability in Huawei eSpace product. An unauthenticated, remote attacker launches man-in-the-middle attack to intercept the packets in non-secure transmission mode. Successful exploitation may intercept and tamper with the call information,…

  • CVE-2018-8929HigJul 6, 2018
    risk 0.48cvss 7.3epss 0.01

    Improper restriction of communication channel to intended endpoints vulnerability in HTTP daemon in Synology SSL VPN Client before 1.2.4-0224 allows remote attackers to conduct man-in-the-middle attacks via a crafted payload.

  • CVE-2017-9035HigMay 26, 2017
    risk 0.48cvss 7.4epss 0.04

    Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows attackers to eavesdrop and tamper with updates by leveraging unencrypted communications with update servers.

  • CVE-2024-44276HigMar 17, 2025
    risk 0.47cvss 7.3epss 0.00

    This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in iOS 18.2 and iPadOS 18.2. A user in a privileged network position may be able to leak sensitive information.

  • CVE-2024-25960HigMar 28, 2024
    risk 0.47cvss 7.3epss 0.00

    Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains a cleartext transmission of sensitive information vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to escalation of privileges.

  • CVE-2023-40729HigSep 12, 2023
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected application lacks security control to prevent unencrypted communication without HTTPS. An attacker who managed to gain machine-in-the-middle position could manipulate, or steal…

  • CVE-2023-36673HigAug 9, 2023
    risk 0.47cvss 7.3epss 0.01

    An issue was discovered in Avira Phantom VPN through 2.23.1 for macOS. The VPN client insecurely configures the operating system such that all IP traffic to the VPN server's IP address is sent in plaintext outside the VPN tunnel, even if this traffic is not generated by the VPN…