VYPR

CWE-319

Cleartext Transmission of Sensitive Information

BaseDraftLikelihood: High

Description

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-117 · CAPEC-383 · CAPEC-477 · CAPEC-65

CVEs mapped to this weakness (950)

page 22 of 48
  • CVE-2021-27209HigFeb 13, 2021
    risk 0.46cvss 7.1epss 0.00

    In the management interface on TP-Link Archer C5v 1.7_181221 devices, credentials are sent in a base64 format over cleartext HTTP.

  • CVE-2020-10124HigAug 21, 2020
    risk 0.46cvss 7.1epss 0.01

    NCR SelfServ ATMs running APTRA XFS 05.01.00 do not encrypt, authenticate, or verify the integrity of messages between the BNA and the host computer, which could allow an attacker with physical access to the internal components of the ATM to execute arbitrary code, including…

  • CVE-2019-10102HigJul 3, 2019
    risk 0.46cvss 8.1epss 0.01

    JetBrains Ktor framework (created using the Kotlin IDE template) versions before 1.1.0 were resolving artifacts using an http connection during the build process, potentially allowing an MITM attack. This issue was fixed in Kotlin plugin version 1.3.30.

  • CVE-2019-10101HigJul 3, 2019
    risk 0.46cvss 8.1epss 0.01

    JetBrains Kotlin versions before 1.3.30 were resolving artifacts using an http connection during the build process, potentially allowing an MITM attack.

  • CVE-2019-10249HigMay 6, 2019
    risk 0.46cvss 8.1epss 0.01

    All Xtext & Xtend versions prior to 2.18.0 were built using HTTP instead of HTTPS file transfer and thus the built artifacts may have been compromised.

  • CVE-2017-1181HigJul 17, 2017
    risk 0.46cvss 7.0epss 0.00

    IBM Tivoli Monitoring Portal V6 client could allow a local attacker to gain elevated privileges for IBM Tivoli Monitoring, caused by the default console connection not being encrypted. IBM X-Force ID: 123487.

  • CVE-2025-52586MedAug 8, 2025
    risk 0.45cvss 6.9epss 0.00

    The MOD3 command traffic between the monitoring application and the inverter is transmitted in plaintext without encryption or obfuscation. This vulnerability may allow an attacker with access to a local network to intercept, manipulate, replay, or forge critical data,…

  • CVE-2025-43013MedApr 17, 2025
    risk 0.45cvss 6.9epss 0.00

    In JetBrains Toolbox App before 2.6 unencrypted credential transmission during SSH authentication was possible

  • CVE-2020-25988MedNov 17, 2020
    risk 0.45cvss 6.5epss 0.03

    UPNP Service listening on port 5555 in Genexis Platinum 4410 Router V2.1 (P4410-V2–1.34H) has an action 'X_GetAccess' which leaks the credentials of 'admin', provided that the attacker is network adjacent.

  • CVE-2026-0714MedFeb 5, 2026
    risk 0.44cvss 6.8epss 0.00

    A physical attack vulnerability exists in certain Moxa industrial computers using TPM-backed LUKS full-disk encryption on Moxa Industrial Linux 3, where the discrete TPM is connected to the CPU via an SPI bus. Exploitation requires invasive physical access, including opening…

  • CVE-2024-32384MedDec 1, 2025
    risk 0.44cvss 6.8epss 0.00

    Kerlink gateways running KerOS prior to version 5.10 expose their web interface exclusively over HTTP, without HTTPS support. This lack of transport layer security allows a man-in-the-middle attacker to intercept and modify traffic between the client and the device.

  • CVE-2025-26654MedApr 8, 2025
    risk 0.44cvss 6.8epss 0.00

    SAP Commerce Cloud (Public Cloud) does not allow to disable unencrypted HTTP (port 80) entirely, but instead allows a redirect from port 80 to 443 (HTTPS). As a result, Commerce normally communicates securely over HTTPS. However, the confidentiality and integrity of data sent on…

  • CVE-2024-26155MedJan 17, 2025
    risk 0.44cvss 6.8epss 0.00

    All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 expose clear text credentials in the web portal. An attacker can access the ETIC RAS web portal and view the HTML code, which is configured to be hidden, thus allowing a connection to the ETIC RAS ssh…

  • CVE-2024-45102MedJan 14, 2025
    risk 0.44cvss 6.8epss 0.00

    A privilege escalation vulnerability was discovered that could allow a valid, authenticated LXCA user to escalate their permissions for a connected XCC instance when using LXCA as a Single Sign On (SSO) provider for XCC instances.

  • CVE-2024-45101MedSep 13, 2024
    risk 0.44cvss 6.8epss 0.00

    A privilege escalation vulnerability was discovered when Single Sign On (SSO) is enabled that could allow an attacker to intercept a valid, authenticated LXCA user’s XCC session if they can convince the user to click on a specially crafted URL.

  • CVE-2023-34441MedOct 19, 2023
    risk 0.44cvss 6.8epss 0.00

    Baker Hughes – Bently Nevada 3500 System TDI Firmware version 5.05 contains a cleartext transmission vulnerability which could allow an attacker to steal the authentication secret from communication traffic to the device and reuse it for arbitrary requests.

  • CVE-2023-43125MedSep 27, 2023
    risk 0.44cvss 6.8epss 0.00

    BIG-IP APM clients may send IP traffic outside of the VPN tunnel.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

  • CVE-2020-4497MedDec 14, 2022
    risk 0.44cvss 6.8epss 0.00

    IBM Spectrum Protect Plus 10.1.0 through 10.1.12 discloses sensitive information due to unencrypted data being used in the communication flow between Spectrum Protect Plus vSnap and its agents. An attacker could obtain information using main in the middle techniques. IBM…

  • CVE-2022-27619MedAug 3, 2022
    risk 0.44cvss 6.8epss 0.00

    Cleartext transmission of sensitive information vulnerability in authentication management in Synology Note Station Client before 2.2.2-609 allows man-in-the-middle attackers to obtain sensitive information via unspecified vectors.

  • CVE-2021-28508MedMay 26, 2022
    risk 0.44cvss 6.8epss 0.01

    This advisory documents the impact of an internally found vulnerability in Arista EOS state streaming telemetry agent TerminAttr and OpenConfig transport protocols. The impact of this vulnerability is that, in certain conditions, TerminAttr might leak IPsec sensitive data in…