VYPR

CWE-319

Cleartext Transmission of Sensitive Information

BaseDraftLikelihood: High

Description

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-117 · CAPEC-383 · CAPEC-477 · CAPEC-65

CVEs mapped to this weakness (914)

page 24 of 46
  • CVE-2025-25728MedFeb 28, 2025
    risk 0.42cvss 6.5epss 0.00

    Bosscomm IF740 Firmware versions:11001.7078 & v11001.0000 and System versions: 6.25 & 6.00 were discovered to send communications to the update API in plaintext, allowing attackers to access sensitive information via a man-in-the-middle attack.

  • CVE-2022-41545MedFeb 18, 2025
    risk 0.42cvss 6.4epss 0.00

    The administrative web interface of a Netgear C7800 Router running firmware version 6.01.07 (and possibly others) authenticates users via basic authentication, with an HTTP header containing a base64 value of the plaintext username and password. Because the web server also does…

  • CVE-2024-28786MedJan 28, 2025
    risk 0.42cvss 6.5epss 0.00

    IBM QRadar SIEM 7.5 transmits sensitive or security-critical data in cleartext in a communication channel that could be obtained by an unauthorized actor using man in the middle techniques.

  • CVE-2024-48121MedJan 15, 2025
    risk 0.42cvss 6.5epss 0.00

    The HI-SCAN 6040i Hitrax HX-03-19-I was discovered to transmit user credentials in cleartext over the GIOP protocol. This allows attackers to possibly gain access to sensitive information via a man-in-the-middle attack.

  • CVE-2024-11946MedDec 30, 2024
    risk 0.42cvss 6.5epss 0.00

    iXsystems TrueNAS CORE fetch_plugin_packagesites tar Cleartext Transmission of Sensitive Information Vulnerability. This vulnerability allows network-adjacent attackers to tamper with firmware update files on affected installations of iXsystems TrueNAS devices. Authentication is…

  • CVE-2024-47833MedOct 9, 2024
    risk 0.42cvss 6.5epss 0.00

    Taipy is an open-source Python library for easy, end-to-end application development for data scientists and machine learning engineers. In affected versions session cookies are served without Secure and HTTPOnly flags. This issue has been addressed in release version 4.0.0 and…

  • CVE-2024-38167MedAug 13, 2024
    risk 0.42cvss 6.5epss 0.01

    .NET and Visual Studio Information Disclosure Vulnerability

  • CVE-2024-7408MedAug 12, 2024
    risk 0.42cvss 6.5epss 0.00

    This vulnerability exists in Airveda Air Quality Monitor PM2.5 PM10 due to transmission of sensitive information in plain text during AP pairing mode. An attacker in close proximity could exploit this vulnerability by capturing Wi-Fi traffic of Airveda-AP. Successful…

  • CVE-2024-32864MedAug 1, 2024
    risk 0.42cvss 6.4epss 0.00

    Under certain circumstances exacqVision Web Services will not enforce secure web communications (HTTPS)

  • CVE-2024-6972MedJul 25, 2024
    risk 0.42cvss 6.5epss 0.00

    In affected versions of Octopus Server under certain circumstances it is possible for sensitive variables to be printed in the task log in clear-text.

  • CVE-2024-27163MedJun 14, 2024
    risk 0.42cvss 6.5epss 0.00

    Toshiba printers will display the password of the admin user in clear-text and additional passwords when sending 2 specific HTTP requests to the internal API. An attacker stealing the cookie of an admin or abusing a XSS vulnerability can recover this password in clear-text and…

  • CVE-2024-37163MedJun 7, 2024
    risk 0.42cvss 6.4epss 0.00

    SkyScrape is a GUI Dashboard for AWS Infrastructure and Managing Resources and Usage Costs. SkyScrape's API requests are currently unsecured HTTP requests, leading to potential vulnerabilities for the user's temporary credentials and data. This affects version 1.0.0.

  • CVE-2024-31840MedMay 21, 2024
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in Italtel Embrace 1.6.4. The web application inserts cleartext passwords in the HTML source code. An authenticated user is able to edit the configuration of the email server. Once the user access the edit function, the web application fills the edit form…

  • CVE-2024-28275MedApr 3, 2024
    risk 0.42cvss 6.5epss 0.00

    Puwell Cloud Tech Co, Ltd 360Eyes Pro v3.9.5.16(3090516) was discovered to transmit sensitive information in cleartext. This vulnerability allows attackers to intercept and access sensitive information, including users' credentials and password change requests.

  • CVE-2023-34829MedDec 28, 2023
    risk 0.42cvss 6.5epss 0.00

    Incorrect access control in TP-Link Tapo before v3.1.315 allows attackers to access user credentials in plaintext.

  • CVE-2023-42579MedDec 5, 2023
    risk 0.42cvss 6.5epss 0.00

    Improper usage of insecure protocol (i.e. HTTP) in SogouSDK of Chinese Samsung Keyboard prior to versions 5.3.70.1 in Android 11, 5.4.60.49, 5.4.85.5, 5.5.00.58 in Android 12, and 5.6.00.52, 5.6.10.42, 5.7.00.45 in Android 13 allows adjacent attackers to access keystroke data…

  • CVE-2023-35833MedJul 13, 2023
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in YSoft SAFEQ 6 Server before 6.0.82. When modifying the URL of the LDAP server configuration from LDAPS to LDAP, the system does not require the password to be (re)entered. This results in exposing cleartext credentials when connecting to a rogue LDAP…

  • CVE-2023-25070MedMay 10, 2023
    risk 0.42cvss 6.5epss 0.01

    Cleartext transmission of sensitive information exists in SkyBridge MB-A100/110 firmware Ver. 4.2.0 and earlier. If the telnet connection is enabled, a remote unauthenticated attacker may eavesdrop on or alter the administrator's communication to the product.

  • CVE-2023-27927MedMar 27, 2023
    risk 0.42cvss 6.5epss 0.00

    An authenticated malicious user could acquire the simple mail transfer protocol (SMTP) Password in cleartext format, despite it being protected and hidden behind asterisks. The attacker could then perform further attacks using the SMTP credentials.

  • CVE-2022-38458MedMar 21, 2023
    risk 0.42cvss 6.5epss 0.01

    A cleartext transmission vulnerability exists in the Remote Management functionality of Netgear Orbi Router RBR750 4.6.8.5. A specially-crafted man-in-the-middle attack can lead to a disclosure of sensitive information.