VYPR

CWE-319

Cleartext Transmission of Sensitive Information

BaseDraftLikelihood: High

Description

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-117 · CAPEC-383 · CAPEC-477 · CAPEC-65

CVEs mapped to this weakness (950)

page 25 of 48
  • CVE-2024-11946MedDec 30, 2024
    risk 0.42cvss 6.5epss 0.00

    iXsystems TrueNAS CORE fetch_plugin_packagesites tar Cleartext Transmission of Sensitive Information Vulnerability. This vulnerability allows network-adjacent attackers to tamper with firmware update files on affected installations of iXsystems TrueNAS devices. Authentication is…

  • CVE-2024-47833MedOct 9, 2024
    risk 0.42cvss 6.5epss 0.00

    Taipy is an open-source Python library for easy, end-to-end application development for data scientists and machine learning engineers. In affected versions session cookies are served without Secure and HTTPOnly flags. This issue has been addressed in release version 4.0.0 and…

  • CVE-2024-38167MedAug 13, 2024
    risk 0.42cvss 6.5epss 0.01

    .NET and Visual Studio Information Disclosure Vulnerability

  • CVE-2024-7408MedAug 12, 2024
    risk 0.42cvss 6.5epss 0.00

    This vulnerability exists in Airveda Air Quality Monitor PM2.5 PM10 due to transmission of sensitive information in plain text during AP pairing mode. An attacker in close proximity could exploit this vulnerability by capturing Wi-Fi traffic of Airveda-AP. Successful…

  • CVE-2024-32864MedAug 1, 2024
    risk 0.42cvss 6.4epss 0.00

    Under certain circumstances exacqVision Web Services will not enforce secure web communications (HTTPS)

  • CVE-2024-6972MedJul 25, 2024
    risk 0.42cvss 6.5epss 0.00

    In affected versions of Octopus Server under certain circumstances it is possible for sensitive variables to be printed in the task log in clear-text.

  • CVE-2024-27163MedJun 14, 2024
    risk 0.42cvss 6.5epss 0.00

    Toshiba printers will display the password of the admin user in clear-text and additional passwords when sending 2 specific HTTP requests to the internal API. An attacker stealing the cookie of an admin or abusing a XSS vulnerability can recover this password in clear-text and…

  • CVE-2024-37163MedJun 7, 2024
    risk 0.42cvss 6.4epss 0.00

    SkyScrape is a GUI Dashboard for AWS Infrastructure and Managing Resources and Usage Costs. SkyScrape's API requests are currently unsecured HTTP requests, leading to potential vulnerabilities for the user's temporary credentials and data. This affects version 1.0.0.

  • CVE-2024-31840MedMay 21, 2024
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in Italtel Embrace 1.6.4. The web application inserts cleartext passwords in the HTML source code. An authenticated user is able to edit the configuration of the email server. Once the user access the edit function, the web application fills the edit form…

  • CVE-2024-28275MedApr 3, 2024
    risk 0.42cvss 6.5epss 0.00

    Puwell Cloud Tech Co, Ltd 360Eyes Pro v3.9.5.16(3090516) was discovered to transmit sensitive information in cleartext. This vulnerability allows attackers to intercept and access sensitive information, including users' credentials and password change requests.

  • CVE-2023-34829MedDec 28, 2023
    risk 0.42cvss 6.5epss 0.00

    Incorrect access control in TP-Link Tapo before v3.1.315 allows attackers to access user credentials in plaintext.

  • CVE-2023-42579MedDec 5, 2023
    risk 0.42cvss 6.5epss 0.00

    Improper usage of insecure protocol (i.e. HTTP) in SogouSDK of Chinese Samsung Keyboard prior to versions 5.3.70.1 in Android 11, 5.4.60.49, 5.4.85.5, 5.5.00.58 in Android 12, and 5.6.00.52, 5.6.10.42, 5.7.00.45 in Android 13 allows adjacent attackers to access keystroke data…

  • CVE-2023-35833MedJul 13, 2023
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in YSoft SAFEQ 6 Server before 6.0.82. When modifying the URL of the LDAP server configuration from LDAPS to LDAP, the system does not require the password to be (re)entered. This results in exposing cleartext credentials when connecting to a rogue LDAP…

  • CVE-2023-25070MedMay 10, 2023
    risk 0.42cvss 6.5epss 0.01

    Cleartext transmission of sensitive information exists in SkyBridge MB-A100/110 firmware Ver. 4.2.0 and earlier. If the telnet connection is enabled, a remote unauthenticated attacker may eavesdrop on or alter the administrator's communication to the product.

  • CVE-2023-27927MedMar 27, 2023
    risk 0.42cvss 6.5epss 0.00

    An authenticated malicious user could acquire the simple mail transfer protocol (SMTP) Password in cleartext format, despite it being protected and hidden behind asterisks. The attacker could then perform further attacks using the SMTP credentials.

  • CVE-2022-38458MedMar 21, 2023
    risk 0.42cvss 6.5epss 0.01

    A cleartext transmission vulnerability exists in the Remote Management functionality of Netgear Orbi Router RBR750 4.6.8.5. A specially-crafted man-in-the-middle attack can lead to a disclosure of sensitive information.

  • CVE-2023-23915MedFeb 23, 2023
    risk 0.42cvss 6.5epss 0.01

    A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality to behave incorrectly when multiple URLs are requested in parallel. Using its HSTS support, curl can be instructed to use HTTPS instead of using an…

  • CVE-2023-22597MedJan 12, 2023
    risk 0.42cvss 6.5epss 0.01

    InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-S-V2.3.0.r5542, contain vulnerability CWE-319: Cleartext Transmission of Sensitive Information. They use an unsecured channel to communicate with the cloud platform by…

  • CVE-2022-0553MedJan 11, 2023
    risk 0.42cvss 6.5epss 0.00

    There is no check to see if slot 0 is being uploaded from the device to the host. When using encrypted images this means the unencrypted firmware can be retrieved easily.

  • CVE-2022-42454MedDec 21, 2022
    risk 0.42cvss 6.4epss 0.00

    Insights for Vulnerability Remediation (IVR) is vulnerable to man-in-the-middle attacks that may lead to information disclosure.  This requires privileged network access.