VYPR

CWE-319

Cleartext Transmission of Sensitive Information

BaseDraftLikelihood: High

Description

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-117 · CAPEC-383 · CAPEC-477 · CAPEC-65

CVEs mapped to this weakness (914)

page 26 of 46
  • CVE-2020-7592MedJul 14, 2020
    risk 0.42cvss 6.5epss 0.00

    A vulnerability has been identified in SIMATIC HMI Basic Panels 1st Generation (incl. SIPLUS variants) (All versions), SIMATIC HMI Basic Panels 2nd Generation (incl. SIPLUS variants) (All versions), SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions), SIMATIC HMI…

  • CVE-2020-14171MedJul 9, 2020
    risk 0.42cvss 6.5epss 0.01

    Atlassian Bitbucket Server from version 4.9.0 before version 7.2.4 allows remote attackers to intercept unencrypted repository import requests via a Man-in-the-Middle (MITM) attack.

  • CVE-2020-15509MedJul 7, 2020
    risk 0.42cvss 6.5epss 0.01

    Nordic Semiconductor Android BLE Library through 2.2.1 and DFU Library through 1.10.4 for Android (as used by nRF Connect and other applications) can engage in unencrypted communication while showing the user that the communication is purportedly encrypted. The problem is in…

  • CVE-2019-12122MedMar 18, 2020
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in ONAP Portal through Dublin. By executing a call to ONAPPORTAL/portalApi/loggedinUser, an attacker who possesses a user's cookie may retrieve that user's password from the database. All Portal setups are affected.

  • CVE-2020-3841MedFeb 27, 2020
    risk 0.42cvss 6.5epss 0.01

    The issue was addressed with improved UI handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, Safari 13.0.5. A local user may unknowingly send a password unencrypted over the network.

  • CVE-2020-2114HigFeb 12, 2020
    risk 0.42cvss 7.5epss 0.01

    Jenkins S3 publisher Plugin 0.11.4 and earlier transmits configured credentials in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure.

  • CVE-2019-8632MedDec 18, 2019
    risk 0.42cvss 6.5epss 0.01

    Some analytics data was sent using HTTP rather than HTTPS. This was addressed by no longer sending this analytics data. This issue is fixed in Texture 5.11.10 for iOS, Texture 4.22.0.4 for Android. An attacker in a privileged network position may be able to intercept analytics…

  • CVE-2019-19316HigDec 2, 2019
    risk 0.42cvss 7.5epss 0.01

    When using the Azure backend with a shared access signature (SAS), Terraform versions prior to 0.12.17 may transmit the token and state snapshot using cleartext HTTP.

  • CVE-2019-6846MedOct 29, 2019
    risk 0.42cvss 6.5epss 0.01

    A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists in Modicon M580, Modicon M340, Modicon BMxCRA and 140CRA modules (all firmware versions), which could cause information disclosure when using the FTP protocol.

  • CVE-2019-12967MedOct 22, 2019
    risk 0.42cvss 6.5epss 0.01

    Stephan Mooltipass Moolticute through 0.42.1 (and possibly earlier versions) has Incorrect Access Control.

  • CVE-2019-17356MedOct 15, 2019
    risk 0.42cvss 6.5epss 0.00

    The Infinite Design application 3.4.12 for Android sends a username and password via TCP without any encryption during login, as demonstrated by sniffing of a public Wi-Fi network.

  • CVE-2019-11739MedSep 27, 2019
    risk 0.42cvss 6.5epss 0.01

    Encrypted S/MIME parts in a crafted multipart/alternative message can leak plaintext when included in a a HTML reply/forward. This vulnerability affects Thunderbird < 68.1 and Thunderbird < 60.9.

  • CVE-2019-6652MedSep 25, 2019
    risk 0.42cvss 6.5epss 0.01

    In BIG-IQ 6.0.0-6.1.0, services for stats do not require authentication nor do they implement any form of Transport Layer Security (TLS).

  • CVE-2019-10412HigSep 25, 2019
    risk 0.42cvss 7.5epss 0.01

    Jenkins Inedo ProGet Plugin 1.2 and earlier transmitted configured credentials in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure.

  • CVE-2019-10411HigSep 25, 2019
    risk 0.42cvss 7.5epss 0.01

    Jenkins Inedo BuildMaster Plugin 2.4.0 and earlier transmitted configured credentials in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure.

  • CVE-2019-14319MedSep 4, 2019
    risk 0.42cvss 6.5epss 0.01

    The TikTok (formerly Musical.ly) application 12.2.0 for Android and iOS performs unencrypted transmission of images, videos, and likes. This allows an attacker to extract private sensitive information by sniffing network traffic.

  • CVE-2019-10391MedAug 28, 2019
    risk 0.42cvss 6.5epss 0.01

    Jenkins IBM Application Security on Cloud Plugin 1.2.4 and earlier transmitted configured passwords in plain text as part of job configuration forms, potentially resulting in their exposure.

  • CVE-2019-0348MedAug 14, 2019
    risk 0.42cvss 6.5epss 0.01

    SAP BusinessObjects Business Intelligence Platform (Web Intelligence), versions 4.1, 4.2, can access database with unencrypted connection, even if the quality of protection should be encrypted.

  • CVE-2019-0346MedAug 14, 2019
    risk 0.42cvss 6.5epss 0.01

    Unencrypted communication error in SAP Business Objects Business Intelligence Platform (Central Management Console), version 4.2, leads to disclosure of list of user names and roles imported from SAP NetWeaver BI systems, resulting in Information Disclosure.

  • CVE-2019-14664MedAug 5, 2019
    risk 0.42cvss 6.5epss 0.01

    In Enigmail below 2.1, an attacker in possession of PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This modified multipart email can be re-sent by the…