VYPR

CWE-319

Cleartext Transmission of Sensitive Information

BaseDraftLikelihood: High

Description

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-117 · CAPEC-383 · CAPEC-477 · CAPEC-65

CVEs mapped to this weakness (950)

page 29 of 48
  • CVE-2025-5087MedJun 24, 2025
    risk 0.39cvss —epss 0.00

    Kaleris NAVIS N4 ULC (Ultra Light Client) communicates insecurely using zlib-compressed data over HTTP. An attacker capable of observing network traffic between Ultra Light Clients and N4 servers can extract sensitive information, including plaintext credentials.

  • CVE-2024-5631MedJul 9, 2024
    risk 0.39cvss —epss 0.00

    Longse NVR (Network Video Recorder) model NVR3608PGE2W, as well as products based on this device, are transmitting user's login and password to a remote control service without using any encryption. This enables an on-path attacker to eavesdrop the credentials and subsequently…

  • CVE-2023-0001MedFeb 8, 2023
    risk 0.39cvss 6.0epss 0.00

    An information exposure vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local system administrator to disclose the admin password for the agent in cleartext, which bad actors can then use to execute privileged cytool commands that disable or…

  • CVE-2020-25605MedFeb 17, 2021
    risk 0.39cvss 5.9epss 0.06

    Cleartext transmission of sensitive information in Agora Video SDK prior to 3.1 allows a remote attacker to obtain access to audio and video of any ongoing Agora video call through observation of cleartext network traffic.

  • CVE-2020-1343MedJun 9, 2020
    risk 0.39cvss 5.9epss 0.03

    An information disclosure vulnerability exists in Visual Studio Code Live Share Extension when it exposes tokens in plain text, aka 'Visual Studio Code Live Share Information Disclosure Vulnerability'.

  • CVE-2012-1257MedNov 20, 2019
    risk 0.39cvss 5.5epss 0.01

    Pidgin 2.10.0 uses DBUS for certain cleartext communication, which allows local users to obtain sensitive information via a dbus session monitor.

  • CVE-2017-6341MedFeb 27, 2017
    risk 0.39cvss 5.9epss 0.08

    Dahua DHI-HCVR7216A-S3 devices with NVR Firmware 3.210.0001.10 2016-06-06, Camera Firmware 2.400.0000.28.R 2016-03-29, and SmartPSS Software 1.16.1 2017-01-19 send cleartext passwords in response to requests from the Web Page, Mobile Application, and Desktop Application…

  • CVE-2026-86689MedSep 18, 2026
    risk 0.38cvss 5.9epss 0.00

    Bransys ELD is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active device across a subset of carriers that were connected to the affected MQTT broker.

  • CVE-2025-36421MedSep 18, 2026
    risk 0.38cvss 5.9epss 0.00

    IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.

  • CVE-2026-87482MedSep 9, 2026
    risk 0.38cvss 5.9epss 0.00

    Cleartext transmission of sensitive data in HttpsUpgrades in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via crafted network traffic. (Chromium security severity: Medium)

  • CVE-2026-73756MedSep 1, 2026
    risk 0.38cvss 5.9epss 0.00

    A vulnerability in an API endpoint of AOS-CX could allow a remote unauthenticated attacker to obtain sensitive information via a man-in-the-middle attack. Successful exploitation allows an attacker to retrieve data which could be used to further compromise the confidentiality of…

  • CVE-2026-36610MedJun 3, 2026
    risk 0.38cvss 5.9epss 0.00

    Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 transmits DDNS credentials over plaintext HTTP with only Base64 encoding. The firmware contains no TLS implementation, allowing man-in-the-middle interception of DDNS service credentials.

  • CVE-2023-52951MedJun 3, 2026
    risk 0.38cvss 5.9epss 0.00

    A cleartext transmission of sensitive information vulnerability in Synology Note Station Client before 2.2.4-703 allows man-in-the-middle attackers to obtain user credential.

  • CVE-2026-10584MedJun 2, 2026
    risk 0.38cvss 5.9epss 0.00

    Proxy server in Graph Explorer before 3.0.1 falls back to HTTP when certificate files are missing, which might allow remote threat actors to obtain sensitive information via interception of requests intended to be sent over HTTPS. To remediate this issue, users should upgrade…

  • CVE-2026-5119MedMar 30, 2026
    risk 0.38cvss 5.9epss 0.00

    A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext within the initial HTTP CONNECT request. A network-positioned attacker or a malicious HTTP proxy can intercept these cookies,…

  • CVE-2025-64648MedMar 25, 2026
    risk 0.38cvss 5.9epss 0.00

    IBM Concert 1.0.0 through 2.2.0 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.

  • CVE-2025-13490MedMar 3, 2026
    risk 0.38cvss 5.9epss 0.00

    IBM App Connect Operator versions CD 11.3.0 through 11.6.0 and 12.1.0 through 12.20.0, LTS versions 12.0.0 through 12.0.20, and IBM App Connect Enterprise Certified Containers Operands versions CD 12.0.11.2‑r1 through 12.0.12.5‑r1 and 13.0.1.0‑r1 through 13.0.6.1‑r1, and…

  • CVE-2026-27752MedFeb 27, 2026
    risk 0.38cvss 5.9epss 0.00

    SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 transmit authentication credentials over unencrypted HTTP, allowing attackers to capture credentials. An attacker positioned to observe network traffic between a user and the device can intercept credentials and reuse…

  • CVE-2025-27903MedFeb 17, 2026
    risk 0.38cvss 5.9epss 0.00

    IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 IBM Db2 Recovery Expert for Linux, UNIX and Windows transmits data in a cleartext communication channel that could allow an attacker to obtain sensitive information using man in the middle techniques.

  • CVE-2026-24441MedFeb 3, 2026
    risk 0.38cvss 5.9epss 0.00

    Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior expose account credentials in plaintext within HTTP responses, allowing an on-path attacker to obtain sensitive authentication material.