VYPR

CWE-319

Cleartext Transmission of Sensitive Information

BaseDraftLikelihood: High

Description

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-117 · CAPEC-383 · CAPEC-477 · CAPEC-65

CVEs mapped to this weakness (914)

page 30 of 46
  • CVE-2023-38275MedOct 22, 2023
    risk 0.38cvss 5.9epss 0.00

    IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 exposes sensitive information in container images which could lead to further attacks against the system. IBM X-Force ID: 260730.

  • CVE-2022-22385MedOct 17, 2023
    risk 0.38cvss 5.9epss 0.00

    IBM Security Verify Privilege On-Premises 11.5 could disclose sensitive information to an attacked due to the transmission of data in clear text. IBM X-Force ID: 221962.

  • CVE-2023-5100MedOct 9, 2023
    risk 0.38cvss 5.9epss 0.00

    Cleartext Transmission of Sensitive Information in RDT400 in SICK APU allows an unprivileged remote attacker to retrieve potentially sensitive information via intercepting network traffic that is not encrypted.

  • CVE-2023-22870MedSep 5, 2023
    risk 0.38cvss 5.9epss 0.00

    IBM Aspera Faspex 5.0.5 transmits sensitive information in cleartext which could be obtained by an attacker using man in the middle techniques. IBM X-Force ID: 244121.

  • CVE-2023-27861MedJun 5, 2023
    risk 0.38cvss 5.9epss 0.00

    IBM Maximo Application Suite - Manage Component 8.8.0 and 8.9.0 transmits sensitive information in cleartext that could be intercepted by an attacker using man in the middle techniques. IBM X-Force ID: 249208.

  • CVE-2019-14942MedApr 16, 2023
    risk 0.38cvss 5.9epss 0.00

    An issue was discovered in GitLab Community and Enterprise Edition before 11.11.8, 12 before 12.0.6, and 12.1 before 12.1.6. Cookies for GitLab Pages (which have access control) could be sent over cleartext HTTP.

  • CVE-2023-1802MedApr 6, 2023
    risk 0.38cvss 5.9epss 0.01

    In Docker Desktop 4.17.x the Artifactory Integration falls back to sending registry credentials over plain HTTP if the HTTPS health check has failed. A targeted network sniffing attack can lead to a disclosure of sensitive information. Only users who have Access Experimental…

  • CVE-2023-0922MedApr 3, 2023
    risk 0.38cvss 5.9epss 0.00

    The Samba AD DC administration tool, when operating against a remote LDAP server, will by default send new or reset passwords over a signed-only connection.

  • CVE-2023-23130MedFeb 1, 2023
    risk 0.38cvss 5.9epss 0.00

    Connectwise Automate 2022.11 is vulnerable to Cleartext authentication. Authentication is being done via HTTP (cleartext) with SSL disabled. OTE: the vendor's position is that, by design, this is controlled by a configuration option in which a customer can choose to use HTTP…

  • CVE-2023-22863MedJan 18, 2023
    risk 0.38cvss 5.9epss 0.00

    IBM Robotic Process Automation 20.12.0 through 21.0.2 defaults to HTTP in some RPA commands when the prefix is not explicitly specified in the URL. This could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 244109.

  • CVE-2022-45478MedDec 5, 2022
    risk 0.38cvss 5.9epss 0.00

    Telepad allows an attacker (in a man-in-the-middle position between the server and a connected device) to see all data (including keypresses) in cleartext. CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

  • CVE-2022-45483MedDec 2, 2022
    risk 0.38cvss 5.9epss 0.00

    Lazy Mouse allows an attacker (in a man in the middle position between the server and a connected device) to see all data (including keypresses) in cleartext. CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

  • CVE-2022-45480MedDec 2, 2022
    risk 0.38cvss 5.9epss 0.00

    PC Keyboard WiFi & Bluetooth allows an attacker (in a man-in-the-middle position between the server and a connected device) to see all data (including keypresses) in cleartext. CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

  • CVE-2022-3206MedOct 17, 2022
    risk 0.38cvss 5.9epss 0.00

    The Passster WordPress plugin before 3.5.5.5.2 stores the password inside a cookie named "passster" using base64 encoding method which is easy to decode. This puts the password at risk in case the cookies get leaked.

  • CVE-2022-38846MedSep 16, 2022
    risk 0.38cvss 5.9epss 0.00

    EspoCRM version 7.1.8 is vulnerable to Missing Secure Flag allowing the browser to send plain text cookies over an insecure channel (HTTP). An attacker may capture the cookie from the insecure channel using MITM attack.

  • CVE-2022-28861MedJul 21, 2022
    risk 0.38cvss 5.9epss 0.01

    The server in Citilog 8.0 allows an attacker (in a man in the middle position between the server and its smart camera Axis M1125) to see FTP credentials in a cleartext HTTP traffic. These can be used for FTP access to the server.

  • CVE-2022-21184MedJun 17, 2022
    risk 0.38cvss 5.9epss 0.00

    An information disclosure vulnerability exists in the License registration functionality of Bachmann Visutec GmbH Atvise 3.5.4, 3.6 and 3.7. A plaintext HTTP request can lead to a disclosure of login credentials. An attacker can perform a man-in-the-middle attack to trigger this…

  • CVE-2022-29733MedJun 2, 2022
    risk 0.38cvss 5.9epss 0.01

    Delta Controls enteliTOUCH 3.40.3935, 3.40.3706, and 3.33.4005 was discovered to transmit and store sensitive information in cleartext. This vulnerability allows attackers to intercept HTTP Cookie authentication credentials via a man-in-the-middle attack.

  • CVE-2020-4970MedMay 19, 2022
    risk 0.38cvss 5.9epss 0.01

    IBM Security Identity Governance and Intelligence 5.2.4, 5.2.5, and 5.2.6 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive…

  • CVE-2021-45894MedApr 5, 2022
    risk 0.38cvss 5.9epss 0.01

    An issue was discovered in Softwarebuero Zauner ARC 4.2.0.4. There is Cleartext Transmission of Sensitive Information.