VYPR

CWE-319

Cleartext Transmission of Sensitive Information

BaseDraftLikelihood: High

Description

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-117 · CAPEC-383 · CAPEC-477 · CAPEC-65

CVEs mapped to this weakness (954)

page 33 of 48
  • CVE-2021-20564MedMay 14, 2021
    risk 0.38cvss 5.9epss 0.01

    IBM Cloud Pak for Security (CP4S) 1.4.0.0, 1.5.0.0, 1.5.0.1, 1.6.0.0, and 1.6.0.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain…

  • CVE-2020-27184MedMay 14, 2021
    risk 0.38cvss 5.9epss 0.00

    The NPort IA5000A Series devices use Telnet as one of the network device management services. Telnet does not support the encryption of client-server communications, making it vulnerable to Man-in-the-Middle attacks.

  • CVE-2021-3494MedApr 26, 2021
    risk 0.38cvss 5.9epss 0.00

    A smart proxy that provides a restful API to various sub-systems of the Foreman is affected by the flaw which can cause a Man-in-the-Middle attack. The FreeIPA module of Foreman smart proxy does not check the SSL certificate, thus, an unauthenticated attacker can perform actions…

  • CVE-2021-20409MedFeb 12, 2021
    risk 0.38cvss 5.9epss 0.01

    IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in…

  • CVE-2020-4969MedJan 21, 2021
    risk 0.38cvss 5.9epss 0.01

    IBM Security Identity Governance and Intelligence 5.2.6 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man…

  • CVE-2020-4893MedJan 7, 2021
    risk 0.38cvss 5.9epss 0.01

    IBM Emptoris Strategic Supply Management 10.1.0, 10.1.1, and 10.1.3 transmits sensitive information in HTTP GET request parameters. This may lead to information disclosure via man in the middle methods. IBM X-Force ID: 190984.

  • CVE-2020-35584MedDec 23, 2020
    risk 0.38cvss 5.9epss 0.01

    In Solstice Pod before 3.0.3, the web services allow users to connect to them over unencrypted channels via the Browser Look-in feature. An attacker suitably positioned to view a legitimate user's network traffic could record and monitor their interactions with the web services…

  • CVE-2020-27586MedNov 30, 2020
    risk 0.38cvss 5.9epss 0.01

    Quick Heal Total Security before version 19.0 transmits quarantine and sysinfo files via clear text.

  • CVE-2020-29380MedNov 29, 2020
    risk 0.38cvss 5.9epss 0.00

    An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600D4L V1.01.49, V1600D-MINI V1.01.48, V1600G1 V2.0.7 and V1.9.7, and V1600G2 V1.1.4 OLT devices. TELNET is offered by default but SSH is not always available. An attacker can intercept passwords sent in cleartext…

  • CVE-2020-29055MedNov 24, 2020
    risk 0.38cvss 5.9epss 0.01

    An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B, FD1104S, FD1104SN, FD1108S, FD1204S-R2, FD1204SN, FD1204SN-R2, FD1208S-R2, FD1216S-R1, FD1608GS, FD1608SN, FD1616GS, FD1616SN,…

  • CVE-2020-9526MedAug 10, 2020
    risk 0.38cvss 5.9epss 0.01

    CS2 Network P2P through 3.x, as used in millions of Internet of Things devices, suffers from an information exposure flaw that exposes user session data to supernodes in the network, as demonstrated by passively eavesdropping on user video/audio streams, capturing credentials,…

  • CVE-2020-4397MedJul 22, 2020
    risk 0.38cvss 5.9epss 0.01

    IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 transmits sensitive information in plain text which could be obtained by an attacker using man in the middle techniques. IBM X-Force ID: 179428.

  • CVE-2019-4667MedMay 11, 2020
    risk 0.38cvss 5.9epss 0.01

    IBM UrbanCode Deploy (UCD) 7.0.5.2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle…

  • CVE-2019-4594MedApr 15, 2020
    risk 0.38cvss 5.9epss 0.01

    IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle…

  • CVE-2019-18285MedDec 12, 2019
    risk 0.38cvss 5.9epss 0.01

    A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The RMI communication between the client and the Application Server is unencrypted. An attacker with access to the communication channel can read credentials of a valid…

  • CVE-2019-0069MedOct 9, 2019
    risk 0.38cvss 5.9epss 0.00

    On EX4600, QFX5100 Series, NFX Series, QFX10K Series, QFX5110, QFX5200 Series, QFX5110, QFX5200, QFX10K Series, vSRX, SRX1500, SRX4000 Series, vSRX, SRX1500, SRX4000, QFX5110, QFX5200, QFX10K Series, when the user uses console management port to authenticate, the credentials…

  • CVE-2019-14959MedOct 2, 2019
    risk 0.38cvss 5.9epss 0.01

    JetBrains Toolbox before 1.15.5605 was resolving an internal URL via a cleartext http connection.

  • CVE-2019-14954MedOct 1, 2019
    risk 0.38cvss 5.9epss 0.01

    JetBrains IntelliJ IDEA before 2019.2 was resolving the markdown plantuml artifact download link via a cleartext http connection.

  • CVE-2016-10933MedAug 26, 2019
    risk 0.38cvss 5.9epss 0.01

    An issue was discovered in the portaudio crate through 0.7.0 for Rust. There is a man-in-the-middle issue because the source code is downloaded over cleartext HTTP.

  • CVE-2019-12813MedJun 13, 2019
    risk 0.38cvss 5.9epss 0.01

    An issue was discovered in Digital Persona U.are.U 4500 Fingerprint Reader v24. The key and salt used for obfuscating the fingerprint image exhibit cleartext when the fingerprint scanner device transfers a fingerprint image to the driver. An attacker who sniffs an encrypted…