CWE-319
Cleartext Transmission of Sensitive Information
Description
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-102 · CAPEC-117 · CAPEC-383 · CAPEC-477 · CAPEC-65
CVEs mapped to this weakness (914)
page 37 of 46| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-35246 | Med | 0.34 | 5.3 | 0.00 | Nov 23, 2022 | The application fails to prevent users from connecting to it over unencrypted connections. An attacker able to modify a legitimate user's network traffic could bypass the application's use of SSL/TLS encryption and use the application as a platform for attacks against its users. | ||
| CVE-2021-38828 | Med | 0.34 | 5.3 | 0.00 | Nov 14, 2022 | Xiongmai Camera XM-JPR2-LX V4.02.R12.A6420987.10002.147502.00000 is vulnerable to plain-text traffic sniffing. | ||
| CVE-2021-3792 | Med | 0.34 | 5.3 | 0.00 | Nov 12, 2021 | Some device communications in some Motorola-branded Binatone Hubble Cameras with backend Hubble services are not encrypted which could lead to the communication channel being accessible by an attacker. | ||
| CVE-2021-39882 | Med | 0.34 | 5.3 | 0.01 | Oct 5, 2021 | In all versions of GitLab CE/EE, provided a user ID, anonymous users can use a few endpoints to retrieve information about any GitLab user. | ||
| CVE-2021-36165 | Med | 0.34 | 5.3 | 0.01 | Sep 28, 2021 | RICON Industrial Cellular Router S9922L 16.10.3(3794) is affected by cleartext storage of sensitive information and sends username and password as base64. | ||
| CVE-2021-38373 | Med | 0.34 | 5.3 | 0.01 | Aug 10, 2021 | In KDE KMail 19.12.3 (aka 5.13.3), the SMTP STARTTLS option is not honored (and cleartext messages are sent) unless "Server requires authentication" is checked. | ||
| CVE-2020-12730 | Med | 0.34 | 5.3 | 0.00 | Jul 15, 2021 | MagicMotion Flamingo 2 lacks BLE encryption, enabling data sniffing and packet forgery. | ||
| CVE-2021-22325 | Med | 0.34 | 5.3 | 0.00 | Jun 3, 2021 | There is an Information Disclosure vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may result in video streams being intercepted during transmission. | ||
| CVE-2020-15785 | Med | 0.34 | 5.3 | 0.01 | Sep 9, 2020 | A vulnerability has been identified in Siveillance Video Client (All versions). In environments where Windows NTLM authentication is enabled the affected client application transmits usernames to the server in cleartext. This could allow an attacker in a privileged network… | ||
| CVE-2020-4092 | Med | 0.34 | 5.3 | 0.00 | May 6, 2020 | "If port encryption is not enabled on the Domino Server, HCL Nomad on Android and iOS Platforms will communicate in clear text and does not currently have a user interface option to change the setting to request an encrypted communication channel with the Domino server. This can… | ||
| CVE-2020-2155 | Med | 0.34 | 5.3 | 0.01 | Mar 9, 2020 | Jenkins OpenShift Deployer Plugin 1.2.0 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure. | ||
| CVE-2020-2149 | Med | 0.34 | 5.3 | 0.01 | Mar 9, 2020 | Jenkins Repository Connector Plugin 1.2.6 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure. | ||
| CVE-2015-7542 | Med | 0.34 | 5.3 | 0.00 | Dec 3, 2019 | A vulnerability exists in libgwenhywfar through 4.12.0 due to the usage of outdated bundled CA certificates. | ||
| CVE-2019-19463 | Med | 0.34 | 5.3 | 0.00 | Nov 30, 2019 | The Anhui Huami Mi Fit application before 4.0.11 for Android has an Unencrypted Update Check. | ||
| CVE-2018-19111 | Med | 0.34 | 5.3 | 0.00 | Nov 8, 2018 | The Google Cardboard application 1.8 for Android and 1.2 for iOS sends potentially private cleartext information to the Unity 3D Stats web site, as demonstrated by device make, model, and OS. | ||
| CVE-2017-8154 | Med | 0.34 | 5.3 | 0.00 | Apr 11, 2018 | The Themes App Honor 8 Lite Huawei mobile phones with software of versions before Prague-L31C576B172, versions before Prague-L31C530B160, versions before Prague-L31C432B180 has a man-in-the-middle (MITM) vulnerability due to the use of the insecure HTTP protocol for theme… | ||
| CVE-2007-4786 | Med | 0.34 | 5.3 | 0.01 | Sep 10, 2007 | Cisco Adaptive Security Appliance (ASA) running PIX 7.0 before 7.0.7.1, 7.1 before 7.1.2.61, 7.2 before 7.2.2.34, and 8.0 before 8.0.2.11, when AAA is enabled, composes %ASA-5-111008 messages from the "test aaa" command with cleartext passwords and sends them over the network to… | ||
| CVE-2024-35210 | Med | 0.33 | 5.1 | 0.00 | Jun 11, 2024 | A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected web server is not enforcing HSTS. This could allow an attacker to perform downgrade attacks exposing confidential information. | ||
| CVE-2024-28250 | Med | 0.33 | 6.1 | 0.00 | Mar 18, 2024 | Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Starting in version 1.14.0 and prior to versions 1.14.8 and 1.15.2, In Cilium clusters with WireGuard enabled and traffic matching Layer 7 policies Wireguard-eligible traffic that is sent… | ||
| CVE-2024-28249 | Med | 0.33 | 6.1 | 0.00 | Mar 18, 2024 | Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.13.13, 1.14.8, and 1.15.2, in Cilium clusters with IPsec enabled and traffic matching Layer 7 policies, IPsec-eligible traffic between a node's Envoy proxy and pods on… |
- risk 0.34cvss 5.3epss 0.00
The application fails to prevent users from connecting to it over unencrypted connections. An attacker able to modify a legitimate user's network traffic could bypass the application's use of SSL/TLS encryption and use the application as a platform for attacks against its users.
- risk 0.34cvss 5.3epss 0.00
Xiongmai Camera XM-JPR2-LX V4.02.R12.A6420987.10002.147502.00000 is vulnerable to plain-text traffic sniffing.
- risk 0.34cvss 5.3epss 0.00
Some device communications in some Motorola-branded Binatone Hubble Cameras with backend Hubble services are not encrypted which could lead to the communication channel being accessible by an attacker.
- risk 0.34cvss 5.3epss 0.01
In all versions of GitLab CE/EE, provided a user ID, anonymous users can use a few endpoints to retrieve information about any GitLab user.
- risk 0.34cvss 5.3epss 0.01
RICON Industrial Cellular Router S9922L 16.10.3(3794) is affected by cleartext storage of sensitive information and sends username and password as base64.
- risk 0.34cvss 5.3epss 0.01
In KDE KMail 19.12.3 (aka 5.13.3), the SMTP STARTTLS option is not honored (and cleartext messages are sent) unless "Server requires authentication" is checked.
- risk 0.34cvss 5.3epss 0.00
MagicMotion Flamingo 2 lacks BLE encryption, enabling data sniffing and packet forgery.
- risk 0.34cvss 5.3epss 0.00
There is an Information Disclosure vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may result in video streams being intercepted during transmission.
- risk 0.34cvss 5.3epss 0.01
A vulnerability has been identified in Siveillance Video Client (All versions). In environments where Windows NTLM authentication is enabled the affected client application transmits usernames to the server in cleartext. This could allow an attacker in a privileged network…
- risk 0.34cvss 5.3epss 0.00
"If port encryption is not enabled on the Domino Server, HCL Nomad on Android and iOS Platforms will communicate in clear text and does not currently have a user interface option to change the setting to request an encrypted communication channel with the Domino server. This can…
- risk 0.34cvss 5.3epss 0.01
Jenkins OpenShift Deployer Plugin 1.2.0 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.
- risk 0.34cvss 5.3epss 0.01
Jenkins Repository Connector Plugin 1.2.6 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.
- risk 0.34cvss 5.3epss 0.00
A vulnerability exists in libgwenhywfar through 4.12.0 due to the usage of outdated bundled CA certificates.
- risk 0.34cvss 5.3epss 0.00
The Anhui Huami Mi Fit application before 4.0.11 for Android has an Unencrypted Update Check.
- risk 0.34cvss 5.3epss 0.00
The Google Cardboard application 1.8 for Android and 1.2 for iOS sends potentially private cleartext information to the Unity 3D Stats web site, as demonstrated by device make, model, and OS.
- risk 0.34cvss 5.3epss 0.00
The Themes App Honor 8 Lite Huawei mobile phones with software of versions before Prague-L31C576B172, versions before Prague-L31C530B160, versions before Prague-L31C432B180 has a man-in-the-middle (MITM) vulnerability due to the use of the insecure HTTP protocol for theme…
- risk 0.34cvss 5.3epss 0.01
Cisco Adaptive Security Appliance (ASA) running PIX 7.0 before 7.0.7.1, 7.1 before 7.1.2.61, 7.2 before 7.2.2.34, and 8.0 before 8.0.2.11, when AAA is enabled, composes %ASA-5-111008 messages from the "test aaa" command with cleartext passwords and sends them over the network to…
- risk 0.33cvss 5.1epss 0.00
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected web server is not enforcing HSTS. This could allow an attacker to perform downgrade attacks exposing confidential information.
- risk 0.33cvss 6.1epss 0.00
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Starting in version 1.14.0 and prior to versions 1.14.8 and 1.15.2, In Cilium clusters with WireGuard enabled and traffic matching Layer 7 policies Wireguard-eligible traffic that is sent…
- risk 0.33cvss 6.1epss 0.00
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.13.13, 1.14.8, and 1.15.2, in Cilium clusters with IPsec enabled and traffic matching Layer 7 policies, IPsec-eligible traffic between a node's Envoy proxy and pods on…