VYPR

CWE-319

Cleartext Transmission of Sensitive Information

BaseDraftLikelihood: High

Description

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-117 · CAPEC-383 · CAPEC-477 · CAPEC-65

CVEs mapped to this weakness (914)

page 38 of 46
  • CVE-2024-25631MedFeb 20, 2024
    risk 0.33cvss 6.1epss 0.00

    Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For Cilium users who have enabled an external kvstore and Wireguard transparent encryption, traffic between pods in the affected cluster is not encrypted. This issue affects Cilium v1.14…

  • CVE-2024-25630MedFeb 20, 2024
    risk 0.33cvss 6.1epss 0.00

    Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For Cilium users who are using CRDs to store Cilium state (the default configuration) and Wireguard transparent encryption, traffic to/from the Ingress and health endpoints is not…

  • CVE-2024-47269MedMay 27, 2026
    risk 0.32cvss 4.9epss 0.00

    Cleartext transmission of sensitive information vulnerability in Export Key functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to obtain sensitive information via unspecified vectors.

  • CVE-2023-30841MedApr 26, 2023
    risk 0.32cvss 6.0epss 0.00

    Baremetal Operator (BMO) is a bare metal host provisioning integration for Kubernetes. Prior to version 0.3.0, ironic and ironic-inspector deployed within Baremetal Operator using the included `deploy.sh` store their `.htpasswd` files as ConfigMaps instead of Secrets. This…

  • CVE-2022-40939MedDec 8, 2022
    risk 0.32cvss 4.9epss 0.00

    In certain Secustation products the administrator account password can be read. This affects V2.5.5.3116-S50-SMA-B20171107A, V2.3.4.1301-M20-TSA-B20150617A, V2.5.5.3116-S50-RXA-B20180502A, V2.5.5.3116-S50-SMA-B20190723A, V2.5.5.3116-S50-SMB-B20161012A,…

  • CVE-2021-25643MedMay 26, 2021
    risk 0.32cvss 4.9epss 0.01

    An issue was discovered in Couchbase Server 5.x and 6.x before 6.5.2 and 6.6.x before 6.6.2. Internal users with administrator privileges, @cbq-engine-cbauth and @index-cbauth, leak credentials in cleartext in the indexer.log file when they make a /listCreateTokens,…

  • CVE-2021-3417MedMar 9, 2021
    risk 0.32cvss 4.9epss 0.01

    An internal product security audit of LXCO, prior to version 1.2.2, discovered that credentials for Lenovo XClarity Administrator (LXCA), if added as a Resource Manager, are encoded then written to an internal LXCO log file each time a session is established with LXCA. Affected…

  • CVE-2020-8356MedMar 9, 2021
    risk 0.32cvss 4.9epss 0.01

    An internal product security audit of LXCO, prior to version 1.2.2, discovered that optional passwords, if specified, for the Syslog and SMTP forwarders are written to an internal LXCO log file in clear text. Affected logs are captured in the First Failure Data Capture (FFDC)…

  • CVE-2020-8355MedFeb 10, 2021
    risk 0.32cvss 4.9epss 0.01

    An internal product security audit of Lenovo XClarity Administrator (LXCA) prior to version 3.1.0 discovered the Windows OS credentials provided by the LXCA user to perform driver updates of managed systems may be captured in the First Failure Data Capture (FFDC) service log if…

  • CVE-2019-15635MedSep 23, 2019
    risk 0.32cvss 4.9epss 0.02

    An issue was discovered in Grafana 5.4.0. Passwords for data sources used by Grafana (e.g., MySQL) are not encrypted. An admin user can reveal passwords for any data source by pressing the "Save and test" button within a data source's settings menu. When watching the transaction…

  • CVE-2026-55568MedJun 23, 2026
    risk 0.31cvss 5.9epss 0.00

    Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, in certain configurations, traffic expected to be protected by TLS on the hop to the proxy is transmitted in cleartext. Proxy authentication credentials (the Proxy-Authorization header, proxy userinfo in the proxy URL, or…

  • CVE-2026-43625MedJun 1, 2026
    risk 0.31cvss 5.9epss 0.00

    CodexBar prior to 0.32.0 contains a session cookie leakage vulnerability that allows network attackers to intercept imported browser session cookies by exploiting improper redirect handling for Amp and Ollama provider sessions. Attackers can position themselves on the network…

  • CVE-2026-41281MedMay 14, 2026
    risk 0.31cvss 4.8epss 0.00

    Android App "あんしんフィルター for au" provided by KDDI CORPORATION contains Cleartext Transmission of Sensitive Information (CWE-319) vulnerability. A man-in-the-middle attacker may access and modify communications transmitted in plaintext, potentially resulting in…

  • CVE-2026-4873MedMay 13, 2026
    risk 0.31cvss 5.9epss 0.00

    A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the same connection pool. If an initial transfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request to that same host bypasses the TLS…

  • CVE-2025-59448MedOct 6, 2025
    risk 0.31cvss 4.7epss 0.00

    Components of the YoSmart YoLink ecosystem through 2025-10-02 leverage unencrypted MQTT to communicate over the internet. An attacker with the ability to monitor network traffic could therefore obtain sensitive information or tamper with the traffic to control affected devices.…

  • CVE-2025-57727MedAug 20, 2025
    risk 0.31cvss 4.7epss 0.00

    In JetBrains IntelliJ IDEA before 2025.2 credentials disclosure was possible via remote reference

  • CVE-2025-43704MedApr 16, 2025
    risk 0.31cvss 4.7epss 0.00

    Arctera/Veritas Data Insight before 7.1.2 can send cleartext credentials when configured to use HTTP Basic Authentication to a Dell Isilon OneFS server.

  • CVE-2022-47895MedDec 22, 2022
    risk 0.31cvss 4.7epss 0.00

    In JetBrains IntelliJ IDEA before 2022.3.1 the "Validate JSP File" action used the HTTP protocol to download required JAR files.

  • CVE-2022-41627MedOct 27, 2022
    risk 0.31cvss 4.8epss 0.00

    The physical IoT device of the AliveCor's KardiaMobile, a smartphone-based personal electrocardiogram (EKG) has no encryption for its data-over-sound protocols. Exploiting this vulnerability could allow an attacker to read patient EKG results or create a denial-of-service…

  • CVE-2020-7308MedApr 15, 2021
    risk 0.31cvss 4.8epss 0.01

    Cleartext Transmission of Sensitive Information between McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Update and McAfee Global Threat Intelligence (GTI) servers using DNS allows a remote attacker to view the requests from ENS and responses from GTI…