CWE-319
Cleartext Transmission of Sensitive Information
Description
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-102 · CAPEC-117 · CAPEC-383 · CAPEC-477 · CAPEC-65
CVEs mapped to this weakness (950)
page 38 of 48| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-25848 | Med | 0.34 | 5.3 | 0.00 | Aug 25, 2023 | ArcGIS Enterprise Server versions 11.0 and below have an information disclosure vulnerability where a remote, unauthorized attacker may submit a crafted query that may result in a low severity information disclosure issue. The information disclosed is limited to a single… | ||
| CVE-2023-31195 | Med | 0.34 | 5.3 | 0.00 | Jun 13, 2023 | ASUS Router RT-AX3000 Firmware versions prior to 3.0.0.4.388.23403 uses sensitive cookies without 'Secure' attribute. When an attacker is in a position to be able to mount a man-in-the-middle attack, and a user is tricked to log into the affected device through an unencrypted… | ||
| CVE-2022-32906 | Med | 0.34 | 5.3 | 0.00 | Feb 27, 2023 | This issue was addressed with using HTTPS when sending information over the network. This issue is fixed in Apple Music 3.9.10 for Android. A user in a privileged network position may intercept SSL/TLS connections. | ||
| CVE-2022-22457 | Med | 0.34 | 5.3 | 0.00 | Dec 22, 2022 | IBM Security Verify Governance, Identity Manager 10.0.1 stores sensitive information including user credentials in plain clear text which can be read by a local privileged user. IBM X-Force ID: 225007. | ||
| CVE-2021-35246 | Med | 0.34 | 5.3 | 0.00 | Nov 23, 2022 | The application fails to prevent users from connecting to it over unencrypted connections. An attacker able to modify a legitimate user's network traffic could bypass the application's use of SSL/TLS encryption and use the application as a platform for attacks against its users. | ||
| CVE-2021-38828 | Med | 0.34 | 5.3 | 0.00 | Nov 14, 2022 | Xiongmai Camera XM-JPR2-LX V4.02.R12.A6420987.10002.147502.00000 is vulnerable to plain-text traffic sniffing. | ||
| CVE-2021-3792 | Med | 0.34 | 5.3 | 0.00 | Nov 12, 2021 | Some device communications in some Motorola-branded Binatone Hubble Cameras with backend Hubble services are not encrypted which could lead to the communication channel being accessible by an attacker. | ||
| CVE-2021-39882 | Med | 0.34 | 5.3 | 0.01 | Oct 5, 2021 | In all versions of GitLab CE/EE, provided a user ID, anonymous users can use a few endpoints to retrieve information about any GitLab user. | ||
| CVE-2021-36165 | Med | 0.34 | 5.3 | 0.01 | Sep 28, 2021 | RICON Industrial Cellular Router S9922L 16.10.3(3794) is affected by cleartext storage of sensitive information and sends username and password as base64. | ||
| CVE-2021-38373 | Med | 0.34 | 5.3 | 0.01 | Aug 10, 2021 | In KDE KMail 19.12.3 (aka 5.13.3), the SMTP STARTTLS option is not honored (and cleartext messages are sent) unless "Server requires authentication" is checked. | ||
| CVE-2020-12730 | Med | 0.34 | 5.3 | 0.00 | Jul 15, 2021 | MagicMotion Flamingo 2 lacks BLE encryption, enabling data sniffing and packet forgery. | ||
| CVE-2021-22325 | Med | 0.34 | 5.3 | 0.00 | Jun 3, 2021 | There is an Information Disclosure vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may result in video streams being intercepted during transmission. | ||
| CVE-2020-15785 | Med | 0.34 | 5.3 | 0.01 | Sep 9, 2020 | A vulnerability has been identified in Siveillance Video Client (All versions). In environments where Windows NTLM authentication is enabled the affected client application transmits usernames to the server in cleartext. This could allow an attacker in a privileged network… | ||
| CVE-2020-4092 | Med | 0.34 | 5.3 | 0.00 | May 6, 2020 | "If port encryption is not enabled on the Domino Server, HCL Nomad on Android and iOS Platforms will communicate in clear text and does not currently have a user interface option to change the setting to request an encrypted communication channel with the Domino server. This can… | ||
| CVE-2020-2155 | Med | 0.34 | 5.3 | 0.01 | Mar 9, 2020 | Jenkins OpenShift Deployer Plugin 1.2.0 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure. | ||
| CVE-2020-2149 | Med | 0.34 | 5.3 | 0.01 | Mar 9, 2020 | Jenkins Repository Connector Plugin 1.2.6 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure. | ||
| CVE-2015-7542 | Med | 0.34 | 5.3 | 0.00 | Dec 3, 2019 | A vulnerability exists in libgwenhywfar through 4.12.0 due to the usage of outdated bundled CA certificates. | ||
| CVE-2019-19463 | Med | 0.34 | 5.3 | 0.00 | Nov 30, 2019 | The Anhui Huami Mi Fit application before 4.0.11 for Android has an Unencrypted Update Check. | ||
| CVE-2018-19111 | Med | 0.34 | 5.3 | 0.00 | Nov 8, 2018 | The Google Cardboard application 1.8 for Android and 1.2 for iOS sends potentially private cleartext information to the Unity 3D Stats web site, as demonstrated by device make, model, and OS. | ||
| CVE-2017-8154 | Med | 0.34 | 5.3 | 0.00 | Apr 11, 2018 | The Themes App Honor 8 Lite Huawei mobile phones with software of versions before Prague-L31C576B172, versions before Prague-L31C530B160, versions before Prague-L31C432B180 has a man-in-the-middle (MITM) vulnerability due to the use of the insecure HTTP protocol for theme… |
- risk 0.34cvss 5.3epss 0.00
ArcGIS Enterprise Server versions 11.0 and below have an information disclosure vulnerability where a remote, unauthorized attacker may submit a crafted query that may result in a low severity information disclosure issue. The information disclosed is limited to a single…
- risk 0.34cvss 5.3epss 0.00
ASUS Router RT-AX3000 Firmware versions prior to 3.0.0.4.388.23403 uses sensitive cookies without 'Secure' attribute. When an attacker is in a position to be able to mount a man-in-the-middle attack, and a user is tricked to log into the affected device through an unencrypted…
- risk 0.34cvss 5.3epss 0.00
This issue was addressed with using HTTPS when sending information over the network. This issue is fixed in Apple Music 3.9.10 for Android. A user in a privileged network position may intercept SSL/TLS connections.
- risk 0.34cvss 5.3epss 0.00
IBM Security Verify Governance, Identity Manager 10.0.1 stores sensitive information including user credentials in plain clear text which can be read by a local privileged user. IBM X-Force ID: 225007.
- risk 0.34cvss 5.3epss 0.00
The application fails to prevent users from connecting to it over unencrypted connections. An attacker able to modify a legitimate user's network traffic could bypass the application's use of SSL/TLS encryption and use the application as a platform for attacks against its users.
- risk 0.34cvss 5.3epss 0.00
Xiongmai Camera XM-JPR2-LX V4.02.R12.A6420987.10002.147502.00000 is vulnerable to plain-text traffic sniffing.
- risk 0.34cvss 5.3epss 0.00
Some device communications in some Motorola-branded Binatone Hubble Cameras with backend Hubble services are not encrypted which could lead to the communication channel being accessible by an attacker.
- risk 0.34cvss 5.3epss 0.01
In all versions of GitLab CE/EE, provided a user ID, anonymous users can use a few endpoints to retrieve information about any GitLab user.
- risk 0.34cvss 5.3epss 0.01
RICON Industrial Cellular Router S9922L 16.10.3(3794) is affected by cleartext storage of sensitive information and sends username and password as base64.
- risk 0.34cvss 5.3epss 0.01
In KDE KMail 19.12.3 (aka 5.13.3), the SMTP STARTTLS option is not honored (and cleartext messages are sent) unless "Server requires authentication" is checked.
- risk 0.34cvss 5.3epss 0.00
MagicMotion Flamingo 2 lacks BLE encryption, enabling data sniffing and packet forgery.
- risk 0.34cvss 5.3epss 0.00
There is an Information Disclosure vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may result in video streams being intercepted during transmission.
- risk 0.34cvss 5.3epss 0.01
A vulnerability has been identified in Siveillance Video Client (All versions). In environments where Windows NTLM authentication is enabled the affected client application transmits usernames to the server in cleartext. This could allow an attacker in a privileged network…
- risk 0.34cvss 5.3epss 0.00
"If port encryption is not enabled on the Domino Server, HCL Nomad on Android and iOS Platforms will communicate in clear text and does not currently have a user interface option to change the setting to request an encrypted communication channel with the Domino server. This can…
- risk 0.34cvss 5.3epss 0.01
Jenkins OpenShift Deployer Plugin 1.2.0 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.
- risk 0.34cvss 5.3epss 0.01
Jenkins Repository Connector Plugin 1.2.6 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.
- risk 0.34cvss 5.3epss 0.00
A vulnerability exists in libgwenhywfar through 4.12.0 due to the usage of outdated bundled CA certificates.
- risk 0.34cvss 5.3epss 0.00
The Anhui Huami Mi Fit application before 4.0.11 for Android has an Unencrypted Update Check.
- risk 0.34cvss 5.3epss 0.00
The Google Cardboard application 1.8 for Android and 1.2 for iOS sends potentially private cleartext information to the Unity 3D Stats web site, as demonstrated by device make, model, and OS.
- risk 0.34cvss 5.3epss 0.00
The Themes App Honor 8 Lite Huawei mobile phones with software of versions before Prague-L31C576B172, versions before Prague-L31C530B160, versions before Prague-L31C432B180 has a man-in-the-middle (MITM) vulnerability due to the use of the insecure HTTP protocol for theme…