VYPR

CWE-319

Cleartext Transmission of Sensitive Information

BaseDraftLikelihood: High

Description

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-117 · CAPEC-383 · CAPEC-477 · CAPEC-65

CVEs mapped to this weakness (914)

page 6 of 46
  • CVE-2022-22758HigDec 22, 2022
    risk 0.57cvss 8.8epss 0.00

    When clicking on a tel: link, USSD codes, specified after a \* character, would be included in the phone number. On certain phones, or on certain carriers, if the number was dialed this could perform actions on a user's account, similar to a cross-site request…

  • CVE-2021-3590HigAug 22, 2022
    risk 0.57cvss 8.8epss 0.01

    A flaw was found in Foreman project. A credential leak was identified which will expose Azure Compute Profile password through JSON of the API output. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

  • CVE-2022-29874HigMay 20, 2022
    risk 0.57cvss 8.8epss 0.01

    A vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices do not encrypt web traffic with clients but communicate in cleartext via HTTP. This could allow an unauthenticated attacker to capture the traffic and interfere with the functionality of the…

  • CVE-2022-24978HigApr 5, 2022
    risk 0.57cvss 8.8epss 0.01

    Zoho ManageEngine ADAudit Plus before 7055 allows authenticated Privilege Escalation on Integrated products. This occurs because a password field is present in a JSON response.

  • CVE-2021-38418HigNov 3, 2021
    risk 0.57cvss 8.8epss 0.01

    Delta Electronics DIALink versions 1.2.4.0 and prior runs by default on HTTP, which may allow an attacker to be positioned between the traffic and perform a machine-in-the-middle attack to access information without authorization.

  • CVE-2021-38142HigSep 7, 2021
    risk 0.57cvss 8.8epss 0.00

    Barco MirrorOp Windows Sender before 2.5.3.65 uses cleartext HTTP and thus allows rogue software upgrades. An attacker on the local network can achieve remote code execution on any computer that tries to update Windows Sender due to the fact that the upgrade mechanism is not…

  • CVE-2021-23846HigJun 18, 2021
    risk 0.57cvss 8.8epss 0.01

    When using http protocol, the user password is transmitted as a clear text parameter for which it is possible to be obtained by an attacker through a MITM attack. This will be fixed starting from Firmware version 3.11.5, which will be released on the 30th of June, 2021.

  • CVE-2021-27251HigApr 14, 2021
    risk 0.57cvss 8.8epss 0.01

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR Nighthawk R7800. Authentication is not required to exploit this vulnerability The specific flaw exists within handling of firmware updates. The issue results from…

  • CVE-2021-27194HigMar 25, 2021
    risk 0.57cvss 8.8epss 0.00

    Cleartext transmission of sensitive information in Netop Vision Pro up to and including 9.7.1 allows a remote unauthenticated attacker to gather credentials including Windows login usernames and passwords.

  • CVE-2020-15062HigAug 7, 2020
    risk 0.57cvss 8.8epss 0.00

    DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to elevate privileges because the administrative password can be discovered by sniffing unencrypted UDP traffic.

  • CVE-2020-15058HigAug 7, 2020
    risk 0.57cvss 8.8epss 0.00

    Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to elevate privileges because the administrative password can be discovered by sniffing unencrypted UDP traffic.

  • CVE-2020-15054HigAug 7, 2020
    risk 0.57cvss 8.8epss 0.00

    TP-Link USB Network Server TL-PS310U devices before 2.079.000.t0210 allow an attacker on the same network to elevate privileges because the administrative password can be discovered by sniffing unencrypted UDP traffic.

  • CVE-2019-18800HigNov 6, 2019
    risk 0.57cvss 8.8epss 0.02

    Viber through 11.7.0.5 allows a remote attacker who can capture a victim's internet traffic to steal their Viber account, because not all Viber protocol traffic is encrypted. TCP data packet 9 on port 4244 from the victim's device contains cleartext information such as the…

  • CVE-2019-16924HigSep 27, 2019
    risk 0.57cvss 8.8epss 0.01

    The Nulock application 1.5.0 for mobile devices sends a cleartext password over Bluetooth, which allows remote attackers (after sniffing the network) to take control of the lock.

  • CVE-2019-12506HigJun 7, 2019
    risk 0.57cvss 8.8epss 0.01

    Due to unencrypted and unauthenticated data communication, the wireless presenter Logitech R700 Laser Presentation Remote R-R0010 is prone to keystroke injection attacks. Thus, an attacker is able to send arbitrary keystrokes to a victim's computer system, e.g., to install…

  • CVE-2019-12505HigJun 7, 2019
    risk 0.57cvss 8.8epss 0.01

    Due to unencrypted and unauthenticated data communication, the wireless presenter Inateck WP1001 v1.3C is prone to keystroke injection attacks. Thus, an attacker is able to send arbitrary keystrokes to a victim's computer system, e.g., to install malware when the target system…

  • CVE-2019-12504HigJun 7, 2019
    risk 0.57cvss 8.8epss 0.02

    Due to unencrypted and unauthenticated data communication, the wireless presenter Inateck WP2002 is prone to keystroke injection attacks. Thus, an attacker is able to send arbitrary keystrokes to a victim's computer system, e.g., to install malware when the target system is…

  • CVE-2018-8842HigSep 26, 2018
    risk 0.57cvss 8.8epss 0.01

    Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors. The Philips e-Alert communication channel is not encrypted which…

  • CVE-2018-11050HigAug 1, 2018
    risk 0.57cvss 8.8epss 0.01

    Dell EMC NetWorker versions between 9.0 and 9.1.1.8 through 9.2.1.3, and the version 18.1.0.1 contain a Clear-Text authentication over network vulnerability in the Rabbit MQ Advanced Message Queuing Protocol (AMQP) component. User credentials are sent unencrypted to the remote…

  • CVE-2025-47698HigSep 18, 2025
    risk 0.56cvss epss 0.00

    An adjacent attacker without authentication can exploit this vulnerability to retrieve a set of user-privileged credentials. These credentials are present during the firmware upgrade procedure.