VYPR

CWE-319

Cleartext Transmission of Sensitive Information

BaseDraftLikelihood: High

Description

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-117 · CAPEC-383 · CAPEC-477 · CAPEC-65

CVEs mapped to this weakness (950)

page 7 of 48
  • CVE-2019-12504HigJun 7, 2019
    risk 0.57cvss 8.8epss 0.02

    Due to unencrypted and unauthenticated data communication, the wireless presenter Inateck WP2002 is prone to keystroke injection attacks. Thus, an attacker is able to send arbitrary keystrokes to a victim's computer system, e.g., to install malware when the target system is…

  • CVE-2018-8842HigSep 26, 2018
    risk 0.57cvss 8.8epss 0.01

    Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors. The Philips e-Alert communication channel is not encrypted which…

  • CVE-2018-11050HigAug 1, 2018
    risk 0.57cvss 8.8epss 0.01

    Dell EMC NetWorker versions between 9.0 and 9.1.1.8 through 9.2.1.3, and the version 18.1.0.1 contain a Clear-Text authentication over network vulnerability in the Rabbit MQ Advanced Message Queuing Protocol (AMQP) component. User credentials are sent unencrypted to the remote…

  • CVE-2025-47698HigSep 18, 2025
    risk 0.56cvss —epss 0.00

    An adjacent attacker without authentication can exploit this vulnerability to retrieve a set of user-privileged credentials. These credentials are present during the firmware upgrade procedure.

  • CVE-2024-4161HigApr 25, 2024
    risk 0.56cvss 8.6epss 0.00

    In Brocade SANnav, before Brocade SANnav v2.3.0, syslog traffic received clear text. This could allow an unauthenticated, remote attacker to capture sensitive information.

  • CVE-2023-3028HigJun 1, 2023
    risk 0.56cvss 8.6epss 0.00

    Insufficient authentication in the MQTT backend (broker) allows an attacker to access and even manipulate the telemetry data of the entire fleet of vehicles using the HopeChart HQT-401 telematics unit. Other models are possibly affected too. Multiple vulnerabilities were…

  • CVE-2020-14930HigJun 19, 2020
    risk 0.56cvss 8.1epss 0.03

    An issue was discovered in BT CTROMS Terminal OS Port Portal CT-464. Account takeover can occur because the password-reset feature discloses the verification token. Upon a getverificationcode.jsp request, this token is transmitted not only to the registered phone number of the…

  • CVE-2012-5562HigDec 2, 2019
    risk 0.56cvss 8.6epss 0.01

    A flaw was found in rhn-proxy. This vulnerability may allow the rhn-proxy to transmit user credentials in clear-text when it accesses RHN Satellite. This could lead to information disclosure, where sensitive authentication details are exposed to unauthorized parties.

  • CVE-2018-1600HigJun 4, 2018
    risk 0.56cvss 8.6epss 0.01

    IBM BigFix Platform 9.2 and 9.5 transmits sensitive or security-critical data in clear text in a communication channel that can be sniffed by unauthorized actors. IBM X-Force ID: 143745.

  • CVE-2025-12508HigOct 31, 2025
    risk 0.55cvss 8.4epss 0.00

    When using domain users as BRAIN2 users, communication with Active Directory services is unencrypted. This can lead to the interception of authentication data and compromise confidentiality.

  • CVE-2025-55976HigSep 10, 2025
    risk 0.55cvss 8.4epss 0.03

    Intelbras IWR 3000N 1.9.8 exposes the Wi-Fi password in plaintext via the /api/wireless endpoint. Any unauthenticated user on the local network can directly obtain the Wi-Fi network password by querying this endpoint.

  • CVE-2025-6180HigAug 20, 2025
    risk 0.55cvss —epss 0.00

    The StrongDM Client insufficiently protected a pre-authentication token. Attackers could exploit this to intercept and reuse the token, potentially redeeming valid authentication credentials through a race condition.

  • CVE-2022-0162HigFeb 9, 2022
    risk 0.55cvss 8.4epss 0.01

    The vulnerability exists in TP-Link TL-WR841N V11 3.16.9 Build 160325 Rel.62500n wireless router due to transmission of authentication information in cleartextbase64 format. Successful exploitation of this vulnerability could allow a remote attacker to intercept credentials and…

  • CVE-2021-39341HigNov 1, 2021
    risk 0.55cvss 8.2epss 0.22

    The OptinMonster WordPress plugin is vulnerable to sensitive information disclosure and unauthorized setting updates due to insufficient authorization validation via the logged_in_or_has_api_key function in the ~/OMAPI/RestApi.php file that can used to exploit inject malicious…

  • CVE-2025-10174HigFeb 11, 2026
    risk 0.54cvss 8.3epss 0.00

    Cleartext Transmission of Sensitive Information vulnerability in Pan Software & Information Technologies Ltd. PanCafe Pro allows Flooding. This issue affects PanCafe Pro: from < 3.3.2 through 23092025.

  • CVE-2025-64389HigOct 31, 2025
    risk 0.54cvss —epss 0.00

    The web server of the device performs exchanges of sensitive information in clear text through an insecure protocol.

  • CVE-2024-0220HigFeb 22, 2024
    risk 0.54cvss 8.3epss 0.00

    B&R Automation Studio Upgrade Service and B&R Technology Guarding use insufficient cryptography for communication to the upgrade and the licensing servers. A network-based attacker could exploit the vulnerability to execute arbitrary code on the products or sniff sensitive data.

  • CVE-2023-45321HigOct 25, 2023
    risk 0.54cvss 8.3epss 0.00

    The Android Client application, when enrolled with the define method 1 (the user manually inserts the server ip address), use HTTP protocol to retrieve sensitive information (ip address and credentials to connect to a remote MQTT broker entity) instead of HTTPS and this feature…

  • CVE-2022-3929HigJan 5, 2023
    risk 0.54cvss 8.3epss 0.00

    Communication between the client and the server application of the affected products is partially done using CORBA (Common Object Request Broker Architecture) over TCP/IP. This protocol is not encrypted and allows tracing of internal messages. This issue affects * …

  • CVE-2022-45877HigDec 8, 2022
    risk 0.54cvss 8.3epss 0.00

    OpenHarmony-v3.1.4 and prior versions had an vulnerability. PIN code is transmitted to the peer device in plain text during cross-device authentication, which reduces the difficulty of man-in-the-middle attacks.