VYPR

CWE-319

Cleartext Transmission of Sensitive Information

BaseDraftLikelihood: High

Description

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-117 · CAPEC-383 · CAPEC-477 · CAPEC-65

CVEs mapped to this weakness (914)

page 9 of 46
  • CVE-2019-5448HigJul 30, 2019
    risk 0.53cvss 8.1epss 0.01

    Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Data due to HTTP URLs in lockfile causing unencrypted authentication data to be sent over the network.

  • CVE-2019-11220HigApr 26, 2019
    risk 0.53cvss 8.1epss 0.01

    An authentication flaw in Shenzhen Yunni Technology iLnkP2P allows remote attackers to actively intercept user-to-device traffic in cleartext, including video streams and device credentials.

  • CVE-2018-1360HigApr 25, 2019
    risk 0.53cvss 8.1epss 0.01

    A cleartext transmission of sensitive information vulnerability in Fortinet FortiManager 5.2.0 through 5.2.7, 5.4.0 and 5.4.1 may allow an unauthenticated attacker in a man in the middle position to retrieve the admin password via intercepting REST API JSON responses.

  • CVE-2019-10240HigApr 3, 2019
    risk 0.53cvss 8.1epss 0.00

    Eclipse hawkBit versions prior to 0.3.0M2 resolved Maven build artifacts for the Vaadin based UI over HTTP instead of HTTPS. Any of these dependent artifacts could have been maliciously compromised by a MITM attack. Hence produced build artifacts of hawkBit might be infected.

  • CVE-2018-15752HigOct 2, 2018
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in the MensaMax (aka com.breustedt.mensamax) application 4.3 for Android. Cleartext Transmission of Sensitive Information allows man-in-the-middle attackers to eavesdrop authentication information between the application and the server.

  • CVE-2018-13140HigSep 24, 2018
    risk 0.53cvss 8.1epss 0.07

    Druide Antidote through 9.5.1 on Windows and Linux allows remote code execution through the update mechanism by leveraging use of HTTP to download installation packages.

  • CVE-2017-16040HigJun 4, 2018
    risk 0.53cvss 8.1epss 0.02

    gfe-sass is a library for promises (CommonJS/Promises/A,B,D) gfe-sass downloads resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if…

  • CVE-2017-16035HigJun 4, 2018
    risk 0.53cvss 8.1epss 0.01

    The hubl-server module is a wrapper for the HubL Development Server. During installation hubl-server downloads a set of dependencies from api.hubapi.com. It appears in the code that these files are downloaded over HTTPS however the api.hubapi.com endpoint redirects to a HTTP…

  • CVE-2018-7298HigFeb 22, 2018
    risk 0.53cvss 8.1epss 0.01

    In /usr/local/etc/config/addons/mh/loopupd.sh on eQ-3 AG HomeMatic CCU2 2.29.22 devices, software update packages are downloaded via the HTTP protocol, which does not provide any cryptographic protection of the downloaded contents. An attacker with a privileged network position…

  • CVE-2017-1694HigDec 20, 2017
    risk 0.53cvss 8.1epss 0.01

    IBM Integration Bus 9.0 and 10.0 transmits user credentials in plain in clear text which can be read by an attacker using man in the middle techniques. IBM X-Force ID: 134165.

  • CVE-2017-6432HigMar 9, 2017
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered on Dahua DHI-HCVR7216A-S3 3.210.0001.10 build 2016-06-06 devices. The Dahua DVR Protocol, which operates on TCP Port 37777, is an unencrypted, binary protocol. Performing a Man-in-the-Middle attack allows both sniffing and injections of packets, which…

  • CVE-2025-54818HigSep 18, 2025
    risk 0.52cvss 8.0epss 0.00

    Cognex In-Sight Explorer and In-Sight Camera Firmware expose a proprietary protocol on TCP port 1069 to perform management operations such as modifying system properties. The user management functionality handles sensitive data such as registered usernames and passwords over…

  • CVE-2024-0860HigMar 14, 2024
    risk 0.52cvss 8.0epss 0.01

    The affected product is vulnerable to a cleartext transmission of sensitive information vulnerability, which may allow an attacker to capture packets to craft their own requests.

  • CVE-2014-5380HigJan 13, 2020
    risk 0.52cvss 7.5epss 0.04

    Grand MA 300 allows retrieval of the access PIN from sniffed data.

  • CVE-2019-3993HigDec 17, 2019
    risk 0.52cvss 7.5epss 0.46

    ELOG 3.1.4-57bea22 and below is affected by an information disclosure vulnerability. A remote unauthenticated attacker can recover a user's password hash by sending a crafted HTTP POST request.

  • CVE-2022-41327HigJun 13, 2023
    risk 0.51cvss 7.8epss 0.00

    A cleartext transmission of sensitive information vulnerability [CWE-319] in Fortinet FortiOS version 7.2.0 through 7.2.4, 7.0.0 through 7.0.8, FortiProxy version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.8 allows an authenticated attacker with readonly superadmin privileges to…

  • CVE-2020-15482HigAug 26, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered on Nescomed Multipara Monitor M1000 devices. The device enables an unencrypted TELNET service by default, with a blank password for the admin account. This allows an attacker to gain root access to the device over the local network.

  • CVE-2020-5899HigJul 1, 2020
    risk 0.51cvss 7.8epss 0.00

    In NGINX Controller 3.0.0-3.4.0, recovery code required to change a user's password is transmitted and stored in the database in plain text, which allows an attacker who can intercept the database connection or have read access to the database, to request a password reset using…

  • CVE-2019-9532HigOct 10, 2019
    risk 0.51cvss 7.8epss 0.00

    The web application portal of the Cobham EXPLORER 710, firmware version 1.07, sends the login password in cleartext. This could allow an unauthenticated, local attacker to intercept the password and gain access to the portal.

  • CVE-2025-53139HigOct 14, 2025
    risk 0.50cvss 7.7epss 0.00

    Cleartext transmission of sensitive information in Windows Hello allows an unauthorized attacker to bypass a security feature locally.