CWE-319— Cleartext Transmission of Sensitive Information
842 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-319page 1 of 17
- CVE-2002-1949HIGHCVSS 7.5EG 7.52002-12-31
The Network Attached Storage (NAS) Administration Web Page for Iomega NAS A300U transmits passwords in cleartext, which allows remote attackers to sniff the administrative password.
- CVE-2003-5002LOWCVSS 3.7EG 5.32022-03-28
A vulnerability was found in ISS BlackICE PC Protection. It has been declared as problematic. Affected by this vulnerability is the component Update Handler which allows cleartext transmission of data. NOTE: This vulnerability only affects…
- CVE-2004-1852NONECVSS 0.0EG 0.02004-03-23
DameWare Mini Remote Control 3.x before 3.74 and 4.x before 4.2 transmits the Blowfish encryption key in plaintext, which allows remote attackers to gain sensitive information.
- CVE-2005-2069NONECVSS 0.0EG 0.02005-06-30
pam_ldap and nss_ldap, when used with OpenLDAP and connecting to a slave using TLS, does not use TLS for the subsequent connection if the client is referred to a master, which may cause a password to be sent in cleartext and allows remote …
- CVE-2005-3140HIGHCVSS 7.5EG 7.52005-10-05
Procom NetFORCE 800 4.02 M10 Build 20 and possibly other versions sends the NIS password map (passwd.nis) as a file attachment in diagnostic e-mail messages, which allows remote attackers to obtain the cleartext NIS password hashes.
- CVE-2007-4786MEDIUMCVSS 5.3EG 5.32007-09-10
Cisco Adaptive Security Appliance (ASA) running PIX 7.0 before 7.0.7.1, 7.1 before 7.1.2.61, 7.2 before 7.2.2.34, and 8.0 before 8.0.2.11, when AAA is enabled, composes %ASA-5-111008 messages from the "test aaa" command with cleartext pass…
- CVE-2007-5626MEDIUMCVSS 5.5EG 5.52007-10-23
make_catalog_backup in Bacula 2.2.5, and probably earlier, sends a MySQL password as a command line argument, and sometimes transmits cleartext e-mail containing this command line, which allows context-dependent attackers to obtain the pas…
- CVE-2008-0374HIGHCVSS 7.5EG 7.52008-01-22
OKI C5510MFP Printer CU H2.15, PU 01.03.01, System F/W 1.01, and Web Page 1.00 sends the configuration of the printer in cleartext, which allows remote attackers to obtain the administrative password by connecting to TCP port 5548 or 7777.
- CVE-2008-3289HIGHCVSS 7.5EG 7.52008-07-24
EMC Dantz Retrospect Backup Client 7.5.116 sends the password hash in cleartext at an unspecified point, which allows remote attackers to obtain sensitive information via a crafted packet.
- CVE-2008-4122HIGHCVSS 7.5EG 7.52008-12-19
Joomla! 1.5.8 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
- CVE-2008-4390HIGHCVSS 7.5EG 7.52008-12-09
The Cisco Linksys WVC54GC wireless video camera before firmware 1.25 sends cleartext configuration data in response to a Setup Wizard remote-management command, which allows remote attackers to obtain sensitive information such as password…
- CVE-2010-4177MEDIUMCVSS 5.5EG 5.52019-11-12
mysql-gui-tools (mysql-query-browser and mysql-admin) before 5.0r14+openSUSE-2.3 exposes the password of a user connected to the MySQL server in clear text form via the list of running processes.
- CVE-2011-3022NONECVSS 0.0EG 0.02012-02-16
translate/translate_manager.cc in Google Chrome before 17.0.963.56 and 19.x before 19.0.1036.7 uses an HTTP session to exchange data for translation, which allows remote attackers to obtain sensitive information by sniffing the network.
- CVE-2012-1257MEDIUMCVSS 5.5EG 5.52019-11-20
Pidgin 2.10.0 uses DBUS for certain cleartext communication, which allows local users to obtain sensitive information via a dbus session monitor.
- CVE-2012-5562HIGHCVSS 8.6EG 8.62019-12-02
A flaw was found in rhn-proxy. This vulnerability may allow the rhn-proxy to transmit user credentials in clear-text when it accesses RHN Satellite. This could lead to information disclosure, where sensitive authentication details are expo…
- CVE-2014-5380HIGHCVSS 7.5EG 7.52020-01-13
Grand MA 300 allows retrieval of the access PIN from sniffed data.
- CVE-2015-0987CRITICALCVSS 10.0EG 0.02015-10-06
Omron CX-One CX-Programmer before 9.6, CJ2M PLC devices before 2.1, and CJ2H PLC devices before 1.5 rely on cleartext password transmission, which allows remote attackers to obtain sensitive information by sniffing the network during a PLC…
- CVE-2015-7542MEDIUMCVSS 5.3EG 5.32019-12-03
A vulnerability exists in libgwenhywfar through 4.12.0 due to the usage of outdated bundled CA certificates.
- CVE-2016-10933MEDIUMCVSS 5.9EG 5.92019-08-26
An issue was discovered in the portaudio crate through 0.7.0 for Rust. There is a man-in-the-middle issue because the source code is downloaded over cleartext HTTP.
- CVE-2016-5638HIGHCVSS 7.5EG 7.52018-07-24
There are few web pages associated with the genie app on the Netgear WNDR4500 running firmware version V1.0.1.40_1.0.6877. Genie app adds some capabilities over the Web GUI and can be accessed even when you are away from home. A remote att…
- CVE-2016-5649CRITICALCVSS 9.8EG 9.82018-07-24
A vulnerability is in the 'BSW_cxttongr.htm' page of the Netgear DGN2200, version DGN2200-V1.0.0.50_7.0.50, and DGND3700, version DGND3700-V1.0.0.17_1.0.17, which can allow a remote attacker to access this page without any authentication. …
- CVE-2017-0925HIGHCVSS 7.2EG 7.22018-03-21
Gitlab Enterprise Edition version 10.1.0 is vulnerable to an insufficiently protected credential issue in the project service integration API endpoint resulting in an information disclosure of plaintext password.
- CVE-2017-12310HIGHCVSS 7.5EG 7.52018-03-27
A vulnerability in the auto discovery phase of Cisco Spark Hybrid Calendar Service could allow an unauthenticated, remote attacker to view sensitive information in the unencrypted headers of an HTTP method request. The attacker could use t…
- CVE-2017-12716MEDIUMCVSS 6.5EG 6.52018-04-25
Abbott Laboratories Accent and Anthem pacemakers manufactured prior to Aug 28, 2017 transmit unencrypted patient information via RF communications to programmers and home monitoring units. Additionally, the Accent and Anthem pacemakers sto…
- CVE-2017-16035HIGHCVSS 8.1EG 8.12018-06-04
The hubl-server module is a wrapper for the HubL Development Server. During installation hubl-server downloads a set of dependencies from api.hubapi.com. It appears in the code that these files are downloaded over HTTPS however the api.hub…
- CVE-2017-16040HIGHCVSS 8.1EG 8.12018-06-04
gfe-sass is a library for promises (CommonJS/Promises/A,B,D) gfe-sass downloads resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resource…
- CVE-2017-16041MEDIUMCVSS 5.9EG 5.92018-06-04
ikst versions before 1.1.2 download resources over HTTP, which leaves it vulnerable to MITM attacks.
- CVE-2017-20109MEDIUMCVSS 4.3EG 6.52022-06-29
A vulnerability classified as problematic was found in Teleopti WFM up to 7.1.0. Affected by this vulnerability is an unknown functionality of the file /TeleoptiWFM/Administration/GetOneTenant of the component Administration. The manipulat…
- CVE-2017-20200LOWCVSS 3.7EG 3.72025-09-23
A vulnerability has been found in Coinomi up to 1.7.6. This issue affects some unknown processing. Such manipulation leads to cleartext transmission of sensitive information. The attack can be launched remotely. This attack is characterize…
- CVE-2017-7252HIGHCVSS 7.5EG 7.52023-11-03
bcrypt password hashing in Botan before 2.1.0 does not correctly handle passwords with a length between 57 and 72 characters, which makes it easier for attackers to determine the cleartext password.
- CVE-2017-8154MEDIUMCVSS 5.3EG 5.32018-04-11
The Themes App Honor 8 Lite Huawei mobile phones with software of versions before Prague-L31C576B172, versions before Prague-L31C530B160, versions before Prague-L31C432B180 has a man-in-the-middle (MITM) vulnerability due to the use of the…
- CVE-2017-9637MEDIUMCVSS 4.1EG 4.12018-05-18
Schneider Electric Ampla MES 6.4 provides capability to interact with data from third party databases. When connectivity to those databases is configured to use a SQL user name and password, an attacker may be able to sniff details from th…
- CVE-2018-0025MEDIUMCVSS 6.1EG 8.12018-07-11
When an SRX Series device is configured to use HTTP/HTTPS pass-through authentication services, a client sending authentication credentials in the initial HTTP/HTTPS session is at risk that these credentials may be captured during follow-o…
- CVE-2018-0281MEDIUMCVSS 5.8EG 5.82018-05-02
A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to restart an instance of the Snort detection engine on an affected device, resulting in a brief denial of service (…
- CVE-2018-0283MEDIUMCVSS 5.8EG 5.82018-05-02
A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to restart an instance of the Snort detection engine on an affected device, resulting in a brief denial of service (…
- CVE-2018-10634MEDIUMCVSS 4.8EG 5.32018-08-13
Communications between Medtronic MiniMed MMT pumps and wireless accessories are transmitted in cleartext. A sufficiently skilled attacker could capture these transmissions and extract sensitive information, such as device serial numbers.
- CVE-2018-11050HIGHCVSS 8.8EG 8.82018-08-01
Dell EMC NetWorker versions between 9.0 and 9.1.1.8 through 9.2.1.3, and the version 18.1.0.1 contain a Clear-Text authentication over network vulnerability in the Rabbit MQ Advanced Message Queuing Protocol (AMQP) component. User credenti…
- CVE-2018-11338HIGHCVSS 7.5EG 7.52018-07-31
Intuit Lacerte 2017 for Windows in a client/server environment transfers the entire customer list in cleartext over SMB, which allows attackers to (1) obtain sensitive information by sniffing the network or (2) conduct man-in-the-middle (M…
- CVE-2018-11399MEDIUMCVSS 4.3EG 4.32018-05-24
SimpliSafe Original has Unencrypted Sensor Transmissions, which allows physically proximate attackers to obtain potentially sensitive information about the specific times when alarm-system events occur.
- CVE-2018-11402MEDIUMCVSS 6.6EG 6.62018-05-24
SimpliSafe Original has Unencrypted Keypad Transmissions, which allows physically proximate attackers to discover the PIN.
- CVE-2018-11421CRITICALCVSS 9.8EG 9.82019-07-03
Moxa OnCell G3100-HSPA Series version 1.6 Build 17100315 and prior use a proprietary monitoring protocol that does not provide confidentiality, integrity, and authenticity security controls. All information is sent in plain text, and can b…
- CVE-2018-11422CRITICALCVSS 9.8EG 9.82019-07-03
Moxa OnCell G3100-HSPA Series version 1.6 Build 17100315 and prior use a proprietary configuration protocol that does not provide confidentiality, integrity, and authenticity security controls. All information is sent in plain text, and ca…
- CVE-2018-11477MEDIUMCVSS 6.5EG 6.52018-05-30
An issue was discovered on Vgate iCar 2 Wi-Fi OBD2 Dongle devices. The data packets that are sent between the iOS or Android application and the OBD dongle are not encrypted. The combination of this vulnerability with the lack of wireless …
- CVE-2018-11749CRITICALCVSS 9.8EG 9.82018-08-24
When users are configured to use startTLS with RBAC LDAP, at login time, the user's credentials are sent via plaintext to the LDAP server. This affects Puppet Enterprise 2018.1.3, 2017.3.9, and 2016.4.14, and is fixed in Puppet Enterprise …
- CVE-2018-12674MEDIUMCVSS 5.7EG 5.72018-10-19
The SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) stores the username and password within the cookies of a session. If an attacker gained access to these session cookies, it would be possible t…
- CVE-2018-12710HIGHCVSS 8.0EG 8.02018-08-29
An issue was discovered on D-Link DIR-601 2.02NA devices. Being local to the network and having only "User" account (which is a low privilege account) access, an attacker can intercept the response from a POST request to obtain "Admin" rig…
- CVE-2018-1297CRITICALCVSS 9.8EG 9.82018-02-13
When using Distributed Test only (RMI based), Apache JMeter 2.x and 3.x uses an unsecured RMI connection. This could allow an attacker to get Access to JMeterEngine and send unauthorized code.
- CVE-2018-13140HIGHCVSS 8.1EG 8.12018-09-24
Druide Antidote through 9.5.1 on Windows and Linux allows remote code execution through the update mechanism by leveraging use of HTTP to download installation packages.
- CVE-2018-1360HIGHCVSS 8.1EG 8.12019-04-25
A cleartext transmission of sensitive information vulnerability in Fortinet FortiManager 5.2.0 through 5.2.7, 5.4.0 and 5.4.1 may allow an unauthenticated attacker in a man in the middle position to retrieve the admin password via intercep…
- CVE-2018-1454MEDIUMCVSS 5.9EG 5.92018-06-05
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to …
Map vulnerabilities like CWE-319 to your infrastructure
EchelonGraph correlates every CVE — across CWE-319 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →