CWE-319— Cleartext Transmission of Sensitive Information
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.— MITRE CWE catalog
913 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-319page 10 of 19
- CVE-2022-21184MEDIUMCVSS 5.9EG 5.92022-06-17
An information disclosure vulnerability exists in the License registration functionality of Bachmann Visutec GmbH Atvise 3.5.4, 3.6 and 3.7. A plaintext HTTP request can lead to a disclosure of login credentials. An attacker can perform a …
- CVE-2022-21798CRITICALCVSS 7.5EG 9.82022-02-25
The affected product is vulnerable due to cleartext transmission of credentials seen in the CIMPLICITY network, which can be easily spoofed and used to log in to make operational changes to the system.
- CVE-2022-21829CRITICALCVSS 9.8EG 9.82022-06-24
Concrete CMS Versions 9.0.0 through 9.0.2 and 8.5.7 and below can download zip files over HTTP and execute code from those zip files which could lead to an RCE. Fixed by enforcing ‘concrete_secure’ instead of ‘concrete’. Concrete n…
- CVE-2022-21951MEDIUMCVSS 6.8EG 6.82022-05-25
A Cleartext Transmission of Sensitive Information vulnerability in SUSE Rancher, Rancher allows attackers on the network to read and change network data due to missing encryption of data transmitted via the network when a cluster is create…
- CVE-2022-22385MEDIUMCVSS 5.9EG 5.92023-10-17
IBM Security Verify Privilege On-Premises 11.5 could disclose sensitive information to an attacked due to the transmission of data in clear text. IBM X-Force ID: 221962.
- CVE-2022-22457MEDIUMCVSS 5.3EG 5.32022-12-22
IBM Security Verify Governance, Identity Manager 10.0.1 stores sensitive information including user credentials in plain clear text which can be read by a local privileged user. IBM X-Force ID: 225007.
- CVE-2022-22758HIGHCVSS 8.8EG 8.82022-12-22
When clicking on a tel: link, USSD codes, specified after a <code>\*</code> character, would be included in the phone number. On certain phones, or on certain carriers, if the number was dialed this could perform actions on a user's accoun…
- CVE-2022-23105MEDIUMCVSS 6.5EG 6.52022-01-12
Jenkins Active Directory Plugin 2.25 and earlier does not encrypt the transmission of data between the Jenkins controller and Active Directory servers in most configurations.
- CVE-2022-2338MEDIUMCVSS 5.7EG 5.72022-08-17
Softing Secure Integration Server V1.22 is vulnerable to authentication bypass via a machine-in-the-middle attack. The default the administration interface is accessible via plaintext HTTP protocol, facilitating the attack. The HTTP reques…
- CVE-2022-23509HIGHCVSS 7.3EG 7.32023-01-09
Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing Kubernetes expertise. GitOps run has a local S3 bucket which it uses for synchronizing files that are later applied agai…
- CVE-2022-2485CRITICALCVSS 9.6EG 9.62022-08-31
Any attempt (good or bad) to log into AutomationDirect Stride Field I/O with a web browser may result in the device responding with its password in the communication packets.
- CVE-2022-24978HIGHCVSS 8.8EG 8.82022-04-05
Zoho ManageEngine ADAudit Plus before 7055 allows authenticated Privilege Escalation on Integrated products. This occurs because a password field is present in a JSON response.
- CVE-2022-25180MEDIUMCVSS 4.3EG 4.32022-02-15
Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier includes password parameters from the original build in replayed builds, allowing attackers with Run/Replay permission to obtain the values of password parameters passed to pre…
- CVE-2022-25805MEDIUMCVSS 6.5EG 6.52022-06-09
An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. The transmission of cleartext LDAP bind credentials by the cmd_mgt_load_mgt_tree command allows an attacker (who can intercept or inspect traffic between an aut…
- CVE-2022-26077HIGHCVSS 7.5EG 7.52022-05-25
A cleartext transmission of sensitive information vulnerability exists in the OAS Engine configuration communications functionality of Open Automation Software OAS Platform V16.00.0112. A targeted network sniffing attack can lead to a disc…
- CVE-2022-27619MEDIUMCVSS 6.8EG 6.82022-08-03
Cleartext transmission of sensitive information vulnerability in authentication management in Synology Note Station Client before 2.2.2-609 allows man-in-the-middle attackers to obtain sensitive information via unspecified vectors.
- CVE-2022-28861MEDIUMCVSS 5.9EG 5.92022-07-21
The server in Citilog 8.0 allows an attacker (in a man in the middle position between the server and its smart camera Axis M1125) to see FTP credentials in a cleartext HTTP traffic. These can be used for FTP access to the server.
- CVE-2022-29519HIGHCVSS 7.5EG 7.52022-06-28
Cleartext transmission of sensitive information vulnerability exists in STARDOM FCN Controller and FCJ Controller R1.01 to R4.31, which may allow an adjacent attacker to login the affected products and alter device configuration settings o…
- CVE-2022-29733MEDIUMCVSS 5.9EG 5.92022-06-02
Delta Controls enteliTOUCH 3.40.3935, 3.40.3706, and 3.33.4005 was discovered to transmit and store sensitive information in cleartext. This vulnerability allows attackers to intercept HTTP Cookie authentication credentials via a man-in-th…
- CVE-2022-29874HIGHCVSS 8.8EG 8.82022-05-20
A vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices do not encrypt web traffic with clients but communicate in cleartext via HTTP. This could allow an unauthenticated attacker to capture the traffic and i…
- CVE-2022-29945HIGHCVSS 4.0EG 7.52022-04-29
DJI drone devices sold in 2017 through 2022 broadcast unencrypted information about the drone operator's physical location via the AeroScope protocol.
- CVE-2022-30115MEDIUMCVSS 4.3EG 4.32022-06-02
Using its HSTS support, curl can be instructed to use HTTPS directly insteadof using an insecure clear-text HTTP step even when HTTP is provided in theURL. This mechanism could be bypassed if the host name in the given URL used atrailing d…
- CVE-2022-30312MEDIUMCVSS 6.5EG 6.52022-09-07
The Trend Controls IC protocol through 2022-05-06 allows Cleartext Transmission of Sensitive Information. According to FSCT-2022-0050, there is a Trend Controls Inter-Controller (IC) protocol cleartext transmission of credentials issue. Th…
- CVE-2022-30993HIGHCVSS 7.5EG 7.52022-05-18
Cleartext transmission of sensitive information. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 29240
- CVE-2022-30994HIGHCVSS 7.5EG 7.52022-05-18
Cleartext transmission of sensitive information. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 29240
- CVE-2022-31046MEDIUMCVSS 4.3EG 4.32022-06-14
TYPO3 is an open source web content management system. Prior to versions 7.6.57 ELTS, 8.7.47 ELTS, 9.5.34 ELTS, 10.4.29, and 11.5.11, the export functionality fails to limit the result set to allowed columns of a particular database table.…
- CVE-2022-31204HIGHCVSS 7.5EG 7.52022-07-26
Omron CS series, CJ series, and CP series PLCs through 2022-05-18 use cleartext passwords. They feature a UM Protection setting that allows users or system integrators to configure a password in order to restrict sensitive engineering oper…
- CVE-2022-3206MEDIUMCVSS 5.9EG 5.92022-10-17
The Passster WordPress plugin before 3.5.5.5.2 stores the password inside a cookie named "passster" using base64 encoding method which is easy to decode. This puts the password at risk in case the cookies get leaked.
- CVE-2022-32227MEDIUMCVSS 6.5EG 6.52022-09-23
A cleartext transmission of sensitive information exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 relating to Oauth tokens by having the permission "view-full-other-user-info", this could cause an oauth token leak in the product.
- CVE-2022-32245HIGHCVSS 8.2EG 8.22022-08-10
SAP BusinessObjects Business Intelligence Platform (Open Document) - versions 420, 430, allows an unauthenticated attacker to retrieve sensitive information plain text over the network. On successful exploitation, the attacker can view any…
- CVE-2022-32510HIGHCVSS 7.1EG 7.12024-05-14
An issue was discovered on certain Nuki Home Solutions devices. The HTTP API exposed by a Bridge used an unencrypted channel to provide an administrative interface. A token can be easily eavesdropped by a malicious actor to impersonate a l…
- CVE-2022-3261MEDIUMCVSS 4.4EG 4.42023-09-15
A flaw was found in OpenStack. Multiple components show plain-text passwords in /var/log/messages during the OpenStack overcloud update run, leading to a disclosure of sensitive information problem.
- CVE-2022-32857MEDIUMCVSS 4.3EG 4.32022-08-24
This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, Security Update 2022-005 Catalina, iOS 15.6 and iPadOS 15.6, tvOS 15.6, watchOS 8.7. A use…
- CVE-2022-32906MEDIUMCVSS 5.3EG 5.32023-02-27
This issue was addressed with using HTTPS when sending information over the network. This issue is fixed in Apple Music 3.9.10 for Android. A user in a privileged network position may intercept SSL/TLS connections.
- CVE-2022-33321CRITICALCVSS 9.8EG 9.82022-11-08
Cleartext Transmission of Sensitive Information vulnerability due to the use of Basic Authentication for HTTP connections in Mitsubishi Electric consumer electronics products (PHOTOVOLTAIC COLOR MONITOR ECO-GUIDE, HEMS adapter, Wi-Fi Inter…
- CVE-2022-33724LOWCVSS 3.3EG 3.32022-08-05
Exposure of Sensitive Information in Samsung Dialer application?prior to SMR Aug-2022 Release 1 allows local attackers to access ICCID via log.
- CVE-2022-34371CRITICALCVSS 8.1EG 9.82022-09-02
Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.3, contain an unprotected transport of credentials vulnerability. A malicious unprivileged network attacker could potentially exploit this vul…
- CVE-2022-34704MEDIUMCVSS 4.7EG 5.52022-08-09
Windows Defender Credential Guard Information Disclosure Vulnerability
- CVE-2022-34801MEDIUMCVSS 4.3EG 4.32022-06-30
Jenkins Build Notifications Plugin 1.5.0 and earlier transmits tokens in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure.
- CVE-2022-34804MEDIUMCVSS 4.3EG 4.32022-06-30
Jenkins OpsGenie Plugin 1.9 and earlier transmits API keys in plain text as part of the global Jenkins configuration form and job configuration forms, potentially resulting in their exposure.
- CVE-2022-36200HIGHCVSS 7.5EG 7.52022-08-29
In FiberHome VDSL2 Modem HG150-Ub_V3.0, Credentials of Admin are submitted in URL, which can be logged/sniffed.
- CVE-2022-38122HIGHCVSS 7.5EG 7.52022-11-10
UPSMON PRO transmits sensitive data in cleartext over HTTP protocol. An unauthenticated remote attacker can exploit this vulnerability to access sensitive data.
- CVE-2022-38458MEDIUMCVSS 6.5EG 6.52023-03-21
A cleartext transmission vulnerability exists in the Remote Management functionality of Netgear Orbi Router RBR750 4.6.8.5. A specially-crafted man-in-the-middle attack can lead to a disclosure of sensitive information.
- CVE-2022-38710MEDIUMCVSS 5.3EG 5.32022-11-03
IBM Robotic Process Automation 21.0.1 and 21.0.2 could disclose sensitive version to an unauthorized control sphere information that could aid in further attacks against the system. IBM X-Force ID: 234292.
- CVE-2022-38846MEDIUMCVSS 5.9EG 5.92022-09-16
EspoCRM version 7.1.8 is vulnerable to Missing Secure Flag allowing the browser to send plain text cookies over an insecure channel (HTTP). An attacker may capture the cookie from the insecure channel using MITM attack.
- CVE-2022-38870HIGHCVSS 7.5EG 7.52022-10-25
Free5gc v3.2.1 is vulnerable to Information disclosure.
- CVE-2022-39269CRITICALCVSS 9.1EG 9.12022-10-06
PJSIP is a free and open source multimedia communication library written in C. When processing certain packets, PJSIP may incorrectly switch from using SRTP media transport to using basic RTP upon SRTP restart, causing the media to be sent…
- CVE-2022-39287HIGHCVSS 8.1EG 8.12022-10-07
tiny-csrf is a Node.js cross site request forgery (CSRF) protection middleware. In versions prior to 1.1.0 cookies were not encrypted and thus CSRF tokens were transmitted in the clear. This issue has been addressed in commit `8eead6d` and…
- CVE-2022-3929CRITICALCVSS 8.3EG 9.82023-01-05
Communication between the client and the server application of the affected products is partially done using CORBA (Common Object Request Broker Architecture) over TCP/IP. This protocol is not encrypted and allows tracing of internal mess…
- CVE-2022-39339MEDIUMCVSS 4.3EG 4.32022-11-25
user_oidc is an OpenID Connect user backend for Nextcloud. In versions prior to 1.2.1 sensitive information such as the OIDC client credentials and tokens are sent in plain text of HTTP without TLS. Any malicious actor with access to monit…
Map vulnerabilities like CWE-319 to your infrastructure
EchelonGraph correlates every CVE — across CWE-319 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →