CWE-319— Cleartext Transmission of Sensitive Information
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.— MITRE CWE catalog
913 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-319page 12 of 19
- CVE-2023-25848MEDIUMCVSS 5.3EG 5.32023-08-25
ArcGIS Enterprise Server versions 11.0 and below have an information disclosure vulnerability where a remote, unauthorized attacker may submit a crafted query that may result in a low severity information disclosure issue. The informatio…
- CVE-2023-27291MEDIUMCVSS 4.5EG 4.52024-03-03
IBM Watson CP4D Data Stores 4.6.0, 4.6.1, 4.6.2, and 4.6.3 does not encrypt sensitive or critical information before storage or transmission which could allow an attacker to obtain sensitive information. IBM X-Force ID: 248740.
- CVE-2023-2754HIGHCVSS 7.4EG 7.42023-08-03
The Cloudflare WARP client for Windows assigns loopback IPv4 addresses for the DNS Servers, since WARP acts as local DNS server that performs DNS queries in a secure manner, however, if a user is connected to WARP over an IPv6-capable netw…
- CVE-2023-27861MEDIUMCVSS 5.9EG 5.92023-06-05
IBM Maximo Application Suite - Manage Component 8.8.0 and 8.9.0 transmits sensitive information in cleartext that could be intercepted by an attacker using man in the middle techniques. IBM X-Force ID: 249208.
- CVE-2023-27927MEDIUMCVSS 6.5EG 6.52023-03-27
An authenticated malicious user could acquire the simple mail transfer protocol (SMTP) Password in cleartext format, despite it being protected and hidden behind asterisks. The attacker could then perform further attacks using the SMTP cre…
- CVE-2023-28348HIGHCVSS 7.4EG 7.42023-05-31
An issue was discovered in Faronics Insight 10.0.19045 on Windows. A suitably positioned attacker could perform a man-in-the-middle attack on either a connected student or teacher, enabling them to intercept student keystrokes or modify ex…
- CVE-2023-28616HIGHCVSS 7.5EG 7.52023-12-26
An issue was discovered in Stormshield Network Security (SNS) before 4.3.17, 4.4.x through 4.6.x before 4.6.4, and 4.7.x before 4.7.1. It affects user accounts for which the password has an equals sign or space character. The serverd proce…
- CVE-2023-29680MEDIUMCVSS 5.7EG 5.72023-05-01
Cleartext Transmission in set-cookie:ecos_pw: Tenda N301 v6.0, Firmware v12.02.01.61_multi allows an authenticated attacker on the LAN or WLAN to intercept communications with the router and obtain the password.
- CVE-2023-29681MEDIUMCVSS 5.7EG 5.72023-05-01
Cleartext Transmission in cookie:ecos_pw: in Tenda N301 v6.0, firmware v12.03.01.06_pt allows an authenticated attacker on the LAN or WLAN to intercept communications with the router and obtain the password.
- CVE-2023-3028HIGHCVSS 8.6EG 8.62023-06-01
Insufficient authentication in the MQTT backend (broker) allows an attacker to access and even manipulate the telemetry data of the entire fleet of vehicles using the HopeChart HQT-401 telematics unit. Other models are possibly affected to…
- CVE-2023-30354CRITICALCVSS 9.8EG 9.82023-05-10
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 does not defend against physical access to U-Boot via the UART: the Wi-Fi password is shown, and the hardcoded boot password can be inserted for console access.
- CVE-2023-30513HIGHCVSS 7.5EG 7.52023-04-12
Jenkins Kubernetes Plugin 3909.v1f2c633e8590 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled.
- CVE-2023-30514HIGHCVSS 7.5EG 7.52023-04-12
Jenkins Azure Key Vault Plugin 187.va_cd5fecd198a_ and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled.
- CVE-2023-30515HIGHCVSS 7.5EG 7.52023-04-12
Jenkins Thycotic DevOps Secrets Vault Plugin 1.0.0 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled.
- CVE-2023-30565LOWCVSS 3.5EG 3.52023-07-13
An insecure connection between Systems Manager and CQI Reporter application could expose infusion data to an attacker.
- CVE-2023-30602HIGHCVSS 7.5EG 7.52023-06-02
Hitron Technologies CODA-5310’s Telnet function transfers sensitive data in plaintext. An unauthenticated remote attacker can exploit this vulnerability to access credentials of normal users and administrator.
- CVE-2023-30841MEDIUMCVSS 6.0EG 6.02023-04-26
Baremetal Operator (BMO) is a bare metal host provisioning integration for Kubernetes. Prior to version 0.3.0, ironic and ironic-inspector deployed within Baremetal Operator using the included `deploy.sh` store their `.htpasswd` files as C…
- CVE-2023-31193HIGHCVSS 7.5EG 7.52023-05-22
Snap One OvrC Pro versions prior to 7.3 use HTTP connections when downloading a program from their servers. Because they do not use HTTPS, OvrC Pro devices are susceptible to exploitation.
- CVE-2023-31195MEDIUMCVSS 5.3EG 5.32023-06-13
ASUS Router RT-AX3000 Firmware versions prior to 3.0.0.4.388.23403 uses sensitive cookies without 'Secure' attribute. When an attacker is in a position to be able to mount a man-in-the-middle attack, and a user is tricked to log into the a…
- CVE-2023-31300HIGHCVSS 7.5EG 7.52023-12-29
An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive information via transmission of unencrypted, cleartext credentials during Password Reset feature.
- CVE-2023-31410CRITICALCVSS 9.8EG 9.82023-06-19
A remote unprivileged attacker can intercept the communication via e.g. Man-In-The-Middle, due to the absence of Transport Layer Security (TLS) in the SICK EventCam App. This lack of encryption in the communication channel can lead to the …
- CVE-2023-31823HIGHCVSS 7.5EG 7.52023-07-13
An issue found in Marui Co Marui Official app v.13.6.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp Marui Official Store function.
- CVE-2023-32290HIGHCVSS 7.5EG 7.52023-05-07
The myMail app through 14.30 for iOS sends cleartext credentials in a situation where STARTTLS is expected by a server.
- CVE-2023-32328HIGHCVSS 7.5EG 7.52024-02-07
IBM Security Verify Access 10.0.0.0 through 10.0.6.1 uses insecure protocols in some instances that could allow an attacker on the network to take control of the server. IBM X-Force Id: 254957.
- CVE-2023-3272HIGHCVSS 7.5EG 7.52023-07-10
Cleartext Transmission of Sensitive Information in the SICK ICR890-4 could allow a remote attacker to gather sensitive information by intercepting network traffic that is not encrypted.
- CVE-2023-32784HIGHCVSS 7.5EG 7.52023-05-15
In KeePass 2.x before 2.54, it is possible to recover the cleartext master password from a memory dump, even when a workspace is locked or no longer running. The memory dump can be a KeePass process dump, swap file (pagefile.sys), hibernat…
- CVE-2023-33187MEDIUMCVSS 5.4EG 5.42023-05-26
Highlight is an open source, full-stack monitoring platform. Highlight may record passwords on customer deployments when a password html input is switched to `type="text"` via a javascript "Show Password" button. This differs from the expe…
- CVE-2023-3361HIGHCVSS 7.7EG 7.72023-10-04
A flaw was found in Red Hat OpenShift Data Science. When exporting a pipeline from the Elyra notebook pipeline editor as Python DSL or YAML, it reads S3 credentials from the cluster (ds pipeline server) and saves them in plain text in the …
- CVE-2023-33730CRITICALCVSS 9.8EG 9.82023-05-31
Privilege Escalation in the "GetUserCurrentPwd" function in Microworld Technologies eScan Management Console 14.0.1400.2281 allows any remote attacker to retrieve password of any admin or normal user in plain text format.
- CVE-2023-33837MEDIUMCVSS 4.1EG 4.12023-10-23
IBM Security Verify Governance 10.0 does not encrypt sensitive or critical information before storage or transmission. IBM X-Force ID: 256020.
- CVE-2023-33960HIGHCVSS 7.5EG 7.52023-06-01
OpenProject is web-based project management software. For any OpenProject installation, a `robots.txt` file is generated through the server to denote which routes shall or shall not be accessed by crawlers. These routes contain project ide…
- CVE-2023-34142CRITICALCVSS 9.0EG 9.02023-07-18
Cleartext Transmission of Sensitive Information vulnerability in Hitachi Device Manager on Windows, Linux (Device Manager Server, Device Manager Agent, Host Data Collector components) allows Interception.This issue affects Hitachi Device M…
- CVE-2023-34441MEDIUMCVSS 6.8EG 6.82023-10-19
Baker Hughes – Bently Nevada 3500 System TDI Firmware version 5.05 contains a cleartext transmission vulnerability which could allow an attacker to steal the authentication secret from communication traffic to the device and reus…
- CVE-2023-34829MEDIUMCVSS 6.5EG 6.52023-12-28
Incorrect access control in TP-Link Tapo before v3.1.315 allows attackers to access user credentials in plaintext.
- CVE-2023-34972LOWCVSS 3.5EG 3.52023-08-24
A cleartext transmission of sensitive information vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows local network clients to read the contents of unexpected sensitive data via…
- CVE-2023-34998HIGHCVSS 8.1EG 8.12023-09-05
An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to arbitrary authentication. An attacker can sniff …
- CVE-2023-35017MEDIUMCVSS 5.9EG 5.92025-01-29
IBM Security Verify Governance 10.0.2 Identity Manager can transmit user credentials in clear text that could be obtained by an attacker using man in the middle techniques.
- CVE-2023-35833MEDIUMCVSS 6.5EG 6.52023-07-13
An issue was discovered in YSoft SAFEQ 6 Server before 6.0.82. When modifying the URL of the LDAP server configuration from LDAPS to LDAP, the system does not require the password to be (re)entered. This results in exposing cleartext crede…
- CVE-2023-36671MEDIUMCVSS 6.3EG 6.32023-08-09
An issue was discovered in the Clario VPN client through 5.9.1.1662 for macOS. The VPN client insecurely configures the operating system such that all IP traffic to the VPN server's IP address is sent in plaintext outside the VPN tunnel ev…
- CVE-2023-36672MEDIUMCVSS 5.7EG 5.72023-08-09
An issue was discovered in the Clario VPN client through 5.9.1.1662 for macOS. The VPN client insecurely configures the operating system such that traffic to the local network is sent in plaintext outside the VPN tunnel even if the local n…
- CVE-2023-36673HIGHCVSS 7.3EG 7.32023-08-09
An issue was discovered in Avira Phantom VPN through 2.23.1 for macOS. The VPN client insecurely configures the operating system such that all IP traffic to the VPN server's IP address is sent in plaintext outside the VPN tunnel, even if t…
- CVE-2023-3761LOWCVSS 3.7EG 3.72023-07-19
A vulnerability was found in Intergard SGS 8.7.0 and classified as problematic. Affected by this issue is some unknown functionality of the component Password Change Handler. The manipulation leads to cleartext transmission of sensitive in…
- CVE-2023-3763LOWCVSS 3.7EG 3.72023-07-19
A vulnerability was found in Intergard SGS 8.7.0. It has been declared as problematic. This vulnerability affects unknown code of the component SQL Query Handler. The manipulation leads to cleartext transmission of sensitive information. T…
- CVE-2023-38275MEDIUMCVSS 5.9EG 5.92023-10-22
IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 exposes sensitive information in container images which could lead to further attacks against the system. IBM X-Force ID: 260730.
- CVE-2023-38276MEDIUMCVSS 5.9EG 5.92023-10-22
IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 exposes sensitive information in environment variables which could aid in further attacks against the system. IBM X-Force ID: 260736.
- CVE-2023-39086HIGHCVSS 7.5EG 7.52023-08-08
ASUS RT-AC66U B1 3.0.0.4.286_51665 was discovered to transmit sensitive information in cleartext.
- CVE-2023-39172CRITICALCVSS 9.1EG 9.12023-12-07
The affected devices transmit sensitive information unencrypted allowing a remote unauthenticated attacker to capture and modify network traffic.
- CVE-2023-39245CRITICALCVSS 9.8EG 9.82024-02-15
DELL ESI (Enterprise Storage Integrator) for SAP LAMA, version 10.0, contains an information disclosure vulnerability in EHAC component. An remote unauthenticated attacker could potentially exploit this vulnerability by eavesdropping the …
- CVE-2023-40544MEDIUMCVSS 5.7EG 5.72024-02-06
An attacker with access to the network where the affected devices are located could maliciously actions to obtain, via a sniffer, sensitive information exchanged via TCP communications.
- CVE-2023-40729HIGHCVSS 7.3EG 7.42023-09-12
A vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected application lacks security control to prevent unencrypted communication without HTTPS. An attacker who managed to gain machine-in-the-middle positi…
Map vulnerabilities like CWE-319 to your infrastructure
EchelonGraph correlates every CVE — across CWE-319 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →