CWE-319— Cleartext Transmission of Sensitive Information
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.— MITRE CWE catalog
913 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-319page 13 of 19
- CVE-2023-41088MEDIUMCVSS 6.5EG 6.52023-10-19
The affected product is vulnerable to a cleartext transmission of sensitive information vulnerability, which may allow an attacker with access to the network, where clients have access to the DexGate server, could capture traffi…
- CVE-2023-42016MEDIUMCVSS 4.3EG 4.32024-02-09
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.3 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http…
- CVE-2023-42144MEDIUMCVSS 5.5EG 5.52024-01-23
Cleartext Transmission during initial setup in Shelly TRV 20220811-15234 v.2.1.8 allows a local attacker to obtain the Wi-Fi password.
- CVE-2023-42147HIGHCVSS 7.5EG 7.52023-09-20
An issue in CloudExplorer Lite 1.3.1 allows an attacker to obtain sensitive information via the login key component.
- CVE-2023-42579MEDIUMCVSS 5.3EG 6.52023-12-05
Improper usage of insecure protocol (i.e. HTTP) in SogouSDK of Chinese Samsung Keyboard prior to versions 5.3.70.1 in Android 11, 5.4.60.49, 5.4.85.5, 5.5.00.58 in Android 12, and 5.6.00.52, 5.6.10.42, 5.7.00.45 in Android 13 allows adjace…
- CVE-2023-43124HIGHCVSS 7.1EG 7.12023-09-27
BIG-IP APM clients may send IP traffic outside of the VPN tunnel. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
- CVE-2023-43125HIGHCVSS 8.2EG 8.22023-09-27
BIG-IP APM clients may send IP traffic outside of the VPN tunnel. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
- CVE-2023-43503HIGHCVSS 7.5EG 7.52023-11-14
A vulnerability has been identified in COMOS (All versions < V10.4.4). Caching system in the affected application leaks sensitive information such as user and project information in cleartext via UDP.
- CVE-2023-4509MEDIUMCVSS 4.3EG 4.32024-04-18
It is possible for an API key to be logged in clear text in the audit log file after an invalid login attempt.
- CVE-2023-45321HIGHCVSS 8.8EG 8.82023-10-25
The Android Client application, when enrolled with the define method 1 (the user manually inserts the server ip address), use HTTP protocol to retrieve sensitive information (ip address and credentials to connect to a remote MQTT broker e…
- CVE-2023-45716LOWCVSS 1.7EG 1.72024-02-09
Sametime is impacted by sensitive information passed in URL.
- CVE-2023-46380HIGHCVSS 7.5EG 7.52023-11-04
LOYTEC LINX-151, LINX-212, LVIS-3ME12-A1, LIOB-586, LIOB-580 V2, LIOB-588, L-INX Configurator devices (all versions) send password-change requests via cleartext HTTP.
- CVE-2023-46382HIGHCVSS 7.5EG 7.52023-11-04
LOYTEC LINX-151, LINX-212, LVIS-3ME12-A1, LIOB-586, LIOB-580 V2, LIOB-588, L-INX Configurator devices (all versions) use cleartext HTTP for login.
- CVE-2023-46383HIGHCVSS 7.5EG 7.52023-11-30
LOYTEC electronics GmbH LINX Configurator (all versions) uses HTTP Basic Authentication, which transmits usernames and passwords in base64-encoded cleartext and allows remote attackers to steal the password and gain full control of Loytec …
- CVE-2023-46385HIGHCVSS 7.5EG 7.52023-11-30
LOYTEC electronics GmbH LINX Configurator (all versions) is vulnerable to Insecure Permissions. An admin credential is passed as a value of URL parameters without encryption, so it allows remote attackers to steal the password and gain ful…
- CVE-2023-46447MEDIUMCVSS 4.3EG 4.32024-01-20
The POPS! Rebel application 5.0 for Android, in POPS! Rebel Bluetooth Glucose Monitoring System, sends unencrypted glucose measurements over BLE.
- CVE-2023-46889MEDIUMCVSS 5.7EG 5.72024-01-23
Meross MSH30Q 4.5.23 is vulnerable to Cleartext Transmission of Sensitive Information. During the device setup phase, the MSH30Q creates an unprotected Wi-Fi access point. In this phase, MSH30Q needs to connect to the Internet through a Wi…
- CVE-2023-47745MEDIUMCVSS 6.2EG 6.22024-03-03
IBM MQ Operator 2.0.0 LTS, 2.0.18 LTS, 3.0.0 CD, 3.0.1 CD, 2.4.0 through 2.4.7, 2.3.0 through 2.3.3, 2.2.0 through 2.2.2, and 2.3.0 through 2.3.3 stores or transmits user credentials in plain clear text which can be read by a local user us…
- CVE-2023-4918HIGHCVSS 8.8EG 8.82023-09-12
A flaw was found in the Keycloak package, more specifically org.keycloak.userprofile. When a user registers itself through registration flow, the "password" and "password-confirm" field from the form will occur as regular user attributes. …
- CVE-2023-5035MEDIUMCVSS 5.3EG 5.32023-11-02
A vulnerability has been identified in PT-G503 Series firmware versions prior to v5.2, where the Secure attribute for sensitive cookies in HTTPS sessions is not set, which could cause the cookie to be transmitted in plaintext over an HTTP …
- CVE-2023-50614HIGHCVSS 7.5EG 7.52024-01-18
An issue discovereed in EBYTE E880-IR01-V1.1 allows an attacker to obtain sensitive information via crafted POST request to /cgi-bin/luci.
- CVE-2023-50703MEDIUMCVSS 5.9EG 6.32023-12-20
An attacker with network access could perform a man-in-the-middle (MitM) attack and capture sensitive information to gain unauthorized access to the application.
- CVE-2023-50962MEDIUMCVSS 5.9EG 5.92024-02-02
IBM PowerSC 1.3, 2.0, and 2.1 MFA does not implement the "HTTP Strict Transport Security" (HSTS) web security policy mechanism. IBM X-Force ID: 276004.
- CVE-2023-5100MEDIUMCVSS 6.5EG 6.52023-10-09
Cleartext Transmission of Sensitive Information in RDT400 in SICK APU allows an unprivileged remote attacker to retrieve potentially sensitive information via intercepting network traffic that is not encrypted.
- CVE-2023-51390HIGHCVSS 7.5EG 7.52023-12-21
journalpump is a daemon that takes log messages from journald and pumps them to a given output. A logging vulnerability was found in journalpump which logs out the configuration of a service integration in plaintext to the supplied logging…
- CVE-2023-51740HIGHCVSS 7.5EG 7.52024-01-17
This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to transmission of authentication credentials in plaintext over the network. A remote attacker could exploit this vulnerability by eavesdropping on the victim’s ne…
- CVE-2023-51741HIGHCVSS 7.5EG 7.52024-01-17
This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to transmission of authentication credentials in plaintext over the network. A remote attacker could exploit this vulnerability by eavesdropping on the victim’s ne…
- CVE-2023-52951MEDIUMCVSS 5.9EG 5.92026-06-03
A cleartext transmission of sensitive information vulnerability in Synology Note Station Client before 2.2.4-703 allows man-in-the-middle attackers to obtain user credential.
- CVE-2023-53875HIGHCVSS 8.8EG 8.82025-12-15
GOM Player 2.3.90.5360 contains a remote code execution vulnerability in its Internet Explorer component that allows attackers to execute arbitrary code through DNS spoofing. Attackers can redirect victims using a malicious URL shortcut an…
- CVE-2023-53881CRITICALCVSS 9.2EG 9.22025-12-15
ReyeeOS 1.204.1614 contains an unencrypted CWMP communication vulnerability that allows attackers to intercept and manipulate device communication through a man-in-the-middle attack. Attackers can create a fake CWMP server to inject and ex…
- CVE-2023-5461MEDIUMCVSS 5.9EG 5.92023-10-09
A vulnerability was found in Delta Electronics WPLSoft 2.51. It has been classified as problematic. Affected is an unknown function of the component Modbus Handler. The manipulation leads to cleartext transmission of sensitive information.…
- CVE-2023-6094MEDIUMCVSS 5.3EG 5.32023-12-31
A vulnerability has been identified in OnCell G3150A-LTE Series firmware versions v1.3 and prior. The vulnerability results from lack of protection for sensitive information during transmission. An attacker eavesdropping on the traffic bet…
- CVE-2023-6248CRITICALCVSS 9.8EG 10.02023-11-21
The Syrus4 IoT gateway utilizes an unsecured MQTT server to download and execute arbitrary commands, allowing a remote unauthenticated attacker to execute code on any Syrus4 device connected to the cloud service. The MQTT server also leaks…
- CVE-2024-0056HIGHCVSS 8.7EG 8.72024-01-09
Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability
- CVE-2024-0066MEDIUMCVSS 5.3EG 5.32024-06-18
Johan Fagerström, member of the AXIS OS Bug Bounty Program, has found that a O3C feature may expose sensitive traffic between the client (Axis device) and (O3C) server. If O3C is not being used this flaw does not apply. Axis has released…
- CVE-2024-0098MEDIUMCVSS 5.5EG 5.52024-05-14
NVIDIA ChatRTX for Windows contains a vulnerability in the ChatRTX UI and backend, where a user can cause a clear-text transmission of sensitive information issue by data sniffing. A successful exploit of this vulnerability might lead to i…
- CVE-2024-0220HIGHCVSS 8.3EG 8.32024-02-22
B&R Automation Studio Upgrade Service and B&R Technology Guarding use insufficient cryptography for communication to the upgrade and the licensing servers. A network-based attacker could exploit the vulnerability to execute arbitrary code …
- CVE-2024-0860HIGHCVSS 8.0EG 8.02024-03-14
The affected product is vulnerable to a cleartext transmission of sensitive information vulnerability, which may allow an attacker to capture packets to craft their own requests.
- CVE-2024-10718HIGHCVSS 7.5EG 7.52025-03-20
In phpipam/phpipam version 1.5.1, the Secure attribute for sensitive cookies in HTTPS sessions is not set. This could cause the user agent to send those cookies in plaintext over an HTTP session, potentially exposing sensitive information.…
- CVE-2024-10973MEDIUMCVSS 5.7EG 5.72024-12-17
A vulnerability was found in Keycloak. The environment option `KC_CACHE_EMBEDDED_MTLS_ENABLED` does not work and the JGroups replication configuration is always used in plain text which can allow an attacker that has access to adjacent net…
- CVE-2024-11946MEDIUMCVSS 6.5EG 6.52024-12-30
iXsystems TrueNAS CORE fetch_plugin_packagesites tar Cleartext Transmission of Sensitive Information Vulnerability. This vulnerability allows network-adjacent attackers to tamper with firmware update files on affected installations of iXsy…
- CVE-2024-12378CRITICALCVSS 9.1EG 9.12025-05-08
On affected platforms running Arista EOS with secure Vxlan configured, restarting the Tunnelsec agent will result in packets being sent over the secure Vxlan tunnels in the clear.
- CVE-2024-13872HIGHCVSS 7.5EG 7.52025-03-12
Bitdefender Box, versions 1.3.11.490 through 1.3.11.505, uses the insecure HTTP protocol to download assets over the Internet to update and restart daemons and detection rules on the devices. Updates can be remotely triggered through the /…
- CVE-2024-1657HIGHCVSS 8.1EG 8.12024-04-25
A flaw was found in the ansible automation platform. An insecure WebSocket connection was being used in installation from the Ansible rulebook EDA server. An attacker that has access to any machine in the CIDR block could download all rule…
- CVE-2024-21406HIGHCVSS 7.5EG 7.52024-02-13
Windows Printing Service Spoofing Vulnerability
- CVE-2024-25630MEDIUMCVSS 6.1EG 6.12024-02-20
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For Cilium users who are using CRDs to store Cilium state (the default configuration) and Wireguard transparent encryption, traffic to/from the Ingr…
- CVE-2024-25631MEDIUMCVSS 6.1EG 6.12024-02-20
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For Cilium users who have enabled an external kvstore and Wireguard transparent encryption, traffic between pods in the affected cluster is not encr…
- CVE-2024-25650MEDIUMCVSS 5.9EG 5.92024-03-14
Insecure key exchange between Delinea PAM Secret Server 11.4 and the Distributed Engine 8.4.3 allows a PAM administrator to obtain the Symmetric Key (used to encrypt RabbitMQ messages) via crafted payloads to the /pre-authenticate, /authen…
- CVE-2024-25735CRITICALCVSS 9.1EG 9.12024-03-27
An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can discover cleartext passwords via a SoftAP /device/config GET request.
- CVE-2024-25960HIGHCVSS 7.3EG 7.32024-03-28
Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains a cleartext transmission of sensitive information vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to escalation of privile…
Map vulnerabilities like CWE-319 to your infrastructure
EchelonGraph correlates every CVE — across CWE-319 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →