CWE-319— Cleartext Transmission of Sensitive Information
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.— MITRE CWE catalog
913 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-319page 5 of 19
- CVE-2019-5489MEDIUMCVSS 5.5EG 5.52019-01-07
The mincore() implementation in mm/mincore.c in the Linux kernel through 4.19.13 allowed local attackers to observe page cache access patterns of other processes on the same system, potentially allowing sniffing of secret information. (Fix…
- CVE-2019-5494HIGHCVSS 7.5EG 7.52019-05-10
OnCommand Unified Manager 7-Mode prior to version 5.2.4 shipped without certain HTTP Security headers configured which could allow an attacker to obtain sensitive information via unspecified vectors.
- CVE-2019-5496HIGHCVSS 7.5EG 7.52019-05-10
Oncommand Insight versions prior to 7.3.5 shipped without certain HTTP Security headers configured which could allow an attacker to obtain sensitive information via unspecified vectors.
- CVE-2019-5503MEDIUMCVSS 5.3EG 5.32019-09-10
OnCommand Workflow Automation versions prior to 5.0 shipped without certain HTTP Security headers configured which could allow an attacker to obtain sensitive information via unspecified vectors.
- CVE-2019-5505CRITICALCVSS 9.8EG 9.82019-09-24
ONTAP Select Deploy administration utility versions 2.2 through 2.12.1 transmit credentials in plaintext.
- CVE-2019-5635HIGHCVSS 7.5EG 7.52019-08-22
A cleartext transmission of sensitive information vulnerability is present in Hickory Smart Ethernet Bridge from Belwith Products, LLC. Captured data reveals that the Hickory Smart Ethernet Bridge device communicates over the network to an…
- CVE-2019-6526CRITICALCVSS 9.8EG 9.82019-04-15
Moxa IKS-G6824A series Versions 4.5 and prior, EDS-405A series Version 3.8 and prior, EDS-408A series Version 3.8 and prior, and EDS-510A series Version 3.8 and prior use plaintext transmission of sensitive data, which may allow an attacke…
- CVE-2019-6540MEDIUMCVSS 6.5EG 6.52019-03-26
The Conexus telemetry protocol utilized within Medtronic MyCareLink Monitor versions 24950 and 24952, CareLink Monitor version 2490C, CareLink 2090 Programmer, Amplia CRT-D, Claria CRT-D, Compia CRT-D, Concerto CRT-D, Concerto II CRT-D, Co…
- CVE-2019-6613MEDIUMCVSS 5.3EG 5.32019-05-03
On BIG-IP 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.2-11.5.8, SNMP may expose sensitive configuration objects over insecure transmission channels. This issue is exposed when a passphrase is used with various profile types a…
- CVE-2019-6640MEDIUMCVSS 5.3EG 5.32019-07-03
On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.1-11.5.8, SNMP exposes sensitive configuration objects over insecure transmission channels. This issue is exposed when a passphrase is in…
- CVE-2019-6652MEDIUMCVSS 6.5EG 6.52019-09-25
In BIG-IQ 6.0.0-6.1.0, services for stats do not require authentication nor do they implement any form of Transport Layer Security (TLS).
- CVE-2019-6845HIGHCVSS 7.5EG 7.52019-10-29
A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists in Modicon M580, Modicon M340, Modicon Premium , Modicon Quantum (all firmware versions), which could cause the disclosure of information when transferring app…
- CVE-2019-6846MEDIUMCVSS 6.5EG 6.52019-10-29
A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists in Modicon M580, Modicon M340, Modicon BMxCRA and 140CRA modules (all firmware versions), which could cause information disclosure when using the FTP protocol.
- CVE-2019-7675HIGHCVSS 7.5EG 7.52019-02-09
An issue was discovered on MOBOTIX S14 MX-V4.2.1.61 devices. The default management application is delivered over cleartext HTTP with Basic Authentication, as demonstrated by the /admin/index.html URI.
- CVE-2019-8345MEDIUMCVSS 4.2EG 4.22019-02-15
The Help feature in the ES File Explorer File Manager application 4.1.9.7.4 for Android allows session hijacking by a Man-in-the-middle attacker on the local network because HTTPS is not used, and an attacker's web site is displayed in a W…
- CVE-2019-8632MEDIUMCVSS 6.5EG 6.52019-12-18
Some analytics data was sent using HTTP rather than HTTPS. This was addressed by no longer sending this analytics data. This issue is fixed in Texture 5.11.10 for iOS, Texture 4.22.0.4 for Android. An attacker in a privileged network posit…
- CVE-2019-9101HIGHCVSS 7.5EG 7.52020-03-11
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. Sensitive information is sent to the web server in cleartext, which…
- CVE-2019-9532HIGHCVSS 7.8EG 7.82019-10-10
The web application portal of the Cobham EXPLORER 710, firmware version 1.07, sends the login password in cleartext. This could allow an unauthenticated, local attacker to intercept the password and gain access to the portal.
- CVE-2019-9860HIGHCVSS 7.5EG 7.52019-03-27
Due to unencrypted signal communication and predictability of rolling codes, an attacker can "desynchronize" an ABUS Secvest wireless remote control (FUBE50014 or FUBE50015) relative to its controlled Secvest wireless alarm system FUAA5000…
- CVE-2020-0884LOWCVSS 3.7EG 3.72020-03-12
A spoofing vulnerability exists in Microsoft Visual Studio as it includes a reply URL that is not secured by SSL, aka 'Microsoft Visual Studio Spoofing Vulnerability'.
- CVE-2020-10124HIGHCVSS 7.1EG 7.12020-08-21
NCR SelfServ ATMs running APTRA XFS 05.01.00 do not encrypt, authenticate, or verify the integrity of messages between the BNA and the host computer, which could allow an attacker with physical access to the internal components of the ATM …
- CVE-2020-10281HIGHCVSS 7.5EG 7.52020-07-03
This vulnerability applies to the Micro Air Vehicle Link (MAVLink) protocol and allows a remote attacker to gain access to sensitive information provided it has access to the communication medium. MAVLink is a header-based protocol that do…
- CVE-2020-10376CRITICALCVSS 9.8EG 9.82020-03-11
Technicolor TC7337NET 08.89.17.23.03 devices allow remote attackers to discover passwords by sniffing the network for an "Authorization: Basic" HTTP header.
- CVE-2020-10624HIGHCVSS 7.5EG 7.52020-06-26
ControlEdge PLC (R130.2, R140, R150, and R151) and RTU (R101, R110, R140, R150, and R151) exposes a session token on the network.
- CVE-2020-10628HIGHCVSS 7.5EG 7.52020-06-26
ControlEdge PLC (R130.2, R140, R150, and R151) and RTU (R101, R110, R140, R150, and R151) exposes unencrypted passwords on the network.
- CVE-2020-11539HIGHCVSS 8.1EG 8.12020-04-22
An issue was discovered on Tata Sonata Smart SF Rush 1.12 devices. It has been identified that the smart band has no pairing (mode 0 Bluetooth LE security level) The data being transmitted over the air is not encrypted. Adding to this, the…
- CVE-2020-11542CRITICALCVSS 9.8EG 9.82020-04-04
3xLOGIC Infinias eIDC32 2.213 devices with Web 1.107 allow Authentication Bypass via CMD.HTM?CMD= because authentication depends on the client side's interpretation of the <KEY>MYKEY</KEY> substring.
- CVE-2020-11557HIGHCVSS 7.5EG 7.52020-04-09
An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. It includes the username and password values in cleartext within each request's cookie value.
- CVE-2020-11614HIGHCVSS 8.1EG 8.12020-06-11
Mids' Reborn Hero Designer 2.6.0.7 downloads the update manifest, as well as update files, over cleartext HTTP. Additionally, the application does not perform file integrity validation for files after download. An attacker can perform a ma…
- CVE-2020-11685HIGHCVSS 7.5EG 7.52020-04-22
In JetBrains GoLand before 2019.3.2, the plugin repository was accessed via HTTP instead of HTTPS.
- CVE-2020-11718HIGHCVSS 7.4EG 7.42020-12-23
An issue was discovered in Programi Bilanc build 007 release 014 31.01.2020 and below. Its software-update packages are downloaded via cleartext HTTP.
- CVE-2020-12008HIGHCVSS 7.5EG 7.52020-06-29
Baxter ExactaMix EM 2400 Versions 1.10, 1.11 and ExactaMix EM1200 Versions 1.1, 1.2 systems use cleartext messages to communicate order information with an order entry system. This could allow an attacker with network access to view sensit…
- CVE-2020-12036HIGHCVSS 7.5EG 7.52020-06-29
Baxter PrismaFlex all versions, PrisMax all versions prior to 3.x, The affected devices do not implement data-in-transit encryption (e.g., TLS/SSL) when configured to send treatment data to a PDMS (Patient Data Management System) or an EMR…
- CVE-2020-12037HIGHCVSS 7.5EG 7.52020-06-29
Baxter PrismaFlex all versions, PrisMax all versions prior to 3.x, The affected devices do not implement data-in-transit encryption (e.g., TLS/SSL) when configured to send treatment data to a PDMS (Patient Data Management System) or an EMR…
- CVE-2020-12040CRITICALCVSS 9.8EG 9.82020-06-29
Sigma Spectrum Infusion System v's6.x (model 35700BAX) and Baxter Spectrum Infusion System Version(s) 8.x (model 35700BAX2) at the application layer uses an unauthenticated clear-text communication channel to send and receive system status…
- CVE-2020-12048HIGHCVSS 7.5EG 7.52020-06-29
Phoenix Hemodialysis Delivery System SW 3.36 and 3.40, The Phoenix Hemodialysis device does not support data-in-transit encryption (e.g., TLS/SSL) when transmitting treatment and prescription data on the network between the Phoenix system …
- CVE-2020-12398HIGHCVSS 7.5EG 7.52020-07-09
If Thunderbird is configured to use STARTTLS for an IMAP server, and the server sends a PREAUTH response, then Thunderbird will continue with an unencrypted connection, causing email data to be sent without protection. This vulnerability a…
- CVE-2020-12638MEDIUMCVSS 6.8EG 6.82020-07-23
An encryption-bypass issue was discovered on Espressif ESP-IDF devices through 4.2, ESP8266_NONOS_SDK devices through 3.0.3, and ESP8266_RTOS_SDK devices through 3.3. Broadcasting forged beacon frames forces a device to change its authenti…
- CVE-2020-12730MEDIUMCVSS 5.3EG 5.32021-07-15
MagicMotion Flamingo 2 lacks BLE encryption, enabling data sniffing and packet forgery.
- CVE-2020-1343MEDIUMCVSS 5.9EG 5.92020-06-09
An information disclosure vulnerability exists in Visual Studio Code Live Share Extension when it exposes tokens in plain text, aka 'Visual Studio Code Live Share Information Disclosure Vulnerability'.
- CVE-2020-13528MEDIUMCVSS 5.3EG 5.92020-12-18
An information disclosure vulnerability exists in the Web Manager and telnet CLI functionality of Lantronix XPort EDGE 3.0.0.0R11, 3.1.0.0R9, 3.4.0.0R12 and 4.2.0.0R7. A specially crafted HTTP request can cause information disclosure. An a…
- CVE-2020-13787HIGHCVSS 7.5EG 7.52020-06-03
D-Link DIR-865L Ax 1.20B01 Beta devices have Cleartext Transmission of Sensitive Information.
- CVE-2020-14093MEDIUMCVSS 5.9EG 5.92020-06-15
Mutt before 1.14.3 allows an IMAP fcc/postpone man-in-the-middle attack via a PREAUTH response.
- CVE-2020-14157HIGHCVSS 8.1EG 8.12020-06-17
The wireless-communication feature of the ABUS Secvest FUBE50001 device does not encrypt sensitive data such as PIN codes or IDs of used proximity chip keys (RFID tokens). This makes it easier for an attacker to disarm the wireless alarm s…
- CVE-2020-14171MEDIUMCVSS 6.5EG 6.52020-07-09
Atlassian Bitbucket Server from version 4.9.0 before version 7.2.4 allows remote attackers to intercept unencrypted repository import requests via a Man-in-the-Middle (MITM) attack.
- CVE-2020-14248MEDIUMCVSS 5.3EG 5.32020-12-16
BigFix Inventory up to v10.0.2 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.
- CVE-2020-14930HIGHCVSS 8.1EG 8.12020-06-19
An issue was discovered in BT CTROMS Terminal OS Port Portal CT-464. Account takeover can occur because the password-reset feature discloses the verification token. Upon a getverificationcode.jsp request, this token is transmitted not only…
- CVE-2020-15054HIGHCVSS 8.8EG 8.82020-08-07
TP-Link USB Network Server TL-PS310U devices before 2.079.000.t0210 allow an attacker on the same network to elevate privileges because the administrative password can be discovered by sniffing unencrypted UDP traffic.
- CVE-2020-15058HIGHCVSS 8.8EG 8.82020-08-07
Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to elevate privileges because the administrative password can be discovered by sniffing unencrypted UDP traffic.
- CVE-2020-15062HIGHCVSS 8.8EG 8.82020-08-07
DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to elevate privileges because the administrative password can be discovered by sniffing unencrypted UDP traffic.
Map vulnerabilities like CWE-319 to your infrastructure
EchelonGraph correlates every CVE — across CWE-319 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →