CWE-319— Cleartext Transmission of Sensitive Information
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.— MITRE CWE catalog
913 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-319page 6 of 19
- CVE-2020-15482HIGHCVSS 7.8EG 7.82020-08-26
An issue was discovered on Nescomed Multipara Monitor M1000 devices. The device enables an unencrypted TELNET service by default, with a blank password for the admin account. This allows an attacker to gain root access to the device over t…
- CVE-2020-15509MEDIUMCVSS 6.5EG 6.52020-07-07
Nordic Semiconductor Android BLE Library through 2.2.1 and DFU Library through 1.10.4 for Android (as used by nRF Connect and other applications) can engage in unencrypted communication while showing the user that the communication is purp…
- CVE-2020-15767MEDIUMCVSS 5.3EG 5.32020-09-18
An issue was discovered in Gradle Enterprise before 2020.2.5. The cookie used to convey the CSRF prevention token is not annotated with the “secure” attribute, which allows an attacker with the ability to MITM plain HTTP requests to ob…
- CVE-2020-15785MEDIUMCVSS 5.3EG 5.32020-09-09
A vulnerability has been identified in Siveillance Video Client (All versions). In environments where Windows NTLM authentication is enabled the affected client application transmits usernames to the server in cleartext. This could allow a…
- CVE-2020-15954MEDIUMCVSS 6.5EG 6.52020-07-27
KDE KMail 19.12.3 (aka 5.13.3) engages in unencrypted POP3 communication during times when the UI indicates that encryption is in use.
- CVE-2020-1749HIGHCVSS 7.5EG 7.52020-09-09
A flaw was found in the Linux kernel's implementation of some networking protocols in IPsec, such as VXLAN and GENEVE tunnels over IPv6. When an encrypted tunnel is created between two hosts, the kernel isn't correctly routing tunneled dat…
- CVE-2020-1902HIGHCVSS 7.5EG 7.52020-10-06
A user running a quick search on a highly forwarded message on WhatsApp for Android from v2.20.108 to v2.20.140 or WhatsApp Business for Android from v2.20.35 to v2.20.49 could have been sent to the Google service over plain HTTP.
- CVE-2020-20128HIGHCVSS 7.5EG 7.52021-09-29
LaraCMS v1.0.1 transmits sensitive information in cleartext which can be intercepted by attackers.
- CVE-2020-2013HIGHCVSS 8.3EG 8.32020-05-13
A cleartext transmission of sensitive information vulnerability in Palo Alto Networks PAN-OS Panorama that discloses an authenticated PAN-OS administrator's PAN-OS session cookie. When an administrator issues a context switch request into …
- CVE-2020-2143MEDIUMCVSS 5.3EG 5.32020-03-09
Jenkins Logstash Plugin 2.3.1 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.
- CVE-2020-2149MEDIUMCVSS 5.3EG 5.32020-03-09
Jenkins Repository Connector Plugin 1.2.6 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.
- CVE-2020-2150MEDIUMCVSS 5.3EG 5.32020-03-09
Jenkins Sonar Quality Gates Plugin 1.3.1 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.
- CVE-2020-2151MEDIUMCVSS 5.3EG 5.32020-03-09
Jenkins Quality Gates Plugin 2.5 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.
- CVE-2020-2153MEDIUMCVSS 4.3EG 4.32020-03-09
Jenkins Backlog Plugin 2.4 and earlier transmits configured credentials in plain text as part of job configuration forms, potentially resulting in their exposure.
- CVE-2020-2155MEDIUMCVSS 5.3EG 5.32020-03-09
Jenkins OpenShift Deployer Plugin 1.2.0 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.
- CVE-2020-2156MEDIUMCVSS 4.3EG 4.32020-03-09
Jenkins DeployHub Plugin 8.0.14 and earlier transmits configured credentials in plain text as part of job configuration forms, potentially resulting in their exposure.
- CVE-2020-2157MEDIUMCVSS 4.3EG 4.32020-03-09
Jenkins Skytap Cloud CI Plugin 2.07 and earlier transmits configured credentials in plain text as part of job configuration forms, potentially resulting in their exposure.
- CVE-2020-2210MEDIUMCVSS 4.3EG 4.32020-07-02
Jenkins Stash Branch Parameter Plugin 0.3.0 and earlier transmits configured passwords in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.
- CVE-2020-2232HIGHCVSS 7.5EG 7.52020-08-12
Jenkins Email Extension Plugin 2.72 and 2.73 transmits and displays the SMTP password in plain text as part of the global Jenkins configuration form, potentially resulting in its exposure.
- CVE-2020-2251MEDIUMCVSS 4.3EG 4.32020-09-01
Jenkins SoapUI Pro Functional Testing Plugin 1.5 and earlier transmits project passwords in its configuration in plain text as part of job configuration forms, potentially resulting in their exposure.
- CVE-2020-25155HIGHCVSS 7.5EG 7.52020-11-13
The affected product transmits unencrypted sensitive information, which may allow an attacker to access this information on the NIO 50 (all versions).
- CVE-2020-25169HIGHCVSS 7.5EG 7.52021-01-26
The affected Reolink P2P products do not sufficiently protect data transferred between the local device and Reolink servers. This can allow an attacker to access sensitive information, such as camera feeds.
- CVE-2020-25178HIGHCVSS 7.5EG 8.82022-03-18
ISaGRAF Workbench communicates with Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x using TCP/IP. This communication protocol provides various file system operations, as well as the uploading of applications. Data is transferred o…
- CVE-2020-25190HIGHCVSS 7.5EG 7.52020-12-23
The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower stores and transmits the credentials of third-party services in cleartext.
- CVE-2020-25605MEDIUMCVSS 5.9EG 5.92021-02-17
Cleartext transmission of sensitive information in Agora Video SDK prior to 3.1 allows a remote attacker to obtain access to audio and video of any ongoing Agora video call through observation of cleartext network traffic.
- CVE-2020-25645HIGHCVSS 7.5EG 7.52020-10-13
A flaw was found in the Linux kernel in versions before 5.9-rc7. Traffic between two Geneve endpoints may be unencrypted when IPsec is configured to encrypt traffic for the specific UDP port used by the GENEVE tunnel allowing anyone betwee…
- CVE-2020-25748HIGHCVSS 8.1EG 8.12020-09-25
A Cleartext Transmission issue was discovered on Rubetek RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339). Someone in the middle can intercept and modify the video data from the camera, which is transmitted in an unencr…
- CVE-2020-25988MEDIUMCVSS 6.5EG 6.52020-11-17
UPNP Service listening on port 5555 in Genexis Platinum 4410 Router V2.1 (P4410-V2–1.34H) has an action 'X_GetAccess' which leaks the credentials of 'admin', provided that the attacker is network adjacent.
- CVE-2020-26197CRITICALCVSS 7.5EG 9.12021-04-20
Dell PowerScale OneFS 8.1.0 - 9.1.0 contains an LDAP Provider inability to connect over TLSv1.2 vulnerability. It may make it easier to eavesdrop and decrypt such traffic for a malicious actor. Note: This does not affect clusters which are…
- CVE-2020-27184MEDIUMCVSS 5.9EG 5.92021-05-14
The NPort IA5000A Series devices use Telnet as one of the network device management services. Telnet does not support the encryption of client-server communications, making it vulnerable to Man-in-the-Middle attacks.
- CVE-2020-27185HIGHCVSS 7.5EG 7.52021-05-14
Cleartext transmission of sensitive information via Moxa Service in NPort IA5000A series serial devices. Successfully exploiting the vulnerability could enable attackers to read authentication data, device configuration, and other sensitiv…
- CVE-2020-27554HIGHCVSS 7.5EG 7.52020-11-17
Cleartext Transmission of Sensitive Information vulnerability in BASETech GE-131 BT-1837836 firmware 20180921 exists which could leak sensitive information transmitted between the mobile app and the camera device.
- CVE-2020-27586MEDIUMCVSS 5.9EG 5.92020-11-30
Quick Heal Total Security before version 19.0 transmits quarantine and sysinfo files via clear text.
- CVE-2020-27656MEDIUMCVSS 6.5EG 6.52020-10-29
Cleartext transmission of sensitive information vulnerability in DDNS in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle attackers to eavesdrop authentication information of DNSExit via unspecified vectors.
- CVE-2020-27657MEDIUMCVSS 6.5EG 6.52020-10-29
Cleartext transmission of sensitive information vulnerability in DDNS in Synology Router Manager (SRM) before 1.2.4-8081 allows man-in-the-middle attackers to eavesdrop authentication information of DNSExit via unspecified vectors.
- CVE-2020-29005HIGHCVSS 7.5EG 7.52021-01-29
The API in the Push extension for MediaWiki through 1.35 used cleartext for ApiPush credentials, allowing for potential information disclosure.
- CVE-2020-29055MEDIUMCVSS 5.9EG 5.92020-11-24
An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B, FD1104S, FD1104SN, FD1108S, FD1204S-R2, FD1204SN, FD1204SN-R2, FD1208S-R2, FD1216S-R1, FD…
- CVE-2020-29380MEDIUMCVSS 5.9EG 5.92020-11-29
An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600D4L V1.01.49, V1600D-MINI V1.01.48, V1600G1 V2.0.7 and V1.9.7, and V1600G2 V1.1.4 OLT devices. TELNET is offered by default but SSH is not always available. An attacker ca…
- CVE-2020-29662MEDIUMCVSS 5.3EG 5.32021-02-02
In Harbor 2.0 before 2.0.5 and 2.1.x before 2.1.2 the catalog’s registry API is exposed on an unauthenticated path.
- CVE-2020-3442MEDIUMCVSS 4.8EG 4.82020-07-20
The DuoConnect client enables users to establish SSH connections to hosts protected by a DNG instance. When a user initiates an SSH connection to a DNG-protected host for the first time using DuoConnect, the user’s browser is opened to a…
- CVE-2020-35456MEDIUMCVSS 5.5EG 5.52021-03-17
The Taidii Diibear Android application 2.4.0 and all its derivatives allow attackers to view private chat messages and media files via logcat because of excessive logging.
- CVE-2020-35584MEDIUMCVSS 5.9EG 5.92020-12-23
In Solstice Pod before 3.0.3, the web services allow users to connect to them over unencrypted channels via the Browser Look-in feature. An attacker suitably positioned to view a legitimate user's network traffic could record and monitor t…
- CVE-2020-36423HIGHCVSS 7.5EG 7.52021-07-19
An issue was discovered in Arm Mbed TLS before 2.23.0. A remote attacker can recover plaintext because a certain Lucky 13 countermeasure doesn't properly consider the case of a hardware accelerator.
- CVE-2020-36914HIGHCVSS 7.5EG 7.52026-01-06
QiHang Media Web Digital Signage 3.0.9 contains a sensitive information disclosure vulnerability that allows remote attackers to intercept user authentication credentials through cleartext cookie transmission. Attackers can perform man-in-…
- CVE-2020-36917HIGHCVSS 7.5EG 7.52026-01-06
iDS6 DSSPro Digital Signage System 6.2 contains a sensitive information disclosure vulnerability that allows remote attackers to intercept authentication credentials through cleartext cookie transmission. Attackers can exploit the autoSave…
- CVE-2020-3702MEDIUMCVSS 6.5EG 6.52020-09-08
u'Specifically timed and handcrafted traffic can cause internal errors in a WLAN device that lead to improper layer 2 Wi-Fi encryption with a consequent possibility of information disclosure over the air for a discrete set of traffic' in S…
- CVE-2020-3841MEDIUMCVSS 6.5EG 6.52020-02-27
The issue was addressed with improved UI handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, Safari 13.0.5. A local user may unknowingly send a password unencrypted over the network.
- CVE-2020-4092MEDIUMCVSS 5.3EG 5.32020-05-06
"If port encryption is not enabled on the Domino Server, HCL Nomad on Android and iOS Platforms will communicate in clear text and does not currently have a user interface option to change the setting to request an encrypted communication …
- CVE-2020-4152MEDIUMCVSS 5.9EG 5.92021-11-08
IBM QRadar Network Security 5.4.0 and 5.5.0 transmits sensitive or security-critical data in cleartext in a communication channel that can be obtained using man in the middle techniques. IBM X-Force ID: 17467.
- CVE-2020-4397MEDIUMCVSS 5.9EG 5.92020-07-22
IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 transmits sensitive information in plain text which could be obtained by an attacker using man in the middle techniques. IBM X-Force ID: 179428.
Map vulnerabilities like CWE-319 to your infrastructure
EchelonGraph correlates every CVE — across CWE-319 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →