CWE-319— Cleartext Transmission of Sensitive Information
843 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-319page 8 of 17
- CVE-2021-29753MEDIUMCVSS 5.9EG 5.92021-11-05
IBM Business Automation Workflow 18. 19, 20, 21, and IBM Business Process Manager 8.5 and d8.6 transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
- CVE-2021-29769MEDIUMCVSS 4.3EG 4.32021-07-26
IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or …
- CVE-2021-29892MEDIUMCVSS 5.9EG 5.92024-12-03
IBM Cognos Controller 11.0.0 and 11.0.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitiv…
- CVE-2021-3003MEDIUMCVSS 5.3EG 5.32021-05-10
Agenzia delle Entrate Desktop Telematico 1.0.0 contacts the jws.agenziaentrate.it server over cleartext HTTP, which allows man-in-the-middle attackers to spoof product updates.
- CVE-2021-31671HIGHCVSS 7.5EG 7.52021-04-27
pgsync before 0.6.7 is affected by Information Disclosure of sensitive information. Syncing the schema with the --schema-first and --schema-only options is mishandled. For example, the sslmode connection parameter may be lost, which means …
- CVE-2021-31815LOWCVSS 3.3EG 3.32021-04-28
GAEN (aka Google/Apple Exposure Notifications) through 2021-04-27 on Android allows attackers to obtain sensitive information, such as a user's location history, in-person social graph, and (sometimes) COVID-19 infection status, because Ro…
- CVE-2021-31855MEDIUMCVSS 6.5EG 6.52021-06-02
KDE Messagelib through 5.17.0 reveals cleartext of encrypted messages in some situations. Deleting an attachment of a decrypted encrypted message stored on a remote server (e.g., an IMAP server) causes KMail to upload the decrypted content…
- CVE-2021-31898HIGHCVSS 7.5EG 7.52021-05-11
In JetBrains WebStorm before 2021.1, HTTP requests were used instead of HTTPS.
- CVE-2021-32456MEDIUMCVSS 6.5EG 6.52021-05-17
SITEL CAP/PRX firmware version 5.2.01 allows an attacker with access to the local network of the device to obtain the authentication passwords by analysing the network traffic.
- CVE-2021-32612HIGHCVSS 8.1EG 8.12021-06-16
The VeryFitPro (com.veryfit2hr.second) application 3.2.8 for Android does all communication with the backend API over cleartext HTTP. This includes logins, registrations, and password change requests. This allows information theft and acco…
- CVE-2021-32934CRITICALCVSS 9.1EG 7.52022-05-19
The affected ThroughTek P2P products (SDKs using versions before 3.1.5, any versions with nossl tag, device firmware not using AuthKey for IOTC conneciton, firmware using AVAPI module without enabling DTLS mechanism, and firmware using P2P…
- CVE-2021-32966LOWCVSS 3.7EG 7.52022-05-25
Philips Interoperability Solution XDS versions 2.5 through 3.11 and 2018-1 through 2021-1 are vulnerable to clear text transmission of sensitive information when configured to use LDAP via TLS and where the domain controller returns LDAP r…
- CVE-2021-32982HIGHCVSS 7.5EG 7.52022-04-04
Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 passwords are sent as plaintext during unlocking and project transfers. An attacker who has network visibility can observe the password exchange.
- CVE-2021-33022HIGHCVSS 7.5EG 7.52022-04-01
Philips Vue PACS versions 12.2.x.x and prior transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
- CVE-2021-33408MEDIUMCVSS 6.5EG 6.52021-05-27
Local File Inclusion vulnerability in Ab Initio Control>Center before 4.0.2.6 allows remote attackers to retrieve arbitrary files. Fixed in v4.0.2.6 and v4.0.3.1.
- CVE-2021-33883MEDIUMCVSS 5.9EG 5.92021-08-25
A Cleartext Transmission of Sensitive Information vulnerability in B. Braun SpaceCom2 prior to 012U000062 allows a remote attacker to obtain sensitive information by snooping on the network traffic. The exposed data includes critical value…
- CVE-2021-33900HIGHCVSS 7.5EG 7.52021-07-26
While investigating DIRSTUDIO-1219 it was noticed that configured StartTLS encryption was not applied when any SASL authentication mechanism (DIGEST-MD5, GSSAPI) was used. While investigating DIRSTUDIO-1220 it was noticed that any configur…
- CVE-2021-3417MEDIUMCVSS 4.9EG 4.92021-03-09
An internal product security audit of LXCO, prior to version 1.2.2, discovered that credentials for Lenovo XClarity Administrator (LXCA), if added as a Resource Manager, are encoded then written to an internal LXCO log file each time a ses…
- CVE-2021-34687MEDIUMCVSS 5.3EG 5.32021-07-15
iDrive RemotePC before 7.6.48 on Windows allows information disclosure. A man in the middle can recover a system's Personal Key when a client attempts to make a LAN connection. The Personal Key is transmitted over the network while only be…
- CVE-2021-3473MEDIUMCVSS 4.5EG 4.52021-04-13
An internal product security audit of Lenovo XClarity Controller (XCC) discovered that the XCC configuration backup/restore password may be written to an internal XCC log buffer if Lenovo XClarity Administrator (LXCA) is used to perform th…
- CVE-2021-34825HIGHCVSS 7.5EG 7.52021-06-17
Quassel through 0.13.1, when --require-ssl is enabled, launches without SSL or TLS support if a usable X.509 certificate is not found on the local system.
- CVE-2021-3494MEDIUMCVSS 5.9EG 5.92021-04-26
A smart proxy that provides a restful API to various sub-systems of the Foreman is affected by the flaw which can cause a Man-in-the-Middle attack. The FreeIPA module of Foreman smart proxy does not check the SSL certificate, thus, an unau…
- CVE-2021-35246MEDIUMCVSS 5.3EG 5.32022-11-23
The application fails to prevent users from connecting to it over unencrypted connections. An attacker able to modify a legitimate user's network traffic could bypass the application's use of SSL/TLS encryption and use the application as a…
- CVE-2021-3590HIGHCVSS 8.8EG 8.82022-08-22
A flaw was found in Foreman project. A credential leak was identified which will expose Azure Compute Profile password through JSON of the API output. The highest threat from this vulnerability is to data confidentiality and integrity as w…
- CVE-2021-36165MEDIUMCVSS 5.3EG 5.32021-09-28
RICON Industrial Cellular Router S9922L 16.10.3(3794) is affected by cleartext storage of sensitive information and sends username and password as base64.
- CVE-2021-36382LOWCVSS 2.6EG 3.72021-07-12
Devolutions Server before 2021.1.18, and LTS before 2020.3.20, allows attackers to intercept private keys via a man-in-the-middle attack against the connections/partial endpoint (which accepts cleartext).
- CVE-2021-3774HIGHCVSS 7.4EG 6.52021-11-05
Meross Smart Wi-Fi 2 Way Wall Switch (MSS550X), on its 3.1.3 version and before, creates an open Wi-Fi Access Point without the required security measures in its initial setup. This could allow a remote attacker to obtain the Wi-Fi SSID as…
- CVE-2021-3792MEDIUMCVSS 5.3EG 5.32021-11-12
Some device communications in some Motorola-branded Binatone Hubble Cameras with backend Hubble services are not encrypted which could lead to the communication channel being accessible by an attacker.
- CVE-2021-37939LOWCVSS 2.7EG 2.72021-11-18
It was discovered that Kibana’s JIRA connector & IBM Resilient connector could be used to return HTTP response data on internal hosts, which may be intentionally hidden from public view. Using this vulnerability, a malicious user with th…
- CVE-2021-38142HIGHCVSS 8.8EG 8.82021-09-07
Barco MirrorOp Windows Sender before 2.5.3.65 uses cleartext HTTP and thus allows rogue software upgrades. An attacker on the local network can achieve remote code execution on any computer that tries to update Windows Sender due to the fa…
- CVE-2021-38373MEDIUMCVSS 5.3EG 5.32021-08-10
In KDE KMail 19.12.3 (aka 5.13.3), the SMTP STARTTLS option is not honored (and cleartext messages are sent) unless "Server requires authentication" is checked.
- CVE-2021-38418HIGHCVSS 8.8EG 8.82021-11-03
Delta Electronics DIALink versions 1.2.4.0 and prior runs by default on HTTP, which may allow an attacker to be positioned between the traffic and perform a machine-in-the-middle attack to access information without authorization.
- CVE-2021-38828MEDIUMCVSS 5.3EG 5.32022-11-14
Xiongmai Camera XM-JPR2-LX V4.02.R12.A6420987.10002.147502.00000 is vulnerable to plain-text traffic sniffing.
- CVE-2021-38978MEDIUMCVSS 5.9EG 5.92021-11-15
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability …
- CVE-2021-39026MEDIUMCVSS 5.9EG 5.92022-02-18
IBM Guardium Data Encryption (GDE) 5.0.0.2 and 5.0.0.3 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to …
- CVE-2021-39077MEDIUMCVSS 4.4EG 4.42022-11-03
IBM Security Guardium 10.5, 10.6, 11.0, 11.1, 11.2, 11.3, and 11.4 stores user credentials in plain clear text which can be read by a local privileged user. IBM X-Force ID: 215587.
- CVE-2021-39081MEDIUMCVSS 5.9EG 5.92024-12-19
IBM Cognos Analytics Mobile for Android 1.1.14 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
- CVE-2021-39090MEDIUMCVSS 5.9EG 5.92024-02-29
IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.6.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerabilit…
- CVE-2021-39272MEDIUMCVSS 5.9EG 5.92021-08-30
Fetchmail before 6.4.22 fails to enforce STARTTLS session encryption in some circumstances, such as a certain situation with IMAP and PREAUTH.
- CVE-2021-39341HIGHCVSS 8.2EG 8.22021-11-01
The OptinMonster WordPress plugin is vulnerable to sensitive information disclosure and unauthorized setting updates due to insufficient authorization validation via the logged_in_or_has_api_key function in the ~/OMAPI/RestApi.php file tha…
- CVE-2021-39342MEDIUMCVSS 5.3EG 7.52021-09-29
The Credova_Financial WordPress plugin discloses a site's associated Credova API account username and password in plaintext via an AJAX action whenever a site user goes to checkout on a page that has the Credova Financing option enabled. T…
- CVE-2021-39882MEDIUMCVSS 5.3EG 5.32021-10-05
In all versions of GitLab CE/EE, provided a user ID, anonymous users can use a few endpoints to retrieve information about any GitLab user.
- CVE-2021-40148HIGHCVSS 7.5EG 7.52022-01-04
In Modem EMM, there is a possible information disclosure due to a missing data encryption. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Pa…
- CVE-2021-40366HIGHCVSS 7.4EG 7.42021-11-09
A vulnerability has been identified in Climatix POL909 (AWB module) (All versions < V11.42), Climatix POL909 (AWM module) (All versions < V11.34). The web server of affected devices transmits data without TLS encryption. This could allow a…
- CVE-2021-40392HIGHCVSS 7.5EG 7.52022-04-14
An information disclosure vulnerability exists in the Web Application functionality of Moxa MXView Series 3.2.4. Network sniffing can lead to a disclosure of sensitive information. An attacker can sniff network traffic to exploit this vuln…
- CVE-2021-40846HIGHCVSS 7.5EG 7.52022-03-04
An issue was discovered in Rhinode Trading Paints through 2.0.36. TP Updater.exe uses cleartext HTTP to check, and request, updates. Thus, attackers can man-in-the-middle a victim to download a malicious binary in place of the real update,…
- CVE-2021-40847HIGHCVSS 8.1EG 8.12021-09-21
The update process of the Circle Parental Control Service on various NETGEAR routers allows remote attackers to achieve remote code execution as root via a MitM attack. While the parental controls themselves are not enabled by default on t…
- CVE-2021-4161CRITICALCVSS 9.8EG 9.82021-12-27
The affected products contain vulnerable firmware, which could allow an attacker to sniff the traffic and decrypt login credential details. This could give an attacker admin rights through the HTTP web server.
- CVE-2021-41835HIGHCVSS 7.3EG 7.32022-01-21
Fresenius Kabi Agilia Link + version 3.0 does not enforce transport layer encryption. Therefore, transmitted data may be sent in cleartext. Transport layer encryption is offered on Port TCP/443, but the affected service does not perform an…
- CVE-2021-41849MEDIUMCVSS 5.5EG 5.52022-03-11
An issue was discovered in Luna Simo PPR1.180610.011/202001031830. It sends the following Personally Identifiable Information (PII) in plaintext using HTTP to servers located in China: user's list of installed apps and device International…
Map vulnerabilities like CWE-319 to your infrastructure
EchelonGraph correlates every CVE — across CWE-319 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →