CWE-319— Cleartext Transmission of Sensitive Information
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.— MITRE CWE catalog
913 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-319page 9 of 19
- CVE-2021-35246MEDIUMCVSS 5.3EG 5.32022-11-23
The application fails to prevent users from connecting to it over unencrypted connections. An attacker able to modify a legitimate user's network traffic could bypass the application's use of SSL/TLS encryption and use the application as a…
- CVE-2021-3590HIGHCVSS 8.8EG 8.82022-08-22
A flaw was found in Foreman project. A credential leak was identified which will expose Azure Compute Profile password through JSON of the API output. The highest threat from this vulnerability is to data confidentiality and integrity as w…
- CVE-2021-36165MEDIUMCVSS 5.3EG 5.32021-09-28
RICON Industrial Cellular Router S9922L 16.10.3(3794) is affected by cleartext storage of sensitive information and sends username and password as base64.
- CVE-2021-36382LOWCVSS 2.6EG 3.72021-07-12
Devolutions Server before 2021.1.18, and LTS before 2020.3.20, allows attackers to intercept private keys via a man-in-the-middle attack against the connections/partial endpoint (which accepts cleartext).
- CVE-2021-3774HIGHCVSS 7.4EG 7.42021-11-05
Meross Smart Wi-Fi 2 Way Wall Switch (MSS550X), on its 3.1.3 version and before, creates an open Wi-Fi Access Point without the required security measures in its initial setup. This could allow a remote attacker to obtain the Wi-Fi SSID as…
- CVE-2021-3792MEDIUMCVSS 5.3EG 5.32021-11-12
Some device communications in some Motorola-branded Binatone Hubble Cameras with backend Hubble services are not encrypted which could lead to the communication channel being accessible by an attacker.
- CVE-2021-37939LOWCVSS 2.7EG 2.72021-11-18
It was discovered that Kibana’s JIRA connector & IBM Resilient connector could be used to return HTTP response data on internal hosts, which may be intentionally hidden from public view. Using this vulnerability, a malicious user with th…
- CVE-2021-38142HIGHCVSS 8.8EG 8.82021-09-07
Barco MirrorOp Windows Sender before 2.5.3.65 uses cleartext HTTP and thus allows rogue software upgrades. An attacker on the local network can achieve remote code execution on any computer that tries to update Windows Sender due to the fa…
- CVE-2021-38373MEDIUMCVSS 5.3EG 5.32021-08-10
In KDE KMail 19.12.3 (aka 5.13.3), the SMTP STARTTLS option is not honored (and cleartext messages are sent) unless "Server requires authentication" is checked.
- CVE-2021-38418HIGHCVSS 8.8EG 8.82021-11-03
Delta Electronics DIALink versions 1.2.4.0 and prior runs by default on HTTP, which may allow an attacker to be positioned between the traffic and perform a machine-in-the-middle attack to access information without authorization.
- CVE-2021-38828MEDIUMCVSS 5.3EG 5.32022-11-14
Xiongmai Camera XM-JPR2-LX V4.02.R12.A6420987.10002.147502.00000 is vulnerable to plain-text traffic sniffing.
- CVE-2021-38978MEDIUMCVSS 5.9EG 5.92021-11-15
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability …
- CVE-2021-39026MEDIUMCVSS 5.9EG 5.92022-02-18
IBM Guardium Data Encryption (GDE) 5.0.0.2 and 5.0.0.3 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to …
- CVE-2021-39077MEDIUMCVSS 4.4EG 4.42022-11-03
IBM Security Guardium 10.5, 10.6, 11.0, 11.1, 11.2, 11.3, and 11.4 stores user credentials in plain clear text which can be read by a local privileged user. IBM X-Force ID: 215587.
- CVE-2021-39081MEDIUMCVSS 5.9EG 5.92024-12-19
IBM Cognos Analytics Mobile for Android 1.1.14 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
- CVE-2021-39090MEDIUMCVSS 5.9EG 5.92024-02-29
IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.6.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerabilit…
- CVE-2021-39272MEDIUMCVSS 5.9EG 5.92021-08-30
Fetchmail before 6.4.22 fails to enforce STARTTLS session encryption in some circumstances, such as a certain situation with IMAP and PREAUTH.
- CVE-2021-39341HIGHCVSS 8.2EG 8.22021-11-01
The OptinMonster WordPress plugin is vulnerable to sensitive information disclosure and unauthorized setting updates due to insufficient authorization validation via the logged_in_or_has_api_key function in the ~/OMAPI/RestApi.php file tha…
- CVE-2021-39342HIGHCVSS 5.3EG 7.52021-09-29
The Credova_Financial WordPress plugin discloses a site's associated Credova API account username and password in plaintext via an AJAX action whenever a site user goes to checkout on a page that has the Credova Financing option enabled. T…
- CVE-2021-39882MEDIUMCVSS 5.3EG 5.32021-10-05
In all versions of GitLab CE/EE, provided a user ID, anonymous users can use a few endpoints to retrieve information about any GitLab user.
- CVE-2021-40148HIGHCVSS 7.5EG 7.52022-01-04
In Modem EMM, there is a possible information disclosure due to a missing data encryption. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Pa…
- CVE-2021-40366HIGHCVSS 7.4EG 7.42021-11-09
A vulnerability has been identified in Climatix POL909 (AWB module) (All versions < V11.42), Climatix POL909 (AWM module) (All versions < V11.34). The web server of affected devices transmits data without TLS encryption. This could allow a…
- CVE-2021-40392HIGHCVSS 7.5EG 7.52022-04-14
An information disclosure vulnerability exists in the Web Application functionality of Moxa MXView Series 3.2.4. Network sniffing can lead to a disclosure of sensitive information. An attacker can sniff network traffic to exploit this vuln…
- CVE-2021-40846HIGHCVSS 7.5EG 7.52022-03-04
An issue was discovered in Rhinode Trading Paints through 2.0.36. TP Updater.exe uses cleartext HTTP to check, and request, updates. Thus, attackers can man-in-the-middle a victim to download a malicious binary in place of the real update,…
- CVE-2021-40847HIGHCVSS 8.1EG 8.12021-09-21
The update process of the Circle Parental Control Service on various NETGEAR routers allows remote attackers to achieve remote code execution as root via a MitM attack. While the parental controls themselves are not enabled by default on t…
- CVE-2021-4161CRITICALCVSS 9.8EG 9.82021-12-27
The affected products contain vulnerable firmware, which could allow an attacker to sniff the traffic and decrypt login credential details. This could give an attacker admin rights through the HTTP web server.
- CVE-2021-41835HIGHCVSS 7.3EG 7.32022-01-21
Fresenius Kabi Agilia Link + version 3.0 does not enforce transport layer encryption. Therefore, transmitted data may be sent in cleartext. Transport layer encryption is offered on Port TCP/443, but the affected service does not perform an…
- CVE-2021-41849MEDIUMCVSS 5.5EG 5.52022-03-11
An issue was discovered in Luna Simo PPR1.180610.011/202001031830. It sends the following Personally Identifiable Information (PII) in plaintext using HTTP to servers located in China: user's list of installed apps and device International…
- CVE-2021-42111MEDIUMCVSS 5.5EG 5.52021-11-10
An issue was discovered in the RCDevs OpenOTP app 1.4.13 and 1.4.14 for iOS. If it is installed on a jailbroken device, it is possible to retrieve the PIN code used to access the application. The IOS app version 1.4.1631262629 resolves thi…
- CVE-2021-4258HIGHCVSS 3.7EG 7.52022-12-19
A vulnerability was found in whohas. It has been rated as problematic. This issue affects some unknown processing of the component Package Information Handler. The manipulation leads to cleartext transmission of sensitive information. The …
- CVE-2021-42699MEDIUMCVSS 5.7EG 5.72021-11-05
The affected product is vulnerable to cookie information being transmitted as cleartext over HTTP. An attacker can capture network traffic, obtain the user’s cookie and take over the account.
- CVE-2021-42948LOWCVSS 3.7EG 3.72022-09-16
HotelDruid Hotel Management Software v3.0.3 and below was discovered to have exposed session tokens in multiple links via GET parameters, allowing attackers to access user session id's.
- CVE-2021-43270HIGHCVSS 7.5EG 7.52021-11-02
Datalust Seq.App.EmailPlus (aka seq-app-htmlemail) 3.1.0-dev-00148, 3.1.0-dev-00170, and 3.1.0-dev-00176 can use cleartext SMTP on port 25 in some cases where encryption on port 465 was intended.
- CVE-2021-44480HIGHCVSS 8.1EG 8.12021-12-01
Wokka Lokka Q50 devices through 2021-11-30 allow remote attackers (who know the SIM phone number and password) to listen to a device's surroundings via a callback in an SMS command, as demonstrated by the 123456 and 523681 default password…
- CVE-2021-44518MEDIUMCVSS 6.8EG 6.82021-12-02
An issue was discovered in the eGeeTouch 3rd Generation Travel Padlock application for Android. The lock sends a pairing code before each operation (lock or unlock) activated via the companion app. The code is sent unencrypted, allowing an…
- CVE-2021-45081MEDIUMCVSS 5.9EG 5.92022-02-20
An issue was discovered in Cobbler through 3.3.1. Routines in several files use the HTTP protocol instead of the more secure HTTPS.
- CVE-2021-45100HIGHCVSS 7.5EG 7.52021-12-16
The ksmbd server through 3.4.2, as used in the Linux kernel through 5.15.8, sometimes communicates in cleartext even though encryption has been enabled. This occurs because it sets the SMB2_GLOBAL_CAP_ENCRYPTION flag when using the SMB 3.1…
- CVE-2021-45104HIGHCVSS 7.4EG 7.42022-04-06
An issue was discovered in HTCondor 9.0.x before 9.0.10 and 9.1.x before 9.5.1. An attacker who can capture HTCondor network data can interfere with users' jobs and data.
- CVE-2021-45447HIGHCVSS 7.7EG 7.72022-11-02
Hitachi Vantara Pentaho Business Analytics Server versions before 9.3.0.0, 9.2.0.2 and 8.3.0.25 with the Data Lineage feature enabled transmits database passwords in clear text. The transmission of sensitive data in clear text allow…
- CVE-2021-45735HIGHCVSS 7.5EG 7.52022-02-04
TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to use the HTTP protocol for authentication into the admin interface, allowing attackers to intercept user credentials via packet capture software.
- CVE-2021-45894MEDIUMCVSS 5.9EG 5.92022-04-05
An issue was discovered in Softwarebuero Zauner ARC 4.2.0.4. There is Cleartext Transmission of Sensitive Information.
- CVE-2022-0005LOWCVSS 2.4EG 2.42022-05-12
Sensitive information accessible by physical probing of JTAG interface for some Intel(R) Processors with SGX may allow an unprivileged user to potentially enable information disclosure via physical access.
- CVE-2022-0162HIGHCVSS 8.4EG 8.42022-02-09
The vulnerability exists in TP-Link TL-WR841N V11 3.16.9 Build 160325 Rel.62500n wireless router due to transmission of authentication information in cleartextbase64 format. Successful exploitation of this vulnerability could allow a remot…
- CVE-2022-0553MEDIUMCVSS 6.5EG 6.52023-01-11
There is no check to see if slot 0 is being uploaded from the device to the host. When using encrypted images this means the unencrypted firmware can be retrieved easily.
- CVE-2022-0988HIGHCVSS 7.1EG 7.52022-03-25
Delta Electronics DIAEnergie (Version 1.7.5 and prior) is vulnerable to cleartext transmission as the web application runs by default on HTTP. This could allow an attacker to remotely read transmitted information between the client and pro…
- CVE-2022-1524HIGHCVSS 7.4EG 7.42022-06-24
LRM version 2.4 and lower does not implement TLS encryption. A malicious actor can MITM attack sensitive data in-transit, including credentials.
- CVE-2022-2003CRITICALCVSS 7.7EG 9.12022-08-31
AutomationDirect DirectLOGIC is vulnerable to a specifically crafted serial message to the CPU serial port that will cause the PLC to respond with the PLC password in cleartext. This could allow an attacker to access and make unauthorized …
- CVE-2022-2005HIGHCVSS 7.5EG 7.52022-08-31
AutomationDirect C-more EA9 HTTP webserver uses an insecure mechanism to transport credentials from client to web server, which may allow an attacker to obtain the login credentials and login as a valid user. This issue affects: Automation…
- CVE-2022-20243MEDIUMCVSS 4.4EG 4.42022-08-11
In Core Utilities, there is a possible log information disclosure. This could lead to local information disclosure of sensitive browsing data with System execution privileges needed. User interaction is not needed for exploitation.Product:…
- CVE-2022-2083HIGHCVSS 7.5EG 7.52022-09-05
The Simple Single Sign On WordPress plugin through 4.1.0 leaks its OAuth client_secret, which could be used by attackers to gain unauthorized access to the site.
Map vulnerabilities like CWE-319 to your infrastructure
EchelonGraph correlates every CVE — across CWE-319 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →