CWE-319— Cleartext Transmission of Sensitive Information
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.— MITRE CWE catalog
976 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-319page 1 of 20
- CVE-2026-22306CRITICALCVSS 10.0EG 10.02026-08-19
Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext transmission of sensitive information vulnerability in Ozols Grupa OZOLS on Windows caused by an abandoned auto-update dom…
- CVE-2025-61481CRITICALCVSS 10.0EG 10.02025-10-27
An issue in MikroTik RouterOS v.7.14.2 and SwOS v.2.18 exposes the WebFig management interface over cleartext HTTP by default, allowing an on-path attacker to execute injected JavaScript in the administrator’s browser and intercept crede…
- CVE-2025-4378CRITICALCVSS 10.0EG 10.02025-06-24
Cleartext Transmission of Sensitive Information, Use of Hard-coded Credentials vulnerability in Ataturk University ATA-AOF Mobile Application allows Authentication Abuse, Authentication Bypass. This issue affects ATA-AOF Mobile Applicatio…
- CVE-2025-47419CRITICALCVSS 10.0EG 10.02025-05-06
Cleartext Transmission of Sensitive Information vulnerability in Crestron Automate VX allows Sniffing Network Traffic. The device allows Web UI and API access over non-secure network ports which exposes sensitive information such as user …
- CVE-2015-0987CRITICALCVSS 10.0EG 10.02015-10-06
Omron CX-One CX-Programmer before 9.6, CJ2M PLC devices before 2.1, and CJ2H PLC devices before 1.5 rely on cleartext password transmission, which allows remote attackers to obtain sensitive information by sniffing the network during a PLC…
- CVE-2023-6248CRITICALCVSS 9.8EG 10.02023-11-21
The Syrus4 IoT gateway utilizes an unsecured MQTT server to download and execute arbitrary commands, allowing a remote unauthenticated attacker to execute code on any Syrus4 device connected to the cloud service. The MQTT server also leaks…
- CVE-2026-69658CRITICALCVSS 9.8EG 9.82026-08-27
MQTT credentials and control traffic are transmitted in cleartext, exposing sensitive information to network-level attackers. This may enable unauthorized device impersonation and disruption of messaging functions.
- CVE-2026-48902CRITICALCVSS 9.8EG 9.82026-05-26
The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.
- CVE-2026-24212CRITICALCVSS 9.8EG 9.82026-05-26
NVIDIA Isaac Launchable for Linux contains a vulnerability where sensitive information is transmitted in clear text. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure,…
- CVE-2025-34271CRITICALCVSS 9.8EG 9.82025-10-30
Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the cluster manager component when requesting sensitive credentials from peer nodes over an unencrypted channel even when SSL/TLS is enabled in the product configur…
- CVE-2025-56447CRITICALCVSS 9.8EG 9.82025-10-22
TM2 Monitoring v3.04 contains an authentication bypass and plaintext credential disclosure.
- CVE-2025-32880CRITICALCVSS 9.8EG 9.82025-06-20
An issue was discovered on COROS PACE 3 devices through 3.0808.0. It implements a function to connect the watch to a WLAN. With WLAN access, the COROS Pace 3 downloads firmware files via HTTP. However, the communication is not encrypted an…
- CVE-2025-26199CRITICALCVSS 9.8EG 9.82025-06-18
CloudClassroom-PHP-Project v1.0 is affected by an insecure credential transmission vulnerability. The application transmits passwords over unencrypted HTTP during the login process, exposing sensitive credentials to potential interception …
- CVE-2023-39245CRITICALCVSS 9.8EG 9.82024-02-15
DELL ESI (Enterprise Storage Integrator) for SAP LAMA, version 10.0, contains an information disclosure vulnerability in EHAC component. An remote unauthenticated attacker could potentially exploit this vulnerability by eavesdropping the …
- CVE-2023-31410CRITICALCVSS 9.8EG 9.82023-06-19
A remote unprivileged attacker can intercept the communication via e.g. Man-In-The-Middle, due to the absence of Transport Layer Security (TLS) in the SICK EventCam App. This lack of encryption in the communication channel can lead to the …
- CVE-2023-33730CRITICALCVSS 9.8EG 9.82023-05-31
Privilege Escalation in the "GetUserCurrentPwd" function in Microworld Technologies eScan Management Console 14.0.1400.2281 allows any remote attacker to retrieve password of any admin or normal user in plain text format.
- CVE-2023-30354CRITICALCVSS 9.8EG 9.82023-05-10
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 does not defend against physical access to U-Boot via the UART: the Wi-Fi password is shown, and the hardcoded boot password can be inserted for console access.
- CVE-2022-47714CRITICALCVSS 9.8EG 9.82023-02-01
Last Yard 22.09.8-1 does not enforce HSTS headers
- CVE-2022-43724CRITICALCVSS 9.8EG 9.82022-12-13
A vulnerability has been identified in SICAM PAS/PQS (All versions < V7.0). Affected software transmits the database credentials for the inbuilt SQL server in cleartext. In combination with the by default enabled xp_cmdshell feature unauth…
- CVE-2022-33321CRITICALCVSS 9.8EG 9.82022-11-08
Cleartext Transmission of Sensitive Information vulnerability due to the use of Basic Authentication for HTTP connections in Mitsubishi Electric consumer electronics products (PHOTOVOLTAIC COLOR MONITOR ECO-GUIDE, HEMS adapter, Wi-Fi Inter…
- CVE-2022-21829CRITICALCVSS 9.8EG 9.82022-06-24
Concrete CMS Versions 9.0.0 through 9.0.2 and 8.5.7 and below can download zip files over HTTP and execute code from those zip files which could lead to an RCE. Fixed by enforcing ‘concrete_secure’ instead of ‘concrete’. Concrete n…
- CVE-2021-4161CRITICALCVSS 9.8EG 9.82021-12-27
The affected products contain vulnerable firmware, which could allow an attacker to sniff the traffic and decrypt login credential details. This could give an attacker admin rights through the HTTP web server.
- CVE-2021-20623CRITICALCVSS 9.8EG 9.82021-02-05
Video Insight VMS versions prior to 7.8 allows a remote attacker to execute arbitrary code with the system user privilege by sending a specially crafted request.
- CVE-2020-5426CRITICALCVSS 9.8EG 9.82020-11-11
Scheduler for TAS prior to version 1.4.0 was permitting plaintext transmission of UAA client token by sending it over a non-TLS connection. This also depended on the configuration of the MySQL server which is used to cache a UAA client tok…
- CVE-2020-12040CRITICALCVSS 9.8EG 9.82020-06-29
Sigma Spectrum Infusion System v's6.x (model 35700BAX) and Baxter Spectrum Infusion System Version(s) 8.x (model 35700BAX2) at the application layer uses an unauthenticated clear-text communication channel to send and receive system status…
- CVE-2020-5594CRITICALCVSS 9.8EG 9.82020-06-23
Mitsubishi Electric MELSEC iQ-R, iQ-F, Q, L, and FX series CPU modules all versions contain a vulnerability that allows cleartext transmission of sensitive information between CPU modules and GX Works3 and/or GX Works2 via unspecified vect…
- CVE-2020-6195CRITICALCVSS 9.8EG 9.82020-04-14
SAP Business Objects Business Intelligence Platform (CMC), version 4.1, 4.2, shows cleartext password in the response, leading to Information Disclosure. It involves social engineering in order to gain access to system and If password is k…
- CVE-2020-11542CRITICALCVSS 9.8EG 9.82020-04-04
3xLOGIC Infinias eIDC32 2.213 devices with Web 1.107 allow Authentication Bypass via CMD.HTM?CMD= because authentication depends on the client side's interpretation of the <KEY>MYKEY</KEY> substring.
- CVE-2019-13394CRITICALCVSS 9.8EG 9.82020-03-13
The Voo branded NETGEAR CG3700b custom firmware V2.02.03 uses HTTP Basic Authentication over cleartext HTTP.
- CVE-2020-10376CRITICALCVSS 9.8EG 9.82020-03-11
Technicolor TC7337NET 08.89.17.23.03 devices allow remote attackers to discover passwords by sniffing the network for an "Authorization: Basic" HTTP header.
- CVE-2020-6198CRITICALCVSS 9.8EG 9.82020-03-10
SAP Solution Manager (Diagnostics Agent), version 720, allows unencrypted connections from unauthenticated sources. This allows an attacker to control all remote functions on the Agent due to Missing Authentication Check.
- CVE-2020-9550CRITICALCVSS 9.8EG 9.82020-03-04
Rubetek SmartHome 2020 devices use unencrypted 433 MHz communication between controllers and beacons, allowing an attacker to sniff and spoof beacon requests remotely.
- CVE-2020-9477CRITICALCVSS 9.8EG 9.82020-03-04
An issue was discovered on HUMAX HGA12R-02 BRGCAA 1.1.53 devices. A vulnerability in the authentication functionality in the web-based interface could allow an unauthenticated remote attacker to capture packets at the time of authenticatio…
- CVE-2019-15911CRITICALCVSS 9.8EG 9.82019-12-20
An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Because of insecure key transport in ZigBee communication, attackers can obtain sensitive information, cause the multiple denial…
- CVE-2019-16674CRITICALCVSS 9.8EG 9.82019-12-06
An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. Authentication Information used in a cookie is predictable and can lead to admin pas…
- CVE-2019-16672CRITICALCVSS 9.8EG 9.82019-12-06
An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. Sensitive Credentials data is transmitted in cleartext.
- CVE-2019-12503CRITICALCVSS 9.8EG 9.82019-12-02
Due to unencrypted and unauthenticated data communication, the wireless barcode scanner Inateck BCST-60 is prone to keystroke injection attacks. Thus, an attacker is able to send arbitrary keystrokes to a victim's computer system, e.g., to…
- CVE-2019-18852CRITICALCVSS 9.8EG 9.82019-11-11
Certain D-Link devices have a hardcoded Alphanetworks user account with TELNET access because of /etc/config/image_sign or /etc/alpha_config/image_sign. This affects DIR-600 B1 V2.01 for WW, DIR-890L A1 v1.03, DIR-615 J1 v100 (for DCN), DI…
- CVE-2019-17393CRITICALCVSS 9.8EG 9.82019-10-18
The Customer's Tomedo Server in Version 1.7.3 communicates to the Vendor Tomedo Server via HTTP (in cleartext) that can be sniffed by unauthorized actors. Basic authentication is used for the authentication, making it possible to base64 de…
- CVE-2019-5505CRITICALCVSS 9.8EG 9.82019-09-24
ONTAP Select Deploy administration utility versions 2.2 through 2.12.1 transmit credentials in plaintext.
- CVE-2018-11422CRITICALCVSS 9.8EG 9.82019-07-03
Moxa OnCell G3100-HSPA Series version 1.6 Build 17100315 and prior use a proprietary configuration protocol that does not provide confidentiality, integrity, and authenticity security controls. All information is sent in plain text, and ca…
- CVE-2018-11421CRITICALCVSS 9.8EG 9.82019-07-03
Moxa OnCell G3100-HSPA Series version 1.6 Build 17100315 and prior use a proprietary monitoring protocol that does not provide confidentiality, integrity, and authenticity security controls. All information is sent in plain text, and can b…
- CVE-2019-3801CRITICALCVSS 9.8EG 9.82019-04-25
Cloud Foundry cf-deployment, versions prior to 7.9.0, contain java components that are using an insecure protocol to fetch dependencies when building. A remote unauthenticated malicious attacker could hijack the DNS entry for the dependenc…
- CVE-2019-3793CRITICALCVSS 9.8EG 9.82019-04-24
Pivotal Apps Manager Release, versions 665.0.x prior to 665.0.28, versions 666.0.x prior to 666.0.21, versions 667.0.x prior to 667.0.7, contain an invitation service that accepts HTTP. A remote unauthenticated user could listen to network…
- CVE-2019-6526CRITICALCVSS 9.8EG 9.82019-04-15
Moxa IKS-G6824A series Versions 4.5 and prior, EDS-405A series Version 3.8 and prior, EDS-408A series Version 3.8 and prior, and EDS-510A series Version 3.8 and prior use plaintext transmission of sensitive data, which may allow an attacke…
- CVE-2018-11749CRITICALCVSS 9.8EG 9.82018-08-24
When users are configured to use startTLS with RBAC LDAP, at login time, the user's credentials are sent via plaintext to the LDAP server. This affects Puppet Enterprise 2018.1.3, 2017.3.9, and 2016.4.14, and is fixed in Puppet Enterprise …
- CVE-2018-8855CRITICALCVSS 9.8EG 9.82018-07-24
Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. The devices allow unencrypted Web connections by default, and devices can receive configuration a…
- CVE-2016-5649CRITICALCVSS 9.8EG 9.82018-07-24
A vulnerability is in the 'BSW_cxttongr.htm' page of the Netgear DGN2200, version DGN2200-V1.0.0.50_7.0.50, and DGND3700, version DGND3700-V1.0.0.17_1.0.17, which can allow a remote attacker to access this page without any authentication. …
- CVE-2018-7246CRITICALCVSS 9.8EG 9.82018-04-18
A cleartext transmission of sensitive information vulnerability exists in Schneider Electric's 66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS. he integrated web server (Port 80/443/TCP) of the affected device…
- CVE-2018-6295CRITICALCVSS 9.8EG 9.82018-03-13
Unencrypted way of remote control and communications in Hanwha Techwin Smartcams
Map vulnerabilities like CWE-319 to your infrastructure
EchelonGraph correlates every CVE — across CWE-319 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →