CWE-319— Cleartext Transmission of Sensitive Information
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.— MITRE CWE catalog
925 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-319page 1 of 19
- CVE-2002-1949HIGHCVSS 7.5EG 7.52002-12-31
The Network Attached Storage (NAS) Administration Web Page for Iomega NAS A300U transmits passwords in cleartext, which allows remote attackers to sniff the administrative password.
- CVE-2003-5002MEDIUMCVSS 3.7EG 5.32022-03-28
A vulnerability was found in ISS BlackICE PC Protection. It has been declared as problematic. Affected by this vulnerability is the component Update Handler which allows cleartext transmission of data. NOTE: This vulnerability only affects…
- CVE-2004-1852MEDIUMCVSS v2 5.0EG 5.02004-03-23
DameWare Mini Remote Control 3.x before 3.74 and 4.x before 4.2 transmits the Blowfish encryption key in plaintext, which allows remote attackers to gain sensitive information.
- CVE-2005-2069MEDIUMCVSS v2 5.0EG 5.02005-06-30
pam_ldap and nss_ldap, when used with OpenLDAP and connecting to a slave using TLS, does not use TLS for the subsequent connection if the client is referred to a master, which may cause a password to be sent in cleartext and allows remote …
- CVE-2005-3140HIGHCVSS 7.5EG 7.52005-10-05
Procom NetFORCE 800 4.02 M10 Build 20 and possibly other versions sends the NIS password map (passwd.nis) as a file attachment in diagnostic e-mail messages, which allows remote attackers to obtain the cleartext NIS password hashes.
- CVE-2007-4786MEDIUMCVSS 5.3EG 5.32007-09-10
Cisco Adaptive Security Appliance (ASA) running PIX 7.0 before 7.0.7.1, 7.1 before 7.1.2.61, 7.2 before 7.2.2.34, and 8.0 before 8.0.2.11, when AAA is enabled, composes %ASA-5-111008 messages from the "test aaa" command with cleartext pass…
- CVE-2007-5626MEDIUMCVSS 5.5EG 5.52007-10-23
make_catalog_backup in Bacula 2.2.5, and probably earlier, sends a MySQL password as a command line argument, and sometimes transmits cleartext e-mail containing this command line, which allows context-dependent attackers to obtain the pas…
- CVE-2008-0374HIGHCVSS 7.5EG 7.52008-01-22
OKI C5510MFP Printer CU H2.15, PU 01.03.01, System F/W 1.01, and Web Page 1.00 sends the configuration of the printer in cleartext, which allows remote attackers to obtain the administrative password by connecting to TCP port 5548 or 7777.
- CVE-2008-3289HIGHCVSS 7.5EG 7.52008-07-24
EMC Dantz Retrospect Backup Client 7.5.116 sends the password hash in cleartext at an unspecified point, which allows remote attackers to obtain sensitive information via a crafted packet.
- CVE-2008-4122HIGHCVSS 7.5EG 7.52008-12-19
Joomla! 1.5.8 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
- CVE-2008-4390HIGHCVSS 7.5EG 7.52008-12-09
The Cisco Linksys WVC54GC wireless video camera before firmware 1.25 sends cleartext configuration data in response to a Setup Wizard remote-management command, which allows remote attackers to obtain sensitive information such as password…
- CVE-2010-4177MEDIUMCVSS 5.5EG 5.52019-11-12
mysql-gui-tools (mysql-query-browser and mysql-admin) before 5.0r14+openSUSE-2.3 exposes the password of a user connected to the MySQL server in clear text form via the list of running processes.
- CVE-2011-3022MEDIUMCVSS v2 5.0EG 5.02012-02-16
translate/translate_manager.cc in Google Chrome before 17.0.963.56 and 19.x before 19.0.1036.7 uses an HTTP session to exchange data for translation, which allows remote attackers to obtain sensitive information by sniffing the network.
- CVE-2012-1257MEDIUMCVSS 5.5EG 5.52019-11-20
Pidgin 2.10.0 uses DBUS for certain cleartext communication, which allows local users to obtain sensitive information via a dbus session monitor.
- CVE-2012-5562HIGHCVSS 8.6EG 8.62019-12-02
A flaw was found in rhn-proxy. This vulnerability may allow the rhn-proxy to transmit user credentials in clear-text when it accesses RHN Satellite. This could lead to information disclosure, where sensitive authentication details are expo…
- CVE-2014-5380HIGHCVSS 7.5EG 7.52020-01-13
Grand MA 300 allows retrieval of the access PIN from sniffed data.
- CVE-2015-0987CRITICALCVSS 10.0EG 10.02015-10-06
Omron CX-One CX-Programmer before 9.6, CJ2M PLC devices before 2.1, and CJ2H PLC devices before 1.5 rely on cleartext password transmission, which allows remote attackers to obtain sensitive information by sniffing the network during a PLC…
- CVE-2015-7542MEDIUMCVSS 5.3EG 5.32019-12-03
A vulnerability exists in libgwenhywfar through 4.12.0 due to the usage of outdated bundled CA certificates.
- CVE-2016-10933MEDIUMCVSS 5.9EG 5.92019-08-26
An issue was discovered in the portaudio crate through 0.7.0 for Rust. There is a man-in-the-middle issue because the source code is downloaded over cleartext HTTP.
- CVE-2016-5638HIGHCVSS 7.5EG 7.52018-07-24
There are few web pages associated with the genie app on the Netgear WNDR4500 running firmware version V1.0.1.40_1.0.6877. Genie app adds some capabilities over the Web GUI and can be accessed even when you are away from home. A remote att…
- CVE-2016-5649CRITICALCVSS 9.8EG 9.82018-07-24
A vulnerability is in the 'BSW_cxttongr.htm' page of the Netgear DGN2200, version DGN2200-V1.0.0.50_7.0.50, and DGND3700, version DGND3700-V1.0.0.17_1.0.17, which can allow a remote attacker to access this page without any authentication. …
- CVE-2017-0925HIGHCVSS 7.2EG 7.22018-03-21
Gitlab Enterprise Edition version 10.1.0 is vulnerable to an insufficiently protected credential issue in the project service integration API endpoint resulting in an information disclosure of plaintext password.
- CVE-2017-1000024HIGHCVSS 7.5EG 7.52017-07-17
Shotwell version 0.24.4 or earlier and 0.25.3 or earlier is vulnerable to an information disclosure in the web publishing plugins resulting in potential password and oauth token plaintext transmission
- CVE-2017-1181HIGHCVSS 7.0EG 7.02017-07-17
IBM Tivoli Monitoring Portal V6 client could allow a local attacker to gain elevated privileges for IBM Tivoli Monitoring, caused by the default console connection not being encrypted. IBM X-Force ID: 123487.
- CVE-2017-12310HIGHCVSS 7.5EG 7.52018-03-27
A vulnerability in the auto discovery phase of Cisco Spark Hybrid Calendar Service could allow an unauthenticated, remote attacker to view sensitive information in the unencrypted headers of an HTTP method request. The attacker could use t…
- CVE-2017-1232MEDIUMCVSS 5.9EG 5.92017-10-26
IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors. IBM X-Force ID: 123911.
- CVE-2017-12716MEDIUMCVSS 6.5EG 6.52018-04-25
Abbott Laboratories Accent and Anthem pacemakers manufactured prior to Aug 28, 2017 transmit unencrypted patient information via RF communications to programmers and home monitoring units. Additionally, the Accent and Anthem pacemakers sto…
- CVE-2017-14009MEDIUMCVSS 6.5EG 6.52017-10-17
An Information Exposure issue was discovered in ProMinent MultiFLEX M10a Controller web interface. When an authenticated user uses the Change Password feature on the application, the current password for the user is specified in plaintext.…
- CVE-2017-14486HIGHCVSS 7.5EG 7.52017-12-01
The Vibease Wireless Remote Vibrator app for Android and the Vibease Chat app for iOS use cleartext to exchange messages with other apps and the PLAIN SASL mechanism to send auth tokens to Vibease servers, which allows remote attackers to …
- CVE-2017-15042MEDIUMCVSS 5.9EG 5.92017-10-05
An unintended cleartext issue exists in Go before 1.8.4 and 1.9.x before 1.9.1. RFC 4954 requires that, during SMTP, the PLAIN auth scheme must only be used on network connections secured with TLS. The original implementation of smtp.Plain…
- CVE-2017-15290HIGHCVSS 7.5EG 7.52017-10-12
Mirasys Video Management System (VMS) 6.x before 6.4.6, 7.x before 7.5.15, and 8.x before 8.1.1 has a login process in which cleartext data is sent from a server to a client, and not all of this data is required for the client functionalit…
- CVE-2017-15999CRITICALCVSS 9.8EG 9.82017-10-29
In the "NQ Contacts Backup & Restore" application 1.1 for Android, no HTTPS is used for transmitting login and synced user data. When logging in, the username is transmitted in cleartext along with an SHA-1 hash of the password. The attack…
- CVE-2017-16035HIGHCVSS 8.1EG 8.12018-06-04
The hubl-server module is a wrapper for the HubL Development Server. During installation hubl-server downloads a set of dependencies from api.hubapi.com. It appears in the code that these files are downloaded over HTTPS however the api.hub…
- CVE-2017-16040HIGHCVSS 8.1EG 8.12018-06-04
gfe-sass is a library for promises (CommonJS/Promises/A,B,D) gfe-sass downloads resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resource…
- CVE-2017-16041MEDIUMCVSS 5.9EG 5.92018-06-04
ikst versions before 1.1.2 download resources over HTTP, which leaves it vulnerable to MITM attacks.
- CVE-2017-1694HIGHCVSS 8.1EG 8.12017-12-20
IBM Integration Bus 9.0 and 10.0 transmits user credentials in plain in clear text which can be read by an attacker using man in the middle techniques. IBM X-Force ID: 134165.
- CVE-2017-17844MEDIUMCVSS 6.5EG 6.52017-12-27
An issue was discovered in Enigmail before 1.9.9. A remote attacker can obtain cleartext content by sending an encrypted data block (that the attacker cannot directly decrypt) to a victim, and relying on the victim to automatically decrypt…
- CVE-2017-20109MEDIUMCVSS 4.3EG 6.52022-06-29
A vulnerability classified as problematic was found in Teleopti WFM up to 7.1.0. Affected by this vulnerability is an unknown functionality of the file /TeleoptiWFM/Administration/GetOneTenant of the component Administration. The manipulat…
- CVE-2017-20200LOWCVSS 3.7EG 3.72025-09-23
A vulnerability has been found in Coinomi up to 1.7.6. This issue affects some unknown processing. Such manipulation leads to cleartext transmission of sensitive information. The attack can be launched remotely. This attack is characterize…
- CVE-2017-2412MEDIUMCVSS 5.9EG 5.92017-04-02
An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves the "iTunes Store" component. It allows man-in-the-middle attackers to modify the client-server data stream to iTunes sandbox web services b…
- CVE-2017-3305MEDIUMCVSS 5.3EG 5.32017-04-24
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: C API). Supported versions that are affected are 5.5.55 and earlier and 5.6.35 and earlier. Difficult to exploit vulnerability allows low privileged attacke…
- CVE-2017-3815MEDIUMCVSS 5.3EG 5.32017-03-17
An API Privilege vulnerability in Cisco TelePresence Server Software could allow an unauthenticated, remote attacker to emulate Cisco TelePresence Server endpoints. Affected Products: This vulnerability affects Cisco TelePresence Server MS…
- CVE-2017-5259HIGHCVSS 8.8EG 8.82017-12-20
In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, an undocumented, root-privilege administration web shell is available using the HTTP path https://<device-ip-or-hostname>/adm/syscmd.asp.
- CVE-2017-5652HIGHCVSS 7.5EG 7.52017-07-10
During a routine security analysis, it was found that one of the ports in Apache Impala (incubating) 2.7.0 to 2.8.0 sent data in plaintext even when the cluster was configured to use TLS. The port in question was used by the StatestoreSubs…
- CVE-2017-6341MEDIUMCVSS 5.9EG 5.92017-02-27
Dahua DHI-HCVR7216A-S3 devices with NVR Firmware 3.210.0001.10 2016-06-06, Camera Firmware 2.400.0000.28.R 2016-03-29, and SmartPSS Software 1.16.1 2017-01-19 send cleartext passwords in response to requests from the Web Page, Mobile Appli…
- CVE-2017-6370MEDIUMCVSS 5.3EG 5.32017-03-17
TYPO3 7.6.15 sends an http request to an index.php?loginProvider URI in cases with an https Referer, which allows remote attackers to obtain sensitive cleartext information by sniffing the network and reading the userident and username fie…
- CVE-2017-6410MEDIUMCVSS 5.5EG 5.52017-03-02
kpac/script.cpp in KDE kio before 5.32 and kdelibs before 4.14.30 calls the PAC FindProxyForURL function with a full https URL (potentially including Basic Authentication credentials, a query string, or PATH_INFO), which allows remote atta…
- CVE-2017-6432HIGHCVSS 8.1EG 8.12017-03-09
An issue was discovered on Dahua DHI-HCVR7216A-S3 3.210.0001.10 build 2016-06-06 devices. The Dahua DVR Protocol, which operates on TCP Port 37777, is an unencrypted, binary protocol. Performing a Man-in-the-Middle attack allows both sniff…
- CVE-2017-6665MEDIUMCVSS 6.5EG 6.52017-08-07
A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to reset the Autonomic Control Plane (ACP) of an affected system and view ACP packets tha…
- CVE-2017-7078MEDIUMCVSS 5.3EG 5.32017-10-23
An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is affected. The issue involves the "Mail Drafts" component. It allows remote attackers to obtain sensitive information by reading unintended …
Map vulnerabilities like CWE-319 to your infrastructure
EchelonGraph correlates every CVE — across CWE-319 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →