CWE-319
923 CVEs • Abstraction: Base • Likelihood of Exploit: High
Cleartext Transmission of Sensitive Information
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
CVEs (923)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Improper usage of insecure protocol (i.e. HTTP) in SogouSDK of Chinese Samsung Keyboard prior to versions 5.3.70.1 in Android 11, 5.4.60.49, 5.4.85.5, 5.5.00.58 in Android 12, and 5.6.00.52, 5.6.10.42, 5.7.00.45 in Andro...Show more |
LOYTEC electronics GmbH LINX Configurator (all versions) is vulnerable to Insecure Permissions. An admin credential is passed as a value of URL parameters without encryption, so it allows remote attackers to steal the pa...Show more |
LOYTEC electronics GmbH LINX Configurator (all versions) uses HTTP Basic Authentication, which transmits usernames and passwords in base64-encoded cleartext and allows remote attackers to steal the password and gain full...Show more |
1Digitalcomtech 1Syrus 4g Iot Telematics Gateway Firmware Jun 17, 2026 Nov 21, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The Syrus4 IoT gateway utilizes an unsecured MQTT server to download and execute arbitrary commands, allowing a remote unauthenticated attacker to execute code on any Syrus4 device connected to the cloud service. The MQT...Show more |
A vulnerability has been identified in COMOS (All versions < V10.4.4). Caching system in the affected application leaks sensitive information such as user and project information in cleartext via UDP. |
1Loytec 3Linx 212 Firmware Liob 586 FirmwareLvis 3me12 A1 FirmwareJun 17, 2026 Nov 4, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 LOYTEC LINX-151, LINX-212, LVIS-3ME12-A1, LIOB-586, LIOB-580 V2, LIOB-588, L-INX Configurator devices (all versions) use cleartext HTTP for login. |
1Loytec 3Linx 212 Firmware Liob 586 FirmwareLvis 3me12 A1 FirmwareJun 17, 2026 Nov 4, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 LOYTEC LINX-151, LINX-212, LVIS-3ME12-A1, LIOB-586, LIOB-580 V2, LIOB-588, L-INX Configurator devices (all versions) send password-change requests via cleartext HTTP. |
bcrypt password hashing in Botan before 2.1.0 does not correctly handle passwords with a length between 57 and 72 characters, which makes it easier for attackers to determine the cleartext password. |
A vulnerability has been identified in PT-G503 Series firmware versions prior to v5.2, where the Secure attribute for sensitive cookies in HTTPS sessions is not set, which could cause the cookie to be transmitted in plai...Show more |
1Boschrexroth 3Ctrlx Hmi Web Panel Wr2107 Firmware Ctrlx Hmi Web Panel Wr2110 FirmwareCtrlx Hmi Web Panel Wr2115 FirmwareJun 17, 2026 Oct 25, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 The Android Client application, when enrolled with the define method 1 (the user manually inserts the server ip address), use HTTP protocol to retrieve sensitive information (ip address and credentials to connect to a r...Show more |
IBM Security Verify Governance 10.0 does not encrypt sensitive or critical information before storage or transmission. IBM X-Force ID: 256020. |
1Ibm 1Cognos Dashboards On Cloud Pak For Data Jun 17, 2026 Oct 22, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 exposes sensitive information in environment variables which could aid in further attacks against the system. IBM X-Force ID: 260736. |
1Ibm 1Cognos Dashboards On Cloud Pak For Data Jun 17, 2026 Oct 22, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 exposes sensitive information in container images which could lead to further attacks against the system. IBM X-Force ID: 260730. |
The affected product is vulnerable to a cleartext transmission of sensitive information vulnerability, which may allow an attacker with access to the network, where clients have access to the DexGate server, c...Show more |
1Bakerhughes 1Bentley Nevada 3500 System Firmware Jun 17, 2026 Oct 19, 2023 N/A· v4 8.2 HIGH· v3 N/A· v2 Baker Hughes – Bently Nevada 3500 System TDI Firmware version 5.05 contains a cleartext transmission vulnerability which could allow an attacker to steal the authentication secret from communication traffic to the...Show more |
1Ibm 1Security Verify Privilege On Premises Jun 17, 2026 Oct 17, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2
IBM Security Verify Privilege On-Premises 11.5 could disclose sensitive information to an attacked due to the transmission of data in clear text. IBM X-Force ID: 221962.
|
A vulnerability was found in Delta Electronics WPLSoft 2.51. It has been classified as problematic. Affected is an unknown function of the component Modbus Handler. The manipulation leads to cleartext transmission of sen...Show more |
Cleartext Transmission of Sensitive Information in RDT400 in SICK APU allows an
unprivileged remote attacker to retrieve potentially sensitive information via intercepting network traffic
that is not encrypted.
|
A cleartext transmission of sensitive information vulnerability has been reported to affect QVPN Device Client. If exploited, the vulnerability could allow local authenticated administrators to read sensitive data via un...Show more |
2Opendatahub Redhat2Open Data Hub Dashboard Openshift Data ScienceJun 17, 2026 Oct 4, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in Red Hat OpenShift Data Science. When exporting a pipeline from the Elyra notebook pipeline editor as Python DSL or YAML, it reads S3 credentials from the cluster (ds pipeline server) and saves them in...Show more |