CWE-319
898 CVEs • Abstraction: Base • Likelihood of Exploit: High
Cleartext Transmission of Sensitive Information
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
CVEs (898)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Globalnorthstar 1Northstar Club Management Jun 17, 2026 Feb 4, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Cleartext Transmission of Sensitive Information in /northstar/Admin/login.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote local user to intercept users credentials transmitted in cleartext o...Show more |
TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to use the HTTP protocol for authentication into the admin interface, allowing attackers to intercept user credentials via packet capture software. |
1Fresenius Kabi 6Agilia Connect Agilia Partner Maintenance SoftwareLink+ Agilia Firmware+3 moreJun 17, 2026 Jan 21, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Fresenius Kabi Agilia Link + version 3.0 does not enforce transport layer encryption. Therefore, transmitted data may be sent in cleartext. Transport layer encryption is offered on Port TCP/443, but the affected service...Show more |
Jenkins Active Directory Plugin 2.25 and earlier does not encrypt the transmission of data between the Jenkins controller and Active Directory servers in most configurations. |
In Modem EMM, there is a possible information disclosure due to a missing data encryption. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed f...Show more |
Netgear Nighthawk R6700 version 1.0.4.120 does not utilize secure communication methods to the SOAP interface. By default, all communication to/from the device's SOAP Interface (port 5000) is sent via HTTP, which causes...Show more |
Netgear Nighthawk R6700 version 1.0.4.120 does not utilize secure communication methods to the web interface. By default, all communication to/from the device's web interface is sent via HTTP, which causes potentially se...Show more |
Netgear RAX43 version 1.0.3.96 does not utilize secure communications to the web interface. By default, all communication to/from the device is sent via HTTP, which causes potentially sensitive information (such as usern...Show more |
1Trendnet 1Tew 827dru Firmware Jun 17, 2026 Dec 30, 2021 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 Trendnet AC2600 TEW-827DRU version 2.08B01 contains an security flaw in the web interface. HTTPS is not enabled on the device by default. This results in cleartext transmission of sensitive information such as passwords. |
1Moxa 3Mgate Mb3180 Firmware Mgate Mb3280 FirmwareMgate Mb3480 FirmwareJun 17, 2026 Dec 27, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The affected products contain vulnerable firmware, which could allow an attacker to sniff the traffic and decrypt login credential details. This could give an attacker admin rights through the HTTP web server. |
2Ksmbd Project Netapp9H300e Firmware H300s FirmwareH410c Firmware+6 moreJun 17, 2026 Dec 16, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The ksmbd server through 3.4.2, as used in the Linux kernel through 5.15.8, sometimes communicates in cleartext even though encryption has been enabled. This occurs because it sets the SMB2_GLOBAL_CAP_ENCRYPTION flag whe...Show more |
An issue was discovered in the eGeeTouch 3rd Generation Travel Padlock application for Android. The lock sends a pairing code before each operation (lock or unlock) activated via the companion app. The code is sent unenc...Show more |
1Wokkalokka 1Wokka Watch Q50 Firmware Jun 17, 2026 Dec 1, 2021 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 Wokka Lokka Q50 devices through 2021-11-30 allow remote attackers (who know the SIM phone number and password) to listen to a device's surroundings via a callback in an SMS command, as demonstrated by the 123456 and 5236...Show more |
It was discovered that Kibana’s JIRA connector & IBM Resilient connector could be used to return HTTP response data on internal hosts, which may be intentionally hidden from public view. Using this vulnerability, a malic...Show more |
1Ibm 2Security Guardium Key Lifecycle Manager Security Key Lifecycle ManagerJun 17, 2026 Nov 15, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit...Show more |
1Binatoneglobal 21Cn28 Firmware Cn40 FirmwareCn50 Firmware+18 moreJun 17, 2026 Nov 12, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Some device communications in some Motorola-branded Binatone Hubble Cameras with backend Hubble services are not encrypted which could lead to the communication channel being accessible by an attacker. |
1Siemens 1Climatix Pol909 Firmware Jun 17, 2026 Nov 9, 2021 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 A vulnerability has been identified in Climatix POL909 (AWB module) (All versions < V11.42), Climatix POL909 (AWM module) (All versions < V11.34). The web server of affected devices transmits data without TLS encryption....Show more |
IBM QRadar Network Security 5.4.0 and 5.5.0 transmits sensitive or security-critical data in cleartext in a communication channel that can be obtained using man in the middle techniques. IBM X-Force ID: 17467. |
Meross Smart Wi-Fi 2 Way Wall Switch (MSS550X), on its 3.1.3 version and before, creates an open Wi-Fi Access Point without the required security measures in its initial setup. This could allow a remote attacker to obtai...Show more |
1Ibm 2Business Automation Workflow Business Process ManagerJun 17, 2026 Nov 5, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 IBM Business Automation Workflow 18. 19, 20, 21, and IBM Business Process Manager 8.5 and d8.6 transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized intercepti...Show more |