← Back
CWE-319

898 CVEs • Abstraction: Base • Likelihood of Exploit: High

Cleartext Transmission of Sensitive Information

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

JSON object

Loading...

CVEs (898)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Qradar Security Information And Event Manager
Jun 17, 2026
Jul 16, 2021
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
IBM QRadar SIEM 7.3 and 7.4 uses less secure methods for protecting data in transit between hosts when encrypt host connections is not enabled as well as data at rest. IBM X-Force ID: 192539.
1Magicsmotion
1Flamingo 2 Firmware
Jun 17, 2026
Jul 15, 2021
N/A· v4
5.3 MEDIUM· v3
2.9 LOW· v2
MagicMotion Flamingo 2 lacks BLE encryption, enabling data sniffing and packet forgery.
1Qualcomm
22Aqt1000 Firmware
Qca6164 FirmwareQca6174 Firmware+19 more
Jun 17, 2026
Jul 13, 2021
N/A· v4
4.3 MEDIUM· v3
3.3 LOW· v2
Weak configuration in WLAN could cause forwarding of unencrypted packets from one client to another in Snapdragon Compute, Snapdragon Connectivity
1Devolutions
1Devolutions Server
Jun 17, 2026
Jul 12, 2021
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
Devolutions Server before 2021.1.18, and LTS before 2020.3.20, allows attackers to intercept private keys via a man-in-the-middle attack against the connections/partial endpoint (which accepts cleartext).
1Huawei
1Emui
Jun 17, 2026
Jun 30, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
There is a Cleartext Transmission of Sensitive Information Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may affect service confidentiality and availability.
1Bosch
1B426 Firmware
Jun 17, 2026
Jun 18, 2021
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
When using http protocol, the user password is transmitted as a clear text parameter for which it is possible to be obtained by an attacker through a MITM attack. This will be fixed starting from Firmware version 3.11.5,...Show more
When using http protocol, the user password is transmitted as a clear text parameter for which it is possible to be obtained by an attacker through a MITM attack. This will be fixed starting from Firmware version 3.11.5, which will be released on the 30th of June, 2021.Show less
2Fedoraproject
Quassel Irc
2Fedora
Quassel
Jun 17, 2026
Jun 17, 2021
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
Quassel through 0.13.1, when --require-ssl is enabled, launches without SSL or TLS support if a usable X.509 certificate is not found on the local system.
1I Doo
1Veryfitpro
Jun 17, 2026
Jun 16, 2021
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
The VeryFitPro (com.veryfit2hr.second) application 3.2.8 for Android does all communication with the backend API over cleartext HTTP. This includes logins, registrations, and password change requests. This allows informa...Show more
The VeryFitPro (com.veryfit2hr.second) application 3.2.8 for Android does all communication with the backend API over cleartext HTTP. This includes logins, registrations, and password change requests. This allows information theft and account takeover via network sniffing.Show less
1Huawei
2Emui
Magic Ui
Jun 17, 2026
Jun 3, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
There is an Information Disclosure vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may result in video streams being intercepted during transmission.
1Mcafee
1Database Security
Jun 17, 2026
Jun 2, 2021
N/A· v4
4.5 MEDIUM· v3
2.7 LOW· v2
Cleartext Transmission of Sensitive Information vulnerability in the administrator interface of McAfee Database Security (DBSec) prior to 4.8.2 allows an administrator to view the unencrypted password of the McAfee Insig...Show more
Cleartext Transmission of Sensitive Information vulnerability in the administrator interface of McAfee Database Security (DBSec) prior to 4.8.2 allows an administrator to view the unencrypted password of the McAfee Insights Server used to pass data to the Insights Server. This user is restricted to only have access to DBSec data in the Insights Server.Show less
1F5
1Nginx Controller
Jun 17, 2026
Jun 1, 2021
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
Intra-cluster communication does not use TLS. The services within the NGINX Controller 3.x before 3.4.0 namespace are using cleartext protocols inside the cluster.
1Abinitio
1Control>center
Jun 17, 2026
May 27, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Local File Inclusion vulnerability in Ab Initio Control>Center before 4.0.2.6 allows remote attackers to retrieve arbitrary files. Fixed in v4.0.2.6 and v4.0.3.1.
1Couchbase
1Couchbase Server
Jun 17, 2026
May 26, 2021
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in Couchbase Server 5.x and 6.x before 6.5.2 and 6.6.x before 6.6.2. Internal users with administrator privileges, @cbq-engine-cbauth and @index-cbauth, leak credentials in cleartext in the indexe...Show more
An issue was discovered in Couchbase Server 5.x and 6.x before 6.5.2 and 6.6.x before 6.6.2. Internal users with administrator privileges, @cbq-engine-cbauth and @index-cbauth, leak credentials in cleartext in the indexer.log file when they make a /listCreateTokens, /listRebalanceTokens, or /listMetadataTokens call.Show less
1Couchbase
1Couchbase Server
Jun 17, 2026
May 19, 2021
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Couchbase Server 6.x through 6.6.1. The Couchbase Server UI is insecurely logging session cookies in the logs. This allows for the impersonation of a user if the log files are obtained by an at...Show more
An issue was discovered in Couchbase Server 6.x through 6.6.1. The Couchbase Server UI is insecurely logging session cookies in the logs. This allows for the impersonation of a user if the log files are obtained by an attacker before a session cookie expires.Show less
1Sitel Sa
1Remote Cap/prx Firmware
Jun 17, 2026
May 17, 2021
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
SITEL CAP/PRX firmware version 5.2.01 allows an attacker with access to the local network of the device to obtain the authentication passwords by analysing the network traffic.
1Ibm
1Cloud Pak For Security
Jun 17, 2026
May 14, 2021
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
IBM Cloud Pak for Security (CP4S) 1.4.0.0, 1.5.0.0, 1.5.0.1, 1.6.0.0, and 1.6.0.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An...Show more
IBM Cloud Pak for Security (CP4S) 1.4.0.0, 1.5.0.0, 1.5.0.1, 1.6.0.0, and 1.6.0.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 199235.Show less
1Moxa
3Nport Ia5150a Firmware
Nport Ia5250a FirmwareNport Ia5450a Firmware
Jun 17, 2026
May 14, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Cleartext transmission of sensitive information via Moxa Service in NPort IA5000A series serial devices. Successfully exploiting the vulnerability could enable attackers to read authentication data, device configuration,...Show more
Cleartext transmission of sensitive information via Moxa Service in NPort IA5000A series serial devices. Successfully exploiting the vulnerability could enable attackers to read authentication data, device configuration, and other sensitive data transmitted over Moxa Service.Show less
1Moxa
3Nport Ia5150a Firmware
Nport Ia5250a FirmwareNport Ia5450a Firmware
Jun 17, 2026
May 14, 2021
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The NPort IA5000A Series devices use Telnet as one of the network device management services. Telnet does not support the encryption of client-server communications, making it vulnerable to Man-in-the-Middle attacks.
1Jetbrains
1Webstorm
Jun 17, 2026
May 11, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In JetBrains WebStorm before 2021.1, HTTP requests were used instead of HTTPS.
1Agenziaentrate
1Desktop Telematico
Jun 17, 2026
May 10, 2021
N/A· v4
5.3 MEDIUM· v3
4.3 MEDIUM· v2
Agenzia delle Entrate Desktop Telematico 1.0.0 contacts the jws.agenziaentrate.it server over cleartext HTTP, which allows man-in-the-middle attackers to spoof product updates.