CWE-319
880 CVEs • Abstraction: Base • Likelihood of Exploit: High
Cleartext Transmission of Sensitive Information
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
CVEs (880)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1F5 11Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+8 moreNov 21, 2024 Apr 30, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 On versions 15.0.0-15.1.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, and 12.1.0-12.1.5.1, BIG-IP systems setup for connection mirroring in a High Availability (HA) pair transfers sensitive cryptographic objects over an insecur...Show more |
1F5 11Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+8 moreNov 21, 2024 Apr 30, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 On versions 15.0.0-15.1.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, and 12.1.0-12.1.5.1, BIG-IP systems set up for connection mirroring in a high availability (HA) pair transfer sensitive cryptographic objects over an insecur...Show more |
1F5 1Big Ip Application Security Manager Nov 21, 2024 Apr 30, 2020 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 On BIG-IP ASM 11.6.1-11.6.5.1, under certain configurations, the BIG-IP system sends data plane traffic to back-end servers unencrypted, even when a Server SSL profile is applied. |
1F5 11Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+8 moreNov 21, 2024 Apr 30, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 On BIG-IP 15.0.0-15.0.1.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, a race condition exists where mcpd and other processes may make unencrypted connection attempts to a new configuration sy...Show more |
2F5 Netapp2Cloud Backup Nginx ControllerNov 21, 2024 Apr 23, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 In versions prior to 3.3.0, the NGINX Controller Agent installer script 'install.sh' uses HTTP instead of HTTPS to check and install packages |
2F5 Netapp2Cloud Backup Nginx ControllerNov 21, 2024 Apr 23, 2020 N/A· v4 4.8 MEDIUM· v3 5.8 MEDIUM· v2 In versions prior to 3.3.0, the NGINX Controller is configured to communicate with its Postgres database server over unencrypted channels, making the communicated data vulnerable to interception via man-in-the-middle (Mi...Show more |
1Schneider Electric 7Ecostruxure Machine Expert Modicon M218 FirmwareModicon M241 Firmware+4 moreMay 28, 2026 Apr 22, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists which could leak sensitive information transmitted between the software and the Modicon M218, M241, M251, and M258 controllers. |
2Abb Busch Jaeger26186/11 Firmware Tg/s3.2 FirmwareNov 21, 2024 Apr 22, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The Configuration pages in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway for user profiles and services transfer the password in plaintext (although hidden when displayed). |
In JetBrains GoLand before 2019.3.2, the plugin repository was accessed via HTTP instead of HTTPS. |
1Titan 1Sf Rush Smart Band Firmware Nov 21, 2024 Apr 22, 2020 N/A· v4 8.1 HIGH· v3 4.8 MEDIUM· v2 An issue was discovered on Tata Sonata Smart SF Rush 1.12 devices. It has been identified that the smart band has no pairing (mode 0 Bluetooth LE security level) The data being transmitted over the air is not encrypted....Show more |
1Schneider Electric 1Tristation 1131 Nov 21, 2024 Apr 16, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 **VERSION NOT SUPPORTED WHEN ASSIGNED** A vulnerability could cause certain data to be visible on the network when the 'password' feature is enabled. This vulnerability was discovered in and remediated in versions v4.9.1...Show more |
1Ibm 1Qradar Security Information And Event Manager Nov 21, 2024 Apr 15, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to ob...Show more |
1Sap 1Businessobjects Business Intelligence Platform Nov 21, 2024 Apr 14, 2020 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 SAP Business Objects Business Intelligence Platform (CMC), version 4.1, 4.2, shows cleartext password in the response, leading to Information Disclosure. It involves social engineering in order to gain access to system a...Show more |
An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. It includes the username and password values in cleartext within each request's cookie value. |
13xlogic 2Infinias Eidc32 Firmware Infinias Eidc32 WebNov 21, 2024 Apr 4, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 3xLOGIC Infinias eIDC32 2.213 devices with Web 1.107 allow Authentication Bypass via CMD.HTM?CMD= because authentication depends on the client side's interpretation of the <KEY>MYKEY</KEY> substring. |
1F5 12Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+9 moreNov 21, 2024 Mar 27, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 On BIG-IP 15.0.0-15.1.0.2, 14.1.0-14.1.2.3, 13.1.0-13.1.3.2, 12.1.0-12.1.5.1, and 11.5.2-11.6.5.1 and BIG-IQ 7.0.0, 6.0.0-6.1.0, and 5.2.0-5.4.0, in a High Availability (HA) network failover in Device Service Cluster (DS...Show more |
An authentication bypass vulnerability is present in the standalone SITS:Vision 9.7.0 component of Tribal SITS in its default configuration, related to unencrypted communications sent by the client each time it is launch...Show more |
1Moxa 2Eds 510e Firmware Eds G516e FirmwareNov 21, 2024 Mar 24, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Moxa EDS-G516E Series firmware, Version 5.2 or lower, sensitive information is transmitted over some web applications in cleartext. |
1Moxa 20Iologik 2512 Hspa T Firmware Iologik 2512 Hspa FirmwareIologik 2512 T Firmware+17 moreNov 21, 2024 Mar 24, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Moxa ioLogik 2500 series firmware, Version 3.0 or lower, and IOxpress configuration utility, Version 2.3.0 or lower, sensitive information is transmitted over some web applications in clear text. |
1Netsas 1Enigma Network Management Solution Nov 21, 2024 Mar 19, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 NETSAS Enigma NMS 65.0.0 and prior does not encrypt sensitive data rendered within web pages. It is possible for an attacker to expose unencrypted sensitive data. |