CWE-319
923 CVEs • Abstraction: Base • Likelihood of Exploit: High
Cleartext Transmission of Sensitive Information
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
CVEs (923)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Rubetek 3Rv 3406 Firmware Rv 3409 FirmwareRv 3411 FirmwareJun 17, 2026 Sep 25, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 A Cleartext Transmission issue was discovered on Rubetek RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339). Someone in the middle can intercept and modify the video data from the camera, which is trans...Show more |
1Siemens 1Siveillance Video Client Jun 17, 2026 Sep 9, 2020 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability has been identified in Siveillance Video Client (All versions). In environments where Windows NTLM authentication is enabled the affected client application transmits usernames to the server in cleartext....Show more |
2Linux Redhat3Enterprise Linux Enterprise MrgLinux KernelJun 17, 2026 Sep 9, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in the Linux kernel's implementation of some networking protocols in IPsec, such as VXLAN and GENEVE tunnels over IPv6. When an encrypted tunnel is created between two hosts, the kernel isn't correctly r...Show more |
3Arista DebianQualcomm13Access Point Apq8053 FirmwareDebian Linux+10 moreJun 17, 2026 Sep 8, 2020 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 u'Specifically timed and handcrafted traffic can cause internal errors in a WLAN device that lead to improper layer 2 Wi-Fi encryption with a consequent possibility of information disclosure over the air for a discrete s...Show more |
1Jenkins 2Jenkins Soapui Pro Functional TestingJun 17, 2026 Sep 1, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Jenkins SoapUI Pro Functional Testing Plugin 1.5 and earlier transmits project passwords in its configuration in plain text as part of job configuration forms, potentially resulting in their exposure. |
1Ibm 2Guardium Data Encryption Guardium For Cloud Key ManagementJun 17, 2026 Aug 26, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IBM Security Guardium Data Encryption (GDE) 3.0.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this v...Show more |
1Niscomed 1M1000 Multipara Patient Monitor Firmware Jun 17, 2026 Aug 26, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An issue was discovered on Nescomed Multipara Monitor M1000 devices. The device enables an unencrypted TELNET service by default, with a blank password for the admin account. This allows an attacker to gain root access t...Show more |
NCR SelfServ ATMs running APTRA XFS 05.01.00 do not encrypt, authenticate, or verify the integrity of messages between the BNA and the host computer, which could allow an attacker with physical access to the internal com...Show more |
Jenkins Email Extension Plugin 2.72 and 2.73 transmits and displays the SMTP password in plain text as part of the global Jenkins configuration form, potentially resulting in its exposure. |
CS2 Network P2P through 3.x, as used in millions of Internet of Things devices, suffers from an information exposure flaw that exposes user session data to supernodes in the network, as demonstrated by passively eavesdro...Show more |
DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to elevate privileges because the administrative password can be discovered by sniffing unencrypted UDP traffic. |
1Lindy International 142633 Firmware Jun 17, 2026 Aug 7, 2020 N/A· v4 8.8 HIGH· v3 3.3 LOW· v2 Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to elevate privileges because the administrative password can be discovered by sniffing unencrypted UDP traffic. |
TP-Link USB Network Server TL-PS310U devices before 2.079.000.t0210 allow an attacker on the same network to elevate privileges because the administrative password can be discovered by sniffing unencrypted UDP traffic. |
2Debian Kde2Debian Linux KmailJun 17, 2026 Jul 27, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 KDE KMail 19.12.3 (aka 5.13.3) engages in unencrypted POP3 communication during times when the UI indicates that encryption is in use. |
1Espressif 3Esp Idf Esp8266 Nonos SdkEsp8266 Rtos SdkJun 17, 2026 Jul 23, 2020 N/A· v4 6.8 MEDIUM· v3 4.3 MEDIUM· v2 An encryption-bypass issue was discovered on Espressif ESP-IDF devices through 4.2, ESP8266_NONOS_SDK devices through 3.0.3, and ESP8266_RTOS_SDK devices through 3.3. Broadcasting forged beacon frames forces a device to...Show more |
IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 transmits sensitive information in plain text which could be obtained by an attacker using man in the middle techniques. IBM X-Force ID: 179428. |
The DuoConnect client enables users to establish SSH connections to hosts protected by a DNG instance. When a user initiates an SSH connection to a DNG-protected host for the first time using DuoConnect, the user’s brows...Show more |
1Siemens 6Simatic Hmi Basic Panels 1st Generation Simatic Hmi Basic Panels 2nd GenerationSimatic Hmi Comfort Panels Firmware+3 moreJun 17, 2026 Jul 14, 2020 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 A vulnerability has been identified in SIMATIC HMI Basic Panels 1st Generation (incl. SIPLUS variants) (All versions), SIMATIC HMI Basic Panels 2nd Generation (incl. SIPLUS variants) (All versions), SIMATIC HMI Comfort P...Show more |
Atlassian Bitbucket Server from version 4.9.0 before version 7.2.4 allows remote attackers to intercept unencrypted repository import requests via a Man-in-the-Middle (MITM) attack. |
2Canonical Mozilla2Thunderbird Ubuntu LinuxJun 17, 2026 Jul 9, 2020 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 If Thunderbird is configured to use STARTTLS for an IMAP server, and the server sends a PREAUTH response, then Thunderbird will continue with an unencrypted connection, causing email data to be sent without protection. T...Show more |