← Back
CWE-319

923 CVEs • Abstraction: Base • Likelihood of Exploit: High

Cleartext Transmission of Sensitive Information

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

JSON object

Loading...

CVEs (923)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Nordicsemi
2Android Ble Library
Dfu Library
Jun 17, 2026
Jul 7, 2020
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
Nordic Semiconductor Android BLE Library through 2.2.1 and DFU Library through 1.10.4 for Android (as used by nRF Connect and other applications) can engage in unencrypted communication while showing the user that the co...Show more
Nordic Semiconductor Android BLE Library through 2.2.1 and DFU Library through 1.10.4 for Android (as used by nRF Connect and other applications) can engage in unencrypted communication while showing the user that the communication is purportedly encrypted. The problem is in bond creation (e.g., internalCreateBond in BleManagerHandler).Show less
1Dronecode
1Micro Air Vehicle Link
Jun 17, 2026
Jul 3, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
This vulnerability applies to the Micro Air Vehicle Link (MAVLink) protocol and allows a remote attacker to gain access to sensitive information provided it has access to the communication medium. MAVLink is a header-bas...Show more
This vulnerability applies to the Micro Air Vehicle Link (MAVLink) protocol and allows a remote attacker to gain access to sensitive information provided it has access to the communication medium. MAVLink is a header-based protocol that does not perform encryption to improve transfer (and reception speed) and efficiency by design. The increasing popularity of the protocol (used accross different autopilots) has led to its use in wired and wireless mediums through insecure communication channels exposing sensitive information to a remote attacker with ability to intercept network traffic.Show less
1Jenkins
1Stash Branch Parameter
Jun 17, 2026
Jul 2, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Jenkins Stash Branch Parameter Plugin 0.3.0 and earlier transmits configured passwords in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.
1F5
1Nginx Controller
Jun 17, 2026
Jul 1, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
In NGINX Controller 3.0.0-3.4.0, recovery code required to change a user's password is transmitted and stored in the database in plain text, which allows an attacker who can intercept the database connection or have read...Show more
In NGINX Controller 3.0.0-3.4.0, recovery code required to change a user's password is transmitted and stored in the database in plain text, which allows an attacker who can intercept the database connection or have read access to the database, to request a password reset using the email address of another registered user then retrieve the recovery code.Show less
1Baxter
1Phoenix X36 Firmware
Jun 17, 2026
Jun 29, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Phoenix Hemodialysis Delivery System SW 3.36 and 3.40, The Phoenix Hemodialysis device does not support data-in-transit encryption (e.g., TLS/SSL) when transmitting treatment and prescription data on the network between...Show more
Phoenix Hemodialysis Delivery System SW 3.36 and 3.40, The Phoenix Hemodialysis device does not support data-in-transit encryption (e.g., TLS/SSL) when transmitting treatment and prescription data on the network between the Phoenix system and the Exalis dialysis data management tool. An attacker with access to the network could observe sensitive treatment and prescription data sent between the Phoenix system and the Exalis tool.Show less
1Baxter
1Sigma Spectrum Infusion System Firmware
Jun 17, 2026
Jun 29, 2020
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Sigma Spectrum Infusion System v's6.x (model 35700BAX) and Baxter Spectrum Infusion System Version(s) 8.x (model 35700BAX2) at the application layer uses an unauthenticated clear-text communication channel to send and re...Show more
Sigma Spectrum Infusion System v's6.x (model 35700BAX) and Baxter Spectrum Infusion System Version(s) 8.x (model 35700BAX2) at the application layer uses an unauthenticated clear-text communication channel to send and receive system status and operational data. This could allow an attacker that has circumvented network security measures to view sensitive non-private data or to perform a man-in-the-middle attack.Show less
1Baxter
2Prismaflex Firmware
Prismax Firmware
Jun 17, 2026
Jun 29, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Baxter PrismaFlex all versions, PrisMax all versions prior to 3.x, The affected devices do not implement data-in-transit encryption (e.g., TLS/SSL) when configured to send treatment data to a PDMS (Patient Data Managemen...Show more
Baxter PrismaFlex all versions, PrisMax all versions prior to 3.x, The affected devices do not implement data-in-transit encryption (e.g., TLS/SSL) when configured to send treatment data to a PDMS (Patient Data Management System) or an EMR (Electronic Medical Record) system. An attacker could observe sensitive data sent from the device.Show less
1Baxter
2Prismaflex Firmware
Prismax Firmware
Jun 17, 2026
Jun 29, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Baxter PrismaFlex all versions, PrisMax all versions prior to 3.x, The affected devices do not implement data-in-transit encryption (e.g., TLS/SSL) when configured to send treatment data to a PDMS (Patient Data Managemen...Show more
Baxter PrismaFlex all versions, PrisMax all versions prior to 3.x, The affected devices do not implement data-in-transit encryption (e.g., TLS/SSL) when configured to send treatment data to a PDMS (Patient Data Management System) or an EMR (Electronic Medical Record) system. An attacker could observe sensitive data sent from the device.Show less
1Baxter
2Em1200 Firmware
Em2400 Firmware
Jun 17, 2026
Jun 29, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Baxter ExactaMix EM 2400 Versions 1.10, 1.11 and ExactaMix EM1200 Versions 1.1, 1.2 systems use cleartext messages to communicate order information with an order entry system. This could allow an attacker with network ac...Show more
Baxter ExactaMix EM 2400 Versions 1.10, 1.11 and ExactaMix EM1200 Versions 1.1, 1.2 systems use cleartext messages to communicate order information with an order entry system. This could allow an attacker with network access to view sensitive data including PHI.Show less
1Biotronik
2Cardiomessenger Ii S Gsm Firmware
Cardiomessenger Ii S T Line Firmware
Jun 17, 2026
Jun 29, 2020
N/A· v4
4.3 MEDIUM· v3
3.3 LOW· v2
BIOTRONIK CardioMessenger II, The affected products transmit credentials in clear-text prior to switching to an encrypted communication channel. An attacker can disclose the product’s client credentials for connecting to...Show more
BIOTRONIK CardioMessenger II, The affected products transmit credentials in clear-text prior to switching to an encrypted communication channel. An attacker can disclose the product’s client credentials for connecting to the BIOTRONIK Remote Communication infrastructure.Show less
1Honeywell
2Controledge Plc Firmware
Controledge Rtu Firmware
Jun 17, 2026
Jun 26, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
ControlEdge PLC (R130.2, R140, R150, and R151) and RTU (R101, R110, R140, R150, and R151) exposes unencrypted passwords on the network.
1Honeywell
2Controledge Plc Firmware
Controledge Rtu Firmware
Jun 17, 2026
Jun 26, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
ControlEdge PLC (R130.2, R140, R150, and R151) and RTU (R101, R110, R140, R150, and R151) exposes a session token on the network.
1Mitsubishielectric
5Melsec Fx Firmware
Melsec L FirmwareMelsec Q Firmware+2 more
Jun 17, 2026
Jun 23, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Mitsubishi Electric MELSEC iQ-R, iQ-F, Q, L, and FX series CPU modules all versions contain a vulnerability that allows cleartext transmission of sensitive information between CPU modules and GX Works3 and/or GX Works2 v...Show more
Mitsubishi Electric MELSEC iQ-R, iQ-F, Q, L, and FX series CPU modules all versions contain a vulnerability that allows cleartext transmission of sensitive information between CPU modules and GX Works3 and/or GX Works2 via unspecified vectors.Show less
1Bt Ctroms Terminal Project
1Bt Ctroms Terminal
Jun 17, 2026
Jun 19, 2020
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
An issue was discovered in BT CTROMS Terminal OS Port Portal CT-464. Account takeover can occur because the password-reset feature discloses the verification token. Upon a getverificationcode.jsp request, this token is t...Show more
An issue was discovered in BT CTROMS Terminal OS Port Portal CT-464. Account takeover can occur because the password-reset feature discloses the verification token. Upon a getverificationcode.jsp request, this token is transmitted not only to the registered phone number of the user account, but is also transmitted to the unauthenticated HTTP client.Show less
1Abus
1Secvest Wireless Control Fube50001 Firmware
Jun 17, 2026
Jun 17, 2020
N/A· v4
8.1 HIGH· v3
4.8 MEDIUM· v2
The wireless-communication feature of the ABUS Secvest FUBE50001 device does not encrypt sensitive data such as PIN codes or IDs of used proximity chip keys (RFID tokens). This makes it easier for an attacker to disarm t...Show more
The wireless-communication feature of the ABUS Secvest FUBE50001 device does not encrypt sensitive data such as PIN codes or IDs of used proximity chip keys (RFID tokens). This makes it easier for an attacker to disarm the wireless alarm system.Show less
4Canonical
DebianMutt+1 more
4Debian Linux
LeapMutt+1 more
Jun 17, 2026
Jun 15, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Mutt before 1.14.3 allows an IMAP fcc/postpone man-in-the-middle attack via a PREAUTH response.
1Mids' Reborn Hero Designer Project
1Mids' Reborn Hero Designer
Jun 17, 2026
Jun 11, 2020
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Mids' Reborn Hero Designer 2.6.0.7 downloads the update manifest, as well as update files, over cleartext HTTP. Additionally, the application does not perform file integrity validation for files after download. An attack...Show more
Mids' Reborn Hero Designer 2.6.0.7 downloads the update manifest, as well as update files, over cleartext HTTP. Additionally, the application does not perform file integrity validation for files after download. An attacker can perform a man-in-the-middle attack against this connection and replace executable files with malicious versions, which the operating system then executes under the context of the user running Hero Designer.Show less
1Microsoft
1Visual Studio Live Share
Jun 17, 2026
Jun 9, 2020
N/A· v4
5.9 MEDIUM· v3
5.0 MEDIUM· v2
An information disclosure vulnerability exists in Visual Studio Code Live Share Extension when it exposes tokens in plain text, aka 'Visual Studio Code Live Share Information Disclosure Vulnerability'.
1Dlink
1Dir 865l Firmware
Jun 17, 2026
Jun 3, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
D-Link DIR-865L Ax 1.20B01 Beta devices have Cleartext Transmission of Sensitive Information.
1Paloaltonetworks
1Pan Os
Jun 17, 2026
May 13, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A cleartext transmission of sensitive information vulnerability in Palo Alto Networks PAN-OS Panorama that discloses an authenticated PAN-OS administrator's PAN-OS session cookie. When an administrator issues a context s...Show more
A cleartext transmission of sensitive information vulnerability in Palo Alto Networks PAN-OS Panorama that discloses an authenticated PAN-OS administrator's PAN-OS session cookie. When an administrator issues a context switch request into a managed firewall with an affected PAN-OS Panorama version, their PAN-OS session cookie is transmitted over cleartext to the firewall. An attacker with the ability to intercept this network traffic between the firewall and Panorama can access the administrator's account and further manipulate devices managed by Panorama. This issue affects: PAN-OS 7.1 versions earlier than 7.1.26; PAN-OS 8.1 versions earlier than 8.1.13; PAN-OS 9.0 versions earlier than 9.0.6; PAN-OS 9.1 versions earlier than 9.1.1; All version of PAN-OS 8.0;Show less