← Back
CWE-319

923 CVEs • Abstraction: Base • Likelihood of Exploit: High

Cleartext Transmission of Sensitive Information

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

JSON object

Loading...

CVEs (923)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jenkins
1Sctmexecutor
Jun 17, 2026
Dec 17, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Jenkins SCTMExecutor Plugin 2.2 and earlier transmits previously configured service credentials in plain text as part of the global configuration, as well as individual jobs' configurations.
2Petwant
Skymee
2Petalk Ai Firmware
Pf 103 Firmware
Jun 17, 2026
Dec 13, 2019
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
Unencrypted HTTP communications for firmware upgrades in Petalk AI and PF-103 allow man-in-the-middle attackers to run arbitrary code as the root user.
1Siemens
1Sppa T3000 Application Server
Jun 17, 2026
Dec 12, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The RMI communication between the client and the Application Server is unencrypted. An attacker with access to...Show more
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The RMI communication between the client and the Application Server is unencrypted. An attacker with access to the communication channel can read credentials of a valid user. Please note that an attacker needs to have access to the Application Highway in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.Show less
1Last.fm
1Last.fm Desktop
Jun 17, 2026
Dec 10, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The Last.fm desktop app (Last.fm Scrobbler) through 2.1.39 on macOS makes HTTP requests that include an API key without the use of SSL/TLS. Although there is an Enable SSL option, it is disabled by default, and cleartext...Show more
The Last.fm desktop app (Last.fm Scrobbler) through 2.1.39 on macOS makes HTTP requests that include an API key without the use of SSL/TLS. Although there is an Enable SSL option, it is disabled by default, and cleartext requests are made as soon as the app starts.Show less
1Weidmueller
40Ie Sw Pl08m 6tx 2sc Firmware
Ie Sw Pl08m 6tx 2scs FirmwareIe Sw Pl08m 6tx 2st Firmware+37 more
Jun 17, 2026
Dec 6, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. Sensitive Credentials data is transmitted in cleartext.
3Aquamaniac
DebianOpensuse
3Debian Linux
GwenhywfarLeap
Nov 21, 2024
Dec 3, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability exists in libgwenhywfar through 4.12.0 due to the usage of outdated bundled CA certificates.
1Hashicorp
1Terraform
Jun 17, 2026
Dec 2, 2019
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
When using the Azure backend with a shared access signature (SAS), Terraform versions prior to 0.12.17 may transmit the token and state snapshot using cleartext HTTP.
1Redhat
1Satellite
Apr 9, 2026
Dec 2, 2019
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
A flaw was found in rhn-proxy. This vulnerability may allow the rhn-proxy to transmit user credentials in clear-text when it accesses RHN Satellite. This could lead to information disclosure, where sensitive authenticati...Show more
A flaw was found in rhn-proxy. This vulnerability may allow the rhn-proxy to transmit user credentials in clear-text when it accesses RHN Satellite. This could lead to information disclosure, where sensitive authentication details are exposed to unauthorized parties.Show less
1Inateck
1Bcst 60 Firmware
Jun 17, 2026
Dec 2, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Due to unencrypted and unauthenticated data communication, the wireless barcode scanner Inateck BCST-60 is prone to keystroke injection attacks. Thus, an attacker is able to send arbitrary keystrokes to a victim's comput...Show more
Due to unencrypted and unauthenticated data communication, the wireless barcode scanner Inateck BCST-60 is prone to keystroke injection attacks. Thus, an attacker is able to send arbitrary keystrokes to a victim's computer system, e.g., to install malware when the target system is unattended. In this way, an attacker can remotely take control over the victim's computer that is operated with an affected receiver of this device.Show less
1Anviz
1Anviz Firmware
Jun 17, 2026
Dec 2, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Anviz access control devices perform cleartext transmission of sensitive information (passwords/pins and names) when replying to query on port tcp/5010.
1Huami
1Mi Fit
Jun 17, 2026
Nov 30, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The Anhui Huami Mi Fit application before 4.0.11 for Android has an Unencrypted Update Check.
1Qmetry
1Jenkins Qmetry For Jira
Jun 17, 2026
Nov 21, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins QMetry for JIRA - Test Management Plugin transmits credentials in its configuration in plain text as part of job configuration forms, potentially resulting in their exposure.
1Pidgin
1Pidgin
Nov 21, 2024
Nov 20, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Pidgin 2.10.0 uses DBUS for certain cleartext communication, which allows local users to obtain sensitive information via a dbus session monitor.
1Mcafee
1Data Loss Prevention
Jun 17, 2026
Nov 14, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Unprotected Transport of Credentials in ePO extension in McAfee Data Loss Prevention 11.x prior to 11.4.0 allows remote attackers with access to the network to collect login details to the LDAP server via the ePO extensi...Show more
Unprotected Transport of Credentials in ePO extension in McAfee Data Loss Prevention 11.x prior to 11.4.0 allows remote attackers with access to the network to collect login details to the LDAP server via the ePO extension not using a secure connection when testing LDAP connectivity.Show less
2Fedoraproject
Oracle
2Fedora
Mysql Gui Tools
Nov 21, 2024
Nov 12, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
mysql-gui-tools (mysql-query-browser and mysql-admin) before 5.0r14+openSUSE-2.3 exposes the password of a user connected to the MySQL server in clear text form via the list of running processes.
1Dlink
7Dir 600 B1 Firmware
Dir 615 J1 FirmwareDir 645 A1 Firmware+4 more
Jun 17, 2026
Nov 11, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Certain D-Link devices have a hardcoded Alphanetworks user account with TELNET access because of /etc/config/image_sign or /etc/alpha_config/image_sign. This affects DIR-600 B1 V2.01 for WW, DIR-890L A1 v1.03, DIR-615 J1...Show more
Certain D-Link devices have a hardcoded Alphanetworks user account with TELNET access because of /etc/config/image_sign or /etc/alpha_config/image_sign. This affects DIR-600 B1 V2.01 for WW, DIR-890L A1 v1.03, DIR-615 J1 v100 (for DCN), DIR-645 A1 v1.03, DIR-815 A1 v1.01, DIR-823 A1 v1.01, and DIR-842 C1 v3.00.Show less
1Rakuten
1Viber
Jun 17, 2026
Nov 6, 2019
N/A· v4
8.8 HIGH· v3
4.3 MEDIUM· v2
Viber through 11.7.0.5 allows a remote attacker who can capture a victim's internet traffic to steal their Viber account, because not all Viber protocol traffic is encrypted. TCP data packet 9 on port 4244 from the victi...Show more
Viber through 11.7.0.5 allows a remote attacker who can capture a victim's internet traffic to steal their Viber account, because not all Viber protocol traffic is encrypted. TCP data packet 9 on port 4244 from the victim's device contains cleartext information such as the device model and OS version, IMSI, and 20 bytes of udid in a binary format, which is located at offset 0x14 of this packet. Then, the attacker installs Viber on his device, initiates the registration process for any phone number, but doesn't enter a pin from SMS. Instead, he closes Viber. Next, the attacker rewrites his udid with the victim's udid, modifying the viber_udid file, which is located in the Viber preferences folder. (The udid is stored in a hexadecimal format.) Finally, the attacker starts Viber again and enters the pin from SMS.Show less
1Schneider Electric
4Modicon 140cra Firmware
Modicon Bmxcra FirmwareModicon M340 Firmware+1 more
Jun 17, 2026
Oct 29, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists in Modicon M580, Modicon M340, Modicon BMxCRA and 140CRA modules (all firmware versions), which could cause information disclosure when usin...Show more
A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists in Modicon M580, Modicon M340, Modicon BMxCRA and 140CRA modules (all firmware versions), which could cause information disclosure when using the FTP protocol.Show less
1Schneider Electric
23Modicon M340 Firmware
Modicon M580 FirmwareTsxmcpc002m Firmware+20 more
Jun 17, 2026
Oct 29, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists in Modicon M580, Modicon M340, Modicon Premium , Modicon Quantum (all firmware versions), which could cause the disclosure of information wh...Show more
A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists in Modicon M580, Modicon M340, Modicon Premium , Modicon Quantum (all firmware versions), which could cause the disclosure of information when transferring applications to the controller using Modbus TCP protocol.Show less
1Fujitsu
1Lx390 Firmware
Jun 17, 2026
Oct 24, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered on Fujitsu Wireless Keyboard Set LX390 GK381 devices. Because of the lack of proper encryption of 2.4 GHz communication, an attacker is able to eavesdrop on sensitive data such as passwords.