CWE-319
878 CVEs • Abstraction: Base • Likelihood of Exploit: High
Cleartext Transmission of Sensitive Information
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
CVEs (878)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Druide Antidote through 9.5.1 on Windows and Linux allows remote code execution through the update mechanism by leveraging use of HTTP to download installation packages. |
2Qbeecam Swisscom3Qbee Multi Sensor Camera Firmware QbeecamSwisscom Home AppNov 21, 2024 Sep 18, 2018 N/A· v4 6.5 MEDIUM· v3 6.1 MEDIUM· v2 The QBee MultiSensor Camera through 4.16.4 accepts unencrypted network traffic from clients (such as the QBee Cam application through 1.0.5 for Android and the Swisscom Home application up to 10.7.2 for Android), which r...Show more |
The IIOP OpenJDK Subsystem in WildFly before version 14.0.0 does not honour configuration when SSL transport is required. Servers before this version that are configured with the following setting allow clients to create...Show more |
An issue was discovered on D-Link DIR-601 2.02NA devices. Being local to the network and having only "User" account (which is a low privilege account) access, an attacker can intercept the response from a POST request to...Show more |
1Puppet 1Puppet Enterprise Nov 21, 2024 Aug 24, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 When users are configured to use startTLS with RBAC LDAP, at login time, the user's credentials are sent via plaintext to the LDAP server. This affects Puppet Enterprise 2018.1.3, 2017.3.9, and 2016.4.14, and is fixed in...Show more |
1Medtronic 9Minimed 530g Mmt 551 Firmware Minimed 530g Mmt 751 FirmwareMinimed Paradigm 508 Insulin Pump Firmware+6 moreMay 22, 2025 Aug 13, 2018 N/A· v4 5.3 MEDIUM· v3 2.9 LOW· v2 Communications between Medtronic MiniMed MMT pumps and wireless accessories are transmitted in cleartext. A sufficiently skilled attacker could capture these transmissions and extract sensitive information, such as devic...Show more |
Dell EMC NetWorker versions between 9.0 and 9.1.1.8 through 9.2.1.3, and the version 18.1.0.1 contain a Clear-Text authentication over network vulnerability in the Rabbit MQ Advanced Message Queuing Protocol (AMQP) compo...Show more |
Intuit Lacerte 2017 for Windows in a client/server environment transfers the entire customer list in cleartext over SMB, which allows attackers to (1) obtain sensitive information by sniffing the network or (2) conduct m...Show more |
1Echelon 4I.lon 100 Firmware I.lon 600 FirmwareSmartserver 1 Firmware+1 moreJun 2, 2026 Jul 24, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. The devices allow unencrypted Web connections by default, and devices can rece...Show more |
1Netgear 2Dgn2200 Firmware Dgnd3700 FirmwareNov 21, 2024 Jul 24, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 A vulnerability is in the 'BSW_cxttongr.htm' page of the Netgear DGN2200, version DGN2200-V1.0.0.50_7.0.50, and DGND3700, version DGND3700-V1.0.0.17_1.0.17, which can allow a remote attacker to access this page without a...Show more |
There are few web pages associated with the genie app on the Netgear WNDR4500 running firmware version V1.0.1.40_1.0.6877. Genie app adds some capabilities over the Web GUI and can be accessed even when you are away from...Show more |
When an SRX Series device is configured to use HTTP/HTTPS pass-through authentication services, a client sending authentication credentials in the initial HTTP/HTTPS session is at risk that these credentials may be captu...Show more |
Improper restriction of communication channel to intended endpoints vulnerability in HTTP daemon in Synology SSL VPN Client before 1.2.4-0224 allows remote attackers to conduct man-in-the-middle attacks via a crafted pay...Show more |
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. The issue involves the "Mail" component. It allows remote attackers to read the cleartext content of S/MIM...Show more |
1Ibm 1Infosphere Information Server Nov 21, 2024 Jun 5, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit thi...Show more |
ikst versions before 1.1.2 download resources over HTTP, which leaves it vulnerable to MITM attacks. |
gfe-sass is a library for promises (CommonJS/Promises/A,B,D) gfe-sass downloads resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the...Show more |
The hubl-server module is a wrapper for the HubL Development Server. During installation hubl-server downloads a set of dependencies from api.hubapi.com. It appears in the code that these files are downloaded over HTTPS...Show more |
IBM BigFix Platform 9.2 and 9.5 transmits sensitive or security-critical data in clear text in a communication channel that can be sniffed by unauthorized actors. IBM X-Force ID: 143745. |
1Vgate 1Icar 2 Wi Fi Obd2 Firmware Nov 21, 2024 May 30, 2018 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 An issue was discovered on Vgate iCar 2 Wi-Fi OBD2 Dongle devices. The data packets that are sent between the iOS or Android application and the OBD dongle are not encrypted. The combination of this vulnerability with th...Show more |