← Back
CWE-319

898 CVEs • Abstraction: Base • Likelihood of Exploit: High

Cleartext Transmission of Sensitive Information

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

JSON object

Loading...

CVEs (898)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Simplisafe
1U9k Kp1000 Firmware
Nov 21, 2024
May 24, 2018
N/A· v4
6.6 MEDIUM· v3
1.9 LOW· v2
SimpliSafe Original has Unencrypted Keypad Transmissions, which allows physically proximate attackers to discover the PIN.
1Simplisafe
4U9k Es1000 Firmware
U9k Kr1 FirmwareU9k Ms1000 Firmware+1 more
Nov 21, 2024
May 24, 2018
N/A· v4
4.3 MEDIUM· v3
1.9 LOW· v2
SimpliSafe Original has Unencrypted Sensor Transmissions, which allows physically proximate attackers to obtain potentially sensitive information about the specific times when alarm-system events occur.
1Schneider Electric
1Ampla Manufacturing Execution System
Nov 21, 2024
May 18, 2018
N/A· v4
4.1 MEDIUM· v3
1.9 LOW· v2
Schneider Electric Ampla MES 6.4 provides capability to interact with data from third party databases. When connectivity to those databases is configured to use a SQL user name and password, an attacker may be able to sn...Show more
Schneider Electric Ampla MES 6.4 provides capability to interact with data from third party databases. When connectivity to those databases is configured to use a SQL user name and password, an attacker may be able to sniff details from the connection string. Schneider Electric recommends that users of Ampla MES versions 6.4 and prior should upgrade to Ampla MES version 6.5 as soon as possible.Show less
1Cisco
1Secure Firewall Management Center
Nov 26, 2024
May 2, 2018
N/A· v4
5.8 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to restart an instance of the Snort detection engine on an affected device, resulting in a brief...Show more
A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to restart an instance of the Snort detection engine on an affected device, resulting in a brief denial of service (DoS) condition. The vulnerability is due to the incorrect handling of Transport Layer Security (TLS) TCP connection setup for the affected software. An attacker could exploit this vulnerability by sending crafted TLS traffic to an affected device. A successful exploit could allow the attacker to cause the Snort detection engine on the affected device to restart, resulting in a DoS condition. Cisco Bug IDs: CSCvg99327.Show less
1Cisco
1Secure Firewall Management Center
Nov 26, 2024
May 2, 2018
N/A· v4
5.8 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to restart an instance of the Snort detection engine on an affected device, resulting in a brief...Show more
A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to restart an instance of the Snort detection engine on an affected device, resulting in a brief denial of service (DoS) condition. The vulnerability is due to the incorrect handling of a Transport Layer Security (TLS) extension during TLS connection setup for the affected software. An attacker could exploit this vulnerability by sending a crafted TLS connection setup request to an affected device. A successful exploit could allow the attacker to cause the Snort detection engine on the affected device to restart, resulting in a DoS condition. Cisco Bug IDs: CSCvg97808.Show less
1Abbott
4Accent Firmware
Accent Mri FirmwareAccent St Firmware+1 more
Nov 21, 2024
Apr 25, 2018
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
Abbott Laboratories Accent and Anthem pacemakers manufactured prior to Aug 28, 2017 transmit unencrypted patient information via RF communications to programmers and home monitoring units. Additionally, the Accent and An...Show more
Abbott Laboratories Accent and Anthem pacemakers manufactured prior to Aug 28, 2017 transmit unencrypted patient information via RF communications to programmers and home monitoring units. Additionally, the Accent and Anthem pacemakers store the optional patient information without encryption. CVSS v3 base score: 3.1, CVSS vector string: AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N. Abbott has developed a firmware update to help mitigate the identified vulnerabilities.Show less
1Schneider Electric
166074 Mge Network Management Card Transverse
Jun 17, 2026
Apr 18, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
A cleartext transmission of sensitive information vulnerability exists in Schneider Electric's 66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS. he integrated web server (Port 80/443/TCP) of...Show more
A cleartext transmission of sensitive information vulnerability exists in Schneider Electric's 66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS. he integrated web server (Port 80/443/TCP) of the affected devices could allow remote attackers to discover an administrative account. If default on device, it is not using a SSL in settings and if multiple request of the page "Access Control" (IP-address device/ups/pas_cont.htm) account data will be sent in cleartextShow less
1Huawei
1Honor 8 Lite Firmware
Nov 21, 2024
Apr 11, 2018
N/A· v4
5.3 MEDIUM· v3
2.6 LOW· v2
The Themes App Honor 8 Lite Huawei mobile phones with software of versions before Prague-L31C576B172, versions before Prague-L31C530B160, versions before Prague-L31C432B180 has a man-in-the-middle (MITM) vulnerability du...Show more
The Themes App Honor 8 Lite Huawei mobile phones with software of versions before Prague-L31C576B172, versions before Prague-L31C530B160, versions before Prague-L31C432B180 has a man-in-the-middle (MITM) vulnerability due to the use of the insecure HTTP protocol for theme download. An attacker may exploit this vulnerability to tamper with downloaded themes.Show less
1Cisco
1Spark Hybrid Calendar Service
Nov 21, 2024
Mar 27, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability in the auto discovery phase of Cisco Spark Hybrid Calendar Service could allow an unauthenticated, remote attacker to view sensitive information in the unencrypted headers of an HTTP method request. The a...Show more
A vulnerability in the auto discovery phase of Cisco Spark Hybrid Calendar Service could allow an unauthenticated, remote attacker to view sensitive information in the unencrypted headers of an HTTP method request. The attacker could use this information to conduct additional reconnaissance attacks leading to the disclosure of sensitive customer data. The vulnerability exists in the auto discovery phase because an unencrypted HTTP request is made due to requirements for implementing the Hybrid Calendar service. An attacker could exploit this vulnerability by monitoring the unencrypted traffic on the network. An exploit could allow the attacker to access sensitive customer data belonging to Office365 users, such as email and calendar events. Cisco Bug IDs: CSCvg35593.Show less
2Debian
Gitlab
2Debian Linux
Gitlab
Nov 21, 2024
Mar 21, 2018
N/A· v4
7.2 HIGH· v3
4.0 MEDIUM· v2
Gitlab Enterprise Edition version 10.1.0 is vulnerable to an insufficiently protected credential issue in the project service integration API endpoint resulting in an information disclosure of plaintext password.
1Hanwha Security
2Snh V6410pn Firmware
Snh V6410pnw Firmware
Jun 17, 2026
Mar 13, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Unencrypted way of remote control and communications in Hanwha Techwin Smartcams
1Belden
134Hirschmann M1 8mm Sc
Hirschmann M1 8sfpHirschmann M1 8sm Sc+131 more
Jun 17, 2026
Mar 6, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
A Cleartext Transmission of Sensitive Information issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, and OCTOPUS Classic Platform Switches. A cleartext transmission of sensitive info...Show more
A Cleartext Transmission of Sensitive Information issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, and OCTOPUS Classic Platform Switches. A cleartext transmission of sensitive information vulnerability in the web interface has been identified, which may allow an attacker to obtain sensitive information through a successful man-in-the-middle attack.Show less
1Samsung
1Display Solutions
Jun 17, 2026
Mar 6, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Samsung Display Solutions App before 3.02 for Android allows man-in-the-middle attackers to spoof B2B content by leveraging failure to use encryption during information transmission.
1Eq 3
1Homematic Central Control Unit Ccu2 Firmware
Jun 17, 2026
Feb 22, 2018
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
In /usr/local/etc/config/addons/mh/loopupd.sh on eQ-3 AG HomeMatic CCU2 2.29.22 devices, software update packages are downloaded via the HTTP protocol, which does not provide any cryptographic protection of the downloade...Show more
In /usr/local/etc/config/addons/mh/loopupd.sh on eQ-3 AG HomeMatic CCU2 2.29.22 devices, software update packages are downloaded via the HTTP protocol, which does not provide any cryptographic protection of the downloaded contents. An attacker with a privileged network position (which could be obtained via DNS spoofing of www.meine-homematic.de or other approaches) can exploit this issue in order to provide arbitrary malicious firmware updates to the CCU2. This can result in a full system compromise.Show less
1Flightsimlabs
1A320 X
Jun 17, 2026
Feb 20, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
The FSX / P3Dv4 installer 2.0.1.231 for Flight Sim Labs A320-X sends a user's Google account credentials to http://installLog.flightsimlabs.com/LogHandler3.ashx if a pirated serial number has been entered, which allows r...Show more
The FSX / P3Dv4 installer 2.0.1.231 for Flight Sim Labs A320-X sends a user's Google account credentials to http://installLog.flightsimlabs.com/LogHandler3.ashx if a pirated serial number has been entered, which allows remote attackers to obtain sensitive information, e.g., by sniffing the network for cleartext HTTP traffic. This behavior was removed in 2.0.1.232.Show less
1Apache
1Jmeter
Nov 21, 2024
Feb 13, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
When using Distributed Test only (RMI based), Apache JMeter 2.x and 3.x uses an unsecured RMI connection. This could allow an attacker to get Access to JMeterEngine and send unauthorized code.
1Tinder
1Tinder
Jun 17, 2026
Jan 24, 2018
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Fixed sizes of HTTPS responses in Tinder iOS app and Tinder Android app allow an attacker to extract private sensitive information by sniffing network traffic.
1Tinder
1Tinder
Jun 17, 2026
Jan 24, 2018
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Unencrypted transmission of images in Tinder iOS app and Tinder Android app allows an attacker to extract private sensitive information by sniffing network traffic.
2Debian
Enigmail
2Debian Linux
Enigmail
May 13, 2026
Dec 27, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Enigmail before 1.9.9. A remote attacker can obtain cleartext content by sending an encrypted data block (that the attacker cannot directly decrypt) to a victim, and relying on the victim to au...Show more
An issue was discovered in Enigmail before 1.9.9. A remote attacker can obtain cleartext content by sending an encrypted data block (that the attacker cannot directly decrypt) to a victim, and relying on the victim to automatically decrypt that block and then send it back to the attacker as quoted text, aka the TBE-01-005 "replay" issue.Show less
1Cambiumnetworks
5Cnpilot E400 Firmware
Cnpilot E410 FirmwareCnpilot E600 Firmware+2 more
May 13, 2026
Dec 20, 2017
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, an undocumented, root-privilege administration web shell is available using the HTTP path https://<device-ip-or-hostname>/adm/syscmd.asp.