CWE-319
898 CVEs • Abstraction: Base • Likelihood of Exploit: High
Cleartext Transmission of Sensitive Information
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
CVEs (898)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Simplisafe 1U9k Kp1000 Firmware Nov 21, 2024 May 24, 2018 N/A· v4 6.6 MEDIUM· v3 1.9 LOW· v2 SimpliSafe Original has Unencrypted Keypad Transmissions, which allows physically proximate attackers to discover the PIN. |
1Simplisafe 4U9k Es1000 Firmware U9k Kr1 FirmwareU9k Ms1000 Firmware+1 moreNov 21, 2024 May 24, 2018 N/A· v4 4.3 MEDIUM· v3 1.9 LOW· v2 SimpliSafe Original has Unencrypted Sensor Transmissions, which allows physically proximate attackers to obtain potentially sensitive information about the specific times when alarm-system events occur. |
1Schneider Electric 1Ampla Manufacturing Execution System Nov 21, 2024 May 18, 2018 N/A· v4 4.1 MEDIUM· v3 1.9 LOW· v2 Schneider Electric Ampla MES 6.4 provides capability to interact with data from third party databases. When connectivity to those databases is configured to use a SQL user name and password, an attacker may be able to sn...Show more |
1Cisco 1Secure Firewall Management Center Nov 26, 2024 May 2, 2018 N/A· v4 5.8 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to restart an instance of the Snort detection engine on an affected device, resulting in a brief...Show more |
1Cisco 1Secure Firewall Management Center Nov 26, 2024 May 2, 2018 N/A· v4 5.8 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to restart an instance of the Snort detection engine on an affected device, resulting in a brief...Show more |
1Abbott 4Accent Firmware Accent Mri FirmwareAccent St Firmware+1 moreNov 21, 2024 Apr 25, 2018 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 Abbott Laboratories Accent and Anthem pacemakers manufactured prior to Aug 28, 2017 transmit unencrypted patient information via RF communications to programmers and home monitoring units. Additionally, the Accent and An...Show more |
1Schneider Electric 166074 Mge Network Management Card Transverse Jun 17, 2026 Apr 18, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 A cleartext transmission of sensitive information vulnerability exists in Schneider Electric's 66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS. he integrated web server (Port 80/443/TCP) of...Show more |
The Themes App Honor 8 Lite Huawei mobile phones with software of versions before Prague-L31C576B172, versions before Prague-L31C530B160, versions before Prague-L31C432B180 has a man-in-the-middle (MITM) vulnerability du...Show more |
1Cisco 1Spark Hybrid Calendar Service Nov 21, 2024 Mar 27, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in the auto discovery phase of Cisco Spark Hybrid Calendar Service could allow an unauthenticated, remote attacker to view sensitive information in the unencrypted headers of an HTTP method request. The a...Show more |
2Debian Gitlab2Debian Linux GitlabNov 21, 2024 Mar 21, 2018 N/A· v4 7.2 HIGH· v3 4.0 MEDIUM· v2 Gitlab Enterprise Edition version 10.1.0 is vulnerable to an insufficiently protected credential issue in the project service integration API endpoint resulting in an information disclosure of plaintext password. |
1Hanwha Security 2Snh V6410pn Firmware Snh V6410pnw FirmwareJun 17, 2026 Mar 13, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Unencrypted way of remote control and communications in Hanwha Techwin Smartcams |
1Belden 134Hirschmann M1 8mm Sc Hirschmann M1 8sfpHirschmann M1 8sm Sc+131 moreJun 17, 2026 Mar 6, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A Cleartext Transmission of Sensitive Information issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, and OCTOPUS Classic Platform Switches. A cleartext transmission of sensitive info...Show more |
Samsung Display Solutions App before 3.02 for Android allows man-in-the-middle attackers to spoof B2B content by leveraging failure to use encryption during information transmission. |
1Eq 3 1Homematic Central Control Unit Ccu2 Firmware Jun 17, 2026 Feb 22, 2018 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 In /usr/local/etc/config/addons/mh/loopupd.sh on eQ-3 AG HomeMatic CCU2 2.29.22 devices, software update packages are downloaded via the HTTP protocol, which does not provide any cryptographic protection of the downloade...Show more |
The FSX / P3Dv4 installer 2.0.1.231 for Flight Sim Labs A320-X sends a user's Google account credentials to http://installLog.flightsimlabs.com/LogHandler3.ashx if a pirated serial number has been entered, which allows r...Show more |
When using Distributed Test only (RMI based), Apache JMeter 2.x and 3.x uses an unsecured RMI connection. This could allow an attacker to get Access to JMeterEngine and send unauthorized code. |
Fixed sizes of HTTPS responses in Tinder iOS app and Tinder Android app allow an attacker to extract private sensitive information by sniffing network traffic. |
Unencrypted transmission of images in Tinder iOS app and Tinder Android app allows an attacker to extract private sensitive information by sniffing network traffic. |
2Debian Enigmail2Debian Linux EnigmailMay 13, 2026 Dec 27, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Enigmail before 1.9.9. A remote attacker can obtain cleartext content by sending an encrypted data block (that the attacker cannot directly decrypt) to a victim, and relying on the victim to au...Show more |
1Cambiumnetworks 5Cnpilot E400 Firmware Cnpilot E410 FirmwareCnpilot E600 Firmware+2 moreMay 13, 2026 Dec 20, 2017 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, an undocumented, root-privilege administration web shell is available using the HTTP path https://<device-ip-or-hostname>/adm/syscmd.asp. |