CWE-319
923 CVEs • Abstraction: Base • Likelihood of Exploit: High
Cleartext Transmission of Sensitive Information
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
CVEs (923)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
ikst versions before 1.1.2 download resources over HTTP, which leaves it vulnerable to MITM attacks. |
gfe-sass is a library for promises (CommonJS/Promises/A,B,D) gfe-sass downloads resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the...Show more |
The hubl-server module is a wrapper for the HubL Development Server. During installation hubl-server downloads a set of dependencies from api.hubapi.com. It appears in the code that these files are downloaded over HTTPS...Show more |
IBM BigFix Platform 9.2 and 9.5 transmits sensitive or security-critical data in clear text in a communication channel that can be sniffed by unauthorized actors. IBM X-Force ID: 143745. |
1Vgate 1Icar 2 Wi Fi Obd2 Firmware Nov 21, 2024 May 30, 2018 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 An issue was discovered on Vgate iCar 2 Wi-Fi OBD2 Dongle devices. The data packets that are sent between the iOS or Android application and the OBD dongle are not encrypted. The combination of this vulnerability with th...Show more |
1Simplisafe 1U9k Kp1000 Firmware Nov 21, 2024 May 24, 2018 N/A· v4 6.6 MEDIUM· v3 1.9 LOW· v2 SimpliSafe Original has Unencrypted Keypad Transmissions, which allows physically proximate attackers to discover the PIN. |
1Simplisafe 4U9k Es1000 Firmware U9k Kr1 FirmwareU9k Ms1000 Firmware+1 moreNov 21, 2024 May 24, 2018 N/A· v4 4.3 MEDIUM· v3 1.9 LOW· v2 SimpliSafe Original has Unencrypted Sensor Transmissions, which allows physically proximate attackers to obtain potentially sensitive information about the specific times when alarm-system events occur. |
1Schneider Electric 1Ampla Manufacturing Execution System Nov 21, 2024 May 18, 2018 N/A· v4 4.1 MEDIUM· v3 1.9 LOW· v2 Schneider Electric Ampla MES 6.4 provides capability to interact with data from third party databases. When connectivity to those databases is configured to use a SQL user name and password, an attacker may be able to sn...Show more |
1Cisco 1Secure Firewall Management Center Nov 26, 2024 May 2, 2018 N/A· v4 5.8 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to restart an instance of the Snort detection engine on an affected device, resulting in a brief...Show more |
1Cisco 1Secure Firewall Management Center Nov 26, 2024 May 2, 2018 N/A· v4 5.8 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to restart an instance of the Snort detection engine on an affected device, resulting in a brief...Show more |
1Abbott 4Accent Firmware Accent Mri FirmwareAccent St Firmware+1 moreNov 21, 2024 Apr 25, 2018 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 Abbott Laboratories Accent and Anthem pacemakers manufactured prior to Aug 28, 2017 transmit unencrypted patient information via RF communications to programmers and home monitoring units. Additionally, the Accent and An...Show more |
1Schneider Electric 166074 Mge Network Management Card Transverse Jun 17, 2026 Apr 18, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 A cleartext transmission of sensitive information vulnerability exists in Schneider Electric's 66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS. he integrated web server (Port 80/443/TCP) of...Show more |
The Themes App Honor 8 Lite Huawei mobile phones with software of versions before Prague-L31C576B172, versions before Prague-L31C530B160, versions before Prague-L31C432B180 has a man-in-the-middle (MITM) vulnerability du...Show more |
1Cisco 1Spark Hybrid Calendar Service Nov 21, 2024 Mar 27, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in the auto discovery phase of Cisco Spark Hybrid Calendar Service could allow an unauthenticated, remote attacker to view sensitive information in the unencrypted headers of an HTTP method request. The a...Show more |
2Debian Gitlab2Debian Linux GitlabNov 21, 2024 Mar 21, 2018 N/A· v4 7.2 HIGH· v3 4.0 MEDIUM· v2 Gitlab Enterprise Edition version 10.1.0 is vulnerable to an insufficiently protected credential issue in the project service integration API endpoint resulting in an information disclosure of plaintext password. |
1Hanwha Security 2Snh V6410pn Firmware Snh V6410pnw FirmwareJun 17, 2026 Mar 13, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Unencrypted way of remote control and communications in Hanwha Techwin Smartcams |
1Belden 134Hirschmann M1 8mm Sc Hirschmann M1 8sfpHirschmann M1 8sm Sc+131 moreJun 17, 2026 Mar 6, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A Cleartext Transmission of Sensitive Information issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, and OCTOPUS Classic Platform Switches. A cleartext transmission of sensitive info...Show more |
Samsung Display Solutions App before 3.02 for Android allows man-in-the-middle attackers to spoof B2B content by leveraging failure to use encryption during information transmission. |
1Eq 3 1Homematic Central Control Unit Ccu2 Firmware Jun 17, 2026 Feb 22, 2018 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 In /usr/local/etc/config/addons/mh/loopupd.sh on eQ-3 AG HomeMatic CCU2 2.29.22 devices, software update packages are downloaded via the HTTP protocol, which does not provide any cryptographic protection of the downloade...Show more |
The FSX / P3Dv4 installer 2.0.1.231 for Flight Sim Labs A320-X sends a user's Google account credentials to http://installLog.flightsimlabs.com/LogHandler3.ashx if a pirated serial number has been entered, which allows r...Show more |