CWE-319

High likelihood

Cleartext Transmission of Sensitive Information

Parent: CWE-311 - Missing Encryption of Sensitive Data

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

898 vulnerabilities with CWE-319
CVE-2024-27163 MEDIUM
Toshiba Tec e-Studio MFP - Cleartext Transmission of Sensitive Information via Internal API
CVSS 6.5
CVE-2024-35210 MEDIUM
SINEC Traffic Analyzer < 1.2 - Cleartext Transmission of Sensitive Information via Missing HSTS Enforcement
CVSS 5.1
CVE-2024-37393 HIGH
SecurEnvoy MFA < 9.4.514 - Unauthenticated LDAP Injection via DESKTOP Service
CVSS 7.5
CVE-2024-37163 MEDIUM
SkyScraper 1.0.0 - Cleartext Transmission of Sensitive Information via Unsecured HTTP Requests
CVSS 6.4
CVE-2024-36426 HIGH
TARGIT Decision Suite <23.2.15007.0 - Info Disclosure
CVSS 7.5
CVE-2024-35060 HIGH
NASA AIT-Core < 2.5.2 - Remote Code Execution via Crafted YAML File
CVSS 7.5
CVE-2024-35059 HIGH
NASA AIT-Core < 2.5.2 - Remote Code Execution via Pickle Deserialization
CVSS 7.5
CVE-2024-35058 HIGH
NASA AIT-Core < 2.5.2 - Remote Code Execution via API Wait Function
CVSS 7.5
CVE-2024-35057 HIGH
NASA AIT-Core < 2.5.2 - Remote Code Execution via Crafted Packet
CVSS 7.5
CVE-2024-31840 MEDIUM
Italtel Embrace 1.6.4 - Info Disclosure
CVSS 6.5
CVE-2024-30209 CRITICAL
SIMATIC RTLS Locating Manager -<V3.0.1.1 - Info Disclosure
CVSS 9.6
CVE-2024-28134 HIGH
CHARX SEC-3000/3050/3100/3150 Firmware < 1.5.1 - Unauthenticated Cleartext Transmission of Sensitive Information
CVSS 7.0
CVE-2024-0098 MEDIUM
NVIDIA ChatRTX < 0.3 - Cleartext Transmission of Sensitive Information
CVSS 5.5
CVE-2024-1657 HIGH
Red Hat Ansible Automation Platform 2.4 for RHEL 8/9 - Cleartext Transmission of Sensitive Information via WebSocket
CVSS 8.1
CVE-2024-4161 HIGH
Brocade SANnav < 2.3.0 - Unauthenticated Cleartext Transmission of Sensitive Information via Syslog
CVSS 8.6
CVE-2024-31206 HIGH
dectalk-tts <1.0.1 - Info Disclosure
CVSS 8.2
CVE-2024-28275 MEDIUM
Puwell Cloud Tech Co, Ltd 360Eyes Pro <3.9.5.16 - Info Disclosure
CVSS 6.5
CVE-2024-25960 HIGH
Dell PowerScale OneFS 8.2.2.x-9.7.0.x - Cleartext Transmission of Sensitive Information
CVSS 7.3
CVE-2024-25735 CRITICAL
WyreStorm Apollo VX20 - Information Disclosure
CVSS 9.1
CVE-2024-28250 MEDIUM
Cilium 1.14.0-1.14.7 - Cleartext Transmission of Sensitive Information via WireGuard Traffic
CVSS 6.1
CVE-2024-28249 MEDIUM
Cilium < 1.13.13, 1.14.0-1.14.8, 1.15.0-1.15.2 - Cleartext Transmission of Sensitive Information via IPsec Traffic
CVSS 6.1
CVE-2024-0860 HIGH
Softing EdgeAggregator and EdgeConnector - Cleartext Transmission of Sensitive Information
CVSS 8.0
CVE-2024-25650 MEDIUM
Delinea Secret Server 11.4 & Distributed Engine 8.4.3 - Cleartext Sensitive Information Transmission
CVSS 5.9
CVE-2024-26288 HIGH
CHARX SEC-3000/3050/3100/3150 Firmware < 1.5.1 - Unauthenticated Cleartext Transmission of Sensitive Information
CVSS 8.7
CVE-2024-0220 HIGH
B&R Automation Studio < 4.6 and Technology Guarding < 1.4.0 - Cleartext Transmission of Sensitive Information
CVSS 8.3
Details
Vulnerabilities 898
Exploit Likelihood High