CWE-319

High likelihood

Cleartext Transmission of Sensitive Information

Parent: CWE-311 - Missing Encryption of Sensitive Data

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

898 vulnerabilities with CWE-319
CVE-2023-27861 MEDIUM
IBM Maximo Application Suite Manage Component 8.8.0 and 8.9.0 - Cleartext Transmission of Sensitive Information
CVSS 5.9
CVE-2023-30602 HIGH
Hitron Technologies CODA-5310 - Cleartext Transmission of Sensitive Information via Telnet
CVSS 7.5
CVE-2023-33960 HIGH
OpenProject <12.5.6 - Info Disclosure
CVSS 7.5
CVE-2023-3028 HIGH
HopeChart HQT-401 - Unauthenticated RCE
CVSS 8.6
CVE-2023-33730 CRITICAL
eScan Management Console 14.0.1400.2281 - Cleartext Transmission of Sensitive Information via GetUserCurrentPwd Function
CVSS 9.8
CVE-2023-28348 HIGH
Faronics Insight 10.0.19045 - Cleartext Transmission of Sensitive Information
CVSS 7.4
CVE-2023-33187 MEDIUM
highlight < 6.0.0 - Cleartext Transmission of Sensitive Information via Password Input Type Switch
CVSS 5.4
CVE-2023-31193 HIGH
Snap One OvrC Pro <7.3 - Info Disclosure
CVSS 7.5
CVE-2023-0864 HIGH
ABB Terra AC Wallbox - Cleartext Transmission of Sensitive Information
CVSS 7.1
CVE-2023-32784 HIGH
KeePass 2.00-2.53 - Cleartext Master Password Exposure via Memory Dump
CVSS 7.5
CVE-2023-30354 CRITICAL
Tenda CP3 Firmware V11.10.00.2211041355 - Cleartext Transmission of Sensitive Information via UART
CVSS 9.8
CVE-2023-25070 MEDIUM
SkyBridge MB-A100/110 Firmware <= 4.2.0 - Unauthenticated Cleartext Transmission of Sensitive Information via Telnet
CVSS 6.5
CVE-2023-32290 HIGH
myMail < 14.30 - Cleartext Transmission of Sensitive Information via STARTTLS Bypass
CVSS 7.5
CVE-2023-29681 MEDIUM
Tenda N301 v6.0 Firmware 12.03.01.06_pt - Cleartext Transmission of Sensitive Information in ecos_pw Cookie
CVSS 5.7
CVE-2023-29680 MEDIUM
Tenda N301 v6.0 Firmware 12.02.01.61_multi - Cleartext Transmission of Sensitive Information
CVSS 5.7
CVE-2023-25437 HIGH
vTech VCS754A Firmware 1.1.1.A-1.1.1.H - Cleartext Transmission of Sensitive Information
CVSS 8.8
CVE-2023-30841 MEDIUM
Baremetal Operator < 0.3.0 - Cleartext Transmission of Sensitive Information via ConfigMap Storage
CVSS 6.0
CVE-2023-1831 HIGH
Mattermost < 7.7.3 - Sensitive Information Exposure in Audit Logs
CVSS 7.2
CVE-2023-30515 HIGH
Jenkins Thycotic DevOps Secrets Vault Plugin < 1.0.0 - Cleartext Transmission of Sensitive Information in Build Log
CVSS 7.5
CVE-2023-30514 HIGH
Jenkins Azure Key Vault Plugin < 187.va_cd5fecd198a - Credential Exposure in Build Log
CVSS 7.5
CVE-2023-30513 HIGH
Jenkins Kubernetes Plugin < 3909.v1f2c633e8590 - Cleartext Transmission of Sensitive Information in Build Log
CVSS 7.5
CVE-2023-1802 MEDIUM
Docker Desktop 4.17.x - Info Disclosure
CVSS 5.9
CVE-2023-0922 MEDIUM
Samba >=4.0.0 <4.16.10 - Cleartext Transmission of Sensitive Information via LDAP Password Operations
CVSS 5.9
CVE-2023-1656 HIGH
ForgeRock Inc. OpenIDM <1.5.20.13 - Info Disclosure
CVSS 7.5
CVE-2023-27927 MEDIUM
sauter-controls ey-as525f001_firmware - Authenticated Cleartext Transmission of SMTP Password
CVSS 6.5
Details
Vulnerabilities 898
Exploit Likelihood High