CWE-319

High likelihood

Cleartext Transmission of Sensitive Information

Parent: CWE-311 - Missing Encryption of Sensitive Data

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

882 vulnerabilities with CWE-319
CVE-2022-43691 MEDIUM
Concrete CMS <8.5.10, 9.0.0-9.1.2 - Info Disclosure
CVSS 5.3
CVE-2022-38122 HIGH
UPSMON PRO - Unauthenticated Cleartext Transmission of Sensitive Information via HTTP
CVSS 7.5
CVE-2022-33321 CRITICAL
Mitsubishi Electric - Info Disclosure
CVSS 9.8
CVE-2022-42916 HIGH
curl 7.77.0-7.85.0 - Cleartext Transmission of Sensitive Information via IDN Character Bypass
CVSS 7.5
CVE-2022-41636 CRITICAL
Haas Controller <100.20.000.1110 - Info Disclosure
CVSS 9.1
CVE-2022-41627 MEDIUM
AliveCor's KardiaMobile - Info Disclosure
CVSS 4.8
CVE-2022-41983 LOW
F5 Big-ip Access Policy Manager < 13.1.5 - Cleartext Transmission
CVSS 3.7
CVE-2022-3206 MEDIUM
Passster WP <3.5.5.5.2 - Info Disclosure
CVSS 5.9
CVE-2022-39287 HIGH
tiny-csrf < 1.1.0 - Cleartext Transmission of Sensitive Information
CVSS 8.1
CVE-2022-39269 CRITICAL
PJSIP 2.11-2.13 - Cleartext Transmission of Sensitive Information via SRTP Restart
CVSS 9.1
CVE-2022-32227 MEDIUM
Rocket.Chat < 4.7.5 - Cleartext Transmission of Sensitive OAuth Tokens
CVSS 6.5
CVE-2022-38846 MEDIUM
EspoCRM 7.1.8 - Cleartext Transmission of Sensitive Information via Missing Secure Flag
CVSS 5.9
CVE-2022-30312 MEDIUM
Honeywell Trend IQ412, IQ411, IQ422, IQ4NC, IQ4E Firmware - Cleartext Sensitive Data Transmission
CVSS 6.5
CVE-2022-2083 HIGH
Simple Single Sign On < 4.1.0 - Cleartext Transmission of OAuth Client Secret
CVSS 7.5
CVE-2022-2485 CRITICAL
AutomationDirect Stride Field I/O < 8.11.3.0 Cleartext Sensitive Info in Login Response
CVSS 9.6
CVE-2022-2005 HIGH
AutomationDirect C-more EA9 Firmware < 6.73 - Cleartext Transmission of Sensitive Information
CVSS 7.5
CVE-2022-2003 HIGH
AutomationDirect DirectLOGIC D0-06 Series < 2.72 - Cleartext Password Exposure via Serial Port
CVSS 7.7
CVE-2022-36200 HIGH
FiberHome VDSL2 Modem HG150-Ub_V3.0 - Info Disclosure
CVSS 7.5
CVE-2022-32857 MEDIUM
iPadOS < 15.6 - Cleartext Transmission of Sensitive Information
CVSS 4.3
CVE-2022-2338 MEDIUM
Softing Secure Integration Server V1.22 - Auth Bypass
CVSS 5.7
CVE-2022-20243 MEDIUM
Android 13 - Local Information Disclosure of Sensitive Browsing Data via Core Utilities Log
CVSS 4.4
CVE-2022-32245 HIGH
SAP BusinessObjects BI Platform 420, 430 - Cleartext Transmission of Sensitive Info
CVSS 8.2
CVE-2022-33724 LOW
Samsung Dialer <SMR Aug-2022 Release 1 - Info Disclosure
CVSS 3.3
CVE-2022-27619 MEDIUM
Synology Note Station < 2.2.2-609 - Cleartext Transmission of Sensitive Information in Authentication Management
CVSS 6.8
CVE-2022-31204 HIGH
Omron CS/CJ/CP PLCs - Info Disclosure
CVSS 7.5
Details
Vulnerabilities 882
Exploit Likelihood High