CWE-319

High likelihood

Cleartext Transmission of Sensitive Information

Parent: CWE-311 - Missing Encryption of Sensitive Data

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

882 vulnerabilities with CWE-319
CVE-2021-29892 MEDIUM
IBM Cognos Controller 11.0.0 and 11.0.1 - Cleartext Transmission of Sensitive Information
CVSS 5.9
CVE-2021-39090 MEDIUM
IBM Cloud Pak for Security 1.10.0.0-1.10.6.0 - Cleartext Transmission of Sensitive Information via Missing HSTS
CVSS 5.9
CVE-2021-4258 LOW
whohas < 2021-11-01 - Cleartext Transmission of Sensitive Information in Package Information Handler
CVSS 3.7
CVE-2021-35246 MEDIUM
SolarWinds Engineer's Toolset - Cleartext Transmission
CVSS 5.3
CVE-2021-38828 MEDIUM
Xiongmai Camera XM-JPR2-LX < 4.02.r12.a6420987.10002.147502.00000 - Cleartext Transmission of Sensitive Information
CVSS 5.3
CVE-2021-39077 MEDIUM
IBM Security Guardium 10.5-11.4 - Cleartext Transmission of Sensitive Information
CVSS 4.4
CVE-2021-45447 HIGH
Hitachi Vantara Pentaho Business Analytics Server < 8.3.0.25, 9.2.0.2 - Cleartext Database Password Transmission
CVSS 7.7
CVE-2021-42948 LOW
HotelDruid Hotel Management Software <3.0.3 - Info Disclosure
CVSS 3.7
CVE-2021-3590 HIGH
Foreman >= 1.6.0 - Cleartext Transmission of Sensitive Information via Azure Compute Profile Password
CVSS 8.8
CVE-2021-28509 MEDIUM
Arista TerminAttr < 1.10.11 and EOS 4.23-4.23.11 - Cleartext Transmission of MACsec Sensitive Data
CVSS 6.1
CVE-2021-28508 MEDIUM
Arista TerminAttr < 1.10.11 and EOS 4.23-4.23.11 - Cleartext Transmission of Sensitive IPsec Data
CVSS 6.8
CVE-2021-32966 LOW
Philips Interoperability Solution XDS 2.5-3.11 - Cleartext Transmission of Sensitive Information via LDAP Referrals
CVSS 3.7
CVE-2021-32934 CRITICAL
ThroughTek P2P <3.1.5 - Info Disclosure
CVSS 9.1
CVE-2021-40392 HIGH
Moxa MXView Series <3.2.4 - Info Disclosure
CVSS 7.5
CVE-2021-45104 HIGH
HTCondor 8.9.3-9.0.9 and 9.1.0-9.5.0 - Cleartext Transmission of Sensitive Information
CVSS 7.4
CVE-2021-45894 MEDIUM
Softwarebuero Zauner ARC 4.2.0.4 - Info Disclosure
CVSS 5.9
CVE-2021-32982 HIGH
Automation Direct CLICK PLC CPU <3.00 - Info Disclosure
CVSS 7.5
CVE-2021-33022 HIGH
Philips Vue PACS <12.2 - Info Disclosure
CVSS 7.5
CVE-2021-27422 HIGH
GE Multilin UR Firmware < 8.10 - Unauthenticated Cleartext Transmission of Sensitive Information
CVSS 7.5
CVE-2021-41849 MEDIUM
Bluproducts G90 Firmware - Information Disclosure
CVSS 5.5
CVE-2021-40846 HIGH
Rhinode Trading Paints <2.0.36 - Man-in-the-Middle
CVSS 7.5
CVE-2021-45081 MEDIUM
Cobbler < 3.3.1 - Cleartext Transmission of Sensitive Information via HTTP Protocol
CVSS 5.9
CVE-2021-39026 MEDIUM
IBM Guardium Data Encryption 5.0.0.2 and 5.0.0.3 - Cleartext Transmission of Sensitive Information
CVSS 5.9
CVE-2021-29397 HIGH
NorthStar Club Management 6.3 - Cleartext Transmission of Sensitive Information in Admin Login
CVSS 7.5
CVE-2021-45735 HIGH
TOTOLINK X5000R <9.1.0u.6118 - Auth Bypass
CVSS 7.5
Details
Vulnerabilities 882
Exploit Likelihood High