CWE-319

High likelihood

Cleartext Transmission of Sensitive Information

Parent: CWE-311 - Missing Encryption of Sensitive Data

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

884 vulnerabilities with CWE-319
CVE-2018-12710 HIGH
D-Link DIR-601 2.02NA - Info Disclosure
CVSS 8.0
CVE-2018-11749 CRITICAL
Puppet Enterprise < 2016.4.14 - Cleartext Transmission of Sensitive Information via startTLS LDAP Login
CVSS 9.8
CVE-2018-10634 MEDIUM
Medtronic MiniMed MMT - Info Disclosure
CVSS 4.8
CVE-2018-11050 HIGH
Dell EMC NetWorker 9.0-9.1.1.8, 9.2.1.3, 18.1.0.1 - Cleartext Transmission of Sensitive Information in RabbitMQ AMQP
CVSS 8.8
CVE-2018-11338 HIGH
Intuit Lacerte < 2017 - Cleartext Transmission of Sensitive Information via SMB
CVSS 7.5
CVE-2018-8855 CRITICAL
Echelon SmartServer <4.11.007 - Info Disclosure
CVSS 9.8
CVE-2018-0025 MEDIUM
Juniper Junos Cleartext Transmission of Sensitive Information via HTTP/HTTPS Pass-Through Authentication
CVSS 6.1
CVE-2018-8929 HIGH
Synology SSL VPN Client <1.2.4-0224 - SSRF
CVSS 7.3
CVE-2018-4227 HIGH
iPhone OS < 11.4 and macOS < 10.13.5 - Cleartext Transmission of Sensitive Information in Mail
CVSS 7.5
CVE-2018-1454 MEDIUM
IBM InfoSphere Information Server <11.8 - Info Disclosure
CVSS 5.9
CVE-2018-1600 HIGH
IBM BigFix Platform <9.5 - Info Disclosure
CVSS 8.6
CVE-2018-11477 MEDIUM
Vgate iCar 2 Wi-Fi OBD2 Dongle - Cleartext Transmission of Sensitive Information
CVSS 6.5
CVE-2018-11402 MEDIUM
SimpliSafe Original - Cleartext Transmission of Sensitive Information via Keypad
CVSS 6.6
CVE-2018-11399 MEDIUM
SimpliSafe Original - Cleartext Transmission of Sensitive Information via Unencrypted Sensor Transmissions
CVSS 4.3
CVE-2018-0283 MEDIUM
Cisco Secure Firewall Management Center - Unauthenticated Denial of Service via TLS TCP Connection Handling
CVSS 5.8
CVE-2018-0281 MEDIUM
Cisco Secure Firewall Management Center - Denial of Service via TLS Extension Handling
CVSS 5.8
CVE-2018-7246 CRITICAL
Schneider Electric 66074 MGE Network Management Card Cleartext Transmission of Sensitive Information
CVSS 9.8
CVE-2018-6295 CRITICAL
Hanwha Techwin Smartcams - Cleartext Transmission of Sensitive Information
CVSS 9.8
CVE-2018-5471 MEDIUM
Belden Hirschmann - Info Disclosure
CVSS 5.9
CVE-2018-6019 MEDIUM
Samsung Display Solutions App <3.02 - Info Disclosure
CVSS 5.9
CVE-2018-7298 HIGH
eQ-3 HomeMatic CCU2 Firmware 2.29.22 - Cleartext Transmission of Sensitive Information via HTTP Firmware Update
CVSS 8.1
CVE-2018-7259 CRITICAL
Flight Sim Labs A320-X 2.0.1.231 - Cleartext Transmission of Sensitive Information via Installer Log Handler
CVSS 9.8
CVE-2018-1297 CRITICAL
Apache JMeter 2.x-3.x - Unauthenticated Remote Code Execution via Unsecured RMI Connection
CVSS 9.8
CVE-2018-6018 CRITICAL
Tinder iOS/Android - Info Disclosure
CVSS 9.1
CVE-2018-6017 CRITICAL
Tinder iOS and Android - Cleartext Transmission of Sensitive Information via Image Traffic
CVSS 9.1
Details
Vulnerabilities 884
Exploit Likelihood High