Vulnerabilities > Cleartext Transmission of Sensitive Information

DATE CVE VULNERABILITY TITLE RISK
2021-04-20 CVE-2020-26197 Cleartext Transmission of Sensitive Information vulnerability in Dell EMC Powerscale Onefs
Dell PowerScale OneFS 8.1.0 - 9.1.0 contains an LDAP Provider inability to connect over TLSv1.2 vulnerability.
network
low complexity
dell CWE-319
critical
9.1
2021-04-19 CVE-2021-20992 Cleartext Transmission of Sensitive Information vulnerability in Fibaro Home Center 2 Firmware and Home Center Lite Firmware
In Fibaro Home Center 2 and Lite devices in all versions provide a web based management interface over unencrypted HTTP protocol.
network
low complexity
fibaro CWE-319
7.5
2021-04-15 CVE-2021-23884 Cleartext Transmission of Sensitive Information vulnerability in Mcafee Content Security Reporter
Cleartext Transmission of Sensitive Information vulnerability in the ePO Extension of McAfee Content Security Reporter (CSR) prior to 2.8.0 allows an ePO administrator to view the unencrypted password of the McAfee Web Gateway (MWG) or the password of the McAfee Web Gateway Cloud Server (MWGCS) read only user used to retrieve log files for analysis in CSR.
low complexity
mcafee CWE-319
4.3
2021-04-15 CVE-2020-7308 Cleartext Transmission of Sensitive Information vulnerability in Mcafee Endpoint Security
Cleartext Transmission of Sensitive Information between McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Update and McAfee Global Threat Intelligence (GTI) servers using DNS allows a remote attacker to view the requests from ENS and responses from GTI over DNS.
network
low complexity
mcafee CWE-319
6.5
2021-03-25 CVE-2021-27194 Cleartext Transmission of Sensitive Information vulnerability in Netop Vision PRO
Cleartext transmission of sensitive information in Netop Vision Pro up to and including 9.7.1 allows a remote unauthenticated attacker to gather credentials including Windows login usernames and passwords.
low complexity
netop CWE-319
8.8
2021-03-17 CVE-2020-35456 Cleartext Transmission of Sensitive Information vulnerability in Taidii Diibear 2.4.0
The Taidii Diibear Android application 2.4.0 and all its derivatives allow attackers to view private chat messages and media files via logcat because of excessive logging.
local
low complexity
taidii CWE-319
5.5
2021-03-09 CVE-2021-3417 Cleartext Transmission of Sensitive Information vulnerability in Lenovo Xclarity Orchestrator 1.0.0/1.1.0/1.2.0
An internal product security audit of LXCO, prior to version 1.2.2, discovered that credentials for Lenovo XClarity Administrator (LXCA), if added as a Resource Manager, are encoded then written to an internal LXCO log file each time a session is established with LXCA.
network
low complexity
lenovo CWE-319
4.9
2021-03-09 CVE-2020-8356 Cleartext Transmission of Sensitive Information vulnerability in Lenovo Xclarity Orchestrator 1.0.0/1.1.0/1.2.0
An internal product security audit of LXCO, prior to version 1.2.2, discovered that optional passwords, if specified, for the Syslog and SMTP forwarders are written to an internal LXCO log file in clear text.
network
low complexity
lenovo CWE-319
4.9
2021-03-08 CVE-2020-4695 Cleartext Transmission of Sensitive Information vulnerability in IBM API Connect 10.0.0.0/10.0.1.0
IBM API Connect V10 is impacted by insecure communications during database replication.
network
low complexity
ibm CWE-319
7.5
2021-02-26 CVE-2021-26565 Cleartext Transmission of Sensitive Information vulnerability in Synology products
Cleartext transmission of sensitive information vulnerability in synorelayd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers to obtain sensitive information via an HTTP session.
network
high complexity
synology CWE-319
5.9