Vulnerabilities > Cleartext Transmission of Sensitive Information

DATE CVE VULNERABILITY TITLE RISK
2020-04-22 CVE-2020-7488 Cleartext Transmission of Sensitive Information vulnerability in Schneider-Electric products
A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists which could leak sensitive information transmitted between the software and the Modicon M218, M241, M251, and M258 controllers.
network
low complexity
schneider-electric CWE-319
7.5
2020-04-22 CVE-2019-19107 Cleartext Transmission of Sensitive Information vulnerability in multiple products
The Configuration pages in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway for user profiles and services transfer the password in plaintext (although hidden when displayed).
local
low complexity
abb busch-jaeger CWE-319
5.5
2020-04-22 CVE-2020-11685 Cleartext Transmission of Sensitive Information vulnerability in Jetbrains Goland
In JetBrains GoLand before 2019.3.2, the plugin repository was accessed via HTTP instead of HTTPS.
network
low complexity
jetbrains CWE-319
7.5
2020-04-22 CVE-2020-11539 Cleartext Transmission of Sensitive Information vulnerability in Titan SF Rush Smart Band Firmware 1.12
An issue was discovered on Tata Sonata Smart SF Rush 1.12 devices.
low complexity
titan CWE-319
8.1
2020-04-16 CVE-2020-7483 Cleartext Transmission of Sensitive Information vulnerability in Schneider-Electric Tristation 1131
**VERSION NOT SUPPORTED WHEN ASSIGNED** A vulnerability could cause certain data to be visible on the network when the 'password' feature is enabled.
network
low complexity
schneider-electric CWE-319
7.5
2020-04-15 CVE-2019-4594 Cleartext Transmission of Sensitive Information vulnerability in IBM Qradar Security Information and Event Manager
IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security.
network
high complexity
ibm CWE-319
5.9
2020-04-04 CVE-2020-11542 Cleartext Transmission of Sensitive Information vulnerability in 3Xlogic Infinias Eidc32 Firmware and Infinias Eidc32 web
3xLOGIC Infinias eIDC32 2.213 devices with Web 1.107 allow Authentication Bypass via CMD.HTM?CMD= because authentication depends on the client side's interpretation of the <KEY>MYKEY</KEY> substring.
network
low complexity
3xlogic CWE-319
critical
9.8
2020-03-27 CVE-2020-5860 Cleartext Transmission of Sensitive Information vulnerability in F5 products
On BIG-IP 15.0.0-15.1.0.2, 14.1.0-14.1.2.3, 13.1.0-13.1.3.2, 12.1.0-12.1.5.1, and 11.5.2-11.6.5.1 and BIG-IQ 7.0.0, 6.0.0-6.1.0, and 5.2.0-5.4.0, in a High Availability (HA) network failover in Device Service Cluster (DSC), the failover service does not require a strong form of authentication and HA network failover traffic is not encrypted by Transport Layer Security (TLS).
network
high complexity
f5 CWE-319
8.1
2020-03-25 CVE-2019-19127 Cleartext Transmission of Sensitive Information vulnerability in Tribalgroup Sits:Vision 9.7.0
An authentication bypass vulnerability is present in the standalone SITS:Vision 9.7.0 component of Tribal SITS in its default configuration, related to unencrypted communications sent by the client each time it is launched.
network
high complexity
tribalgroup CWE-319
8.1
2020-03-24 CVE-2020-6997 Cleartext Transmission of Sensitive Information vulnerability in Moxa Eds-510E Firmware and Eds-G516E Firmware
In Moxa EDS-G516E Series firmware, Version 5.2 or lower, sensitive information is transmitted over some web applications in cleartext.
network
low complexity
moxa CWE-319
7.5