CWE-319
Overview
- CWE ID
- 319
- CWE Name
- Cleartext Transmission of Sensitive Information
- CWE Abstraction
- Base
- CWE structure
- Simple
- CWE Status
- Draft
Description
The software transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Extended Description
Many communication channels can be "sniffed" by attackers during data transmission. For example, network traffic can often be sniffed by any attacker who has access to a network interface. This significantly lowers the difficulty of exploitation by attack