CWE · MITRE source
CWE-319Cleartext Transmission of Sensitive Information
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Last updated: 09 May 2026 03:25 UTC
NIST 800-53 r5 controls that address this weakness (15)AI
Showing the 10 most specific. Generic controls that address many weakness types are collapsed below.
| Control | Title | Family | Why it addresses this CWE |
|---|---|---|---|
SC-12 | Cryptographic Key Establishment and Management | SC | Key-establishment procedures specify secure distribution channels that preclude cleartext transmission of key material. |
SC-13 | Cryptographic Protection | SC | Requires cryptography for transmission uses, eliminating cleartext exposure of sensitive data in transit. |
SC-19 | Voice Over Internet Protocol | SC | Usage restrictions and technology-specific guidance routinely mandate encryption (SRTP, TLS) for voice streams that carry sensitive information. |
CM-13 | Data Action Mapping | CM | Mapping transmission actions in data flows helps prevent cleartext transmission of sensitive information. |
CM-6 | Configuration Settings | CM | Settings can enforce secure transmission protocols to prevent cleartext transmission of sensitive data. |
AT-3 | Role-based Training | AT | Role-based training covers secure transmission methods, mitigating cleartext transmission of sensitive data. |
CA-3 | Information Exchange | CA | By requiring documented security controls for information exchanges, the control reduces the risk of cleartext transmission of sensitive data. |
MP-1 | Policy and Procedures | MP | Policy addresses secure transport and handling of media to avoid cleartext transmission of sensitive information. |
PM-17 | Protecting Controlled Unclassified Information on External Systems | PM | Enforces safeguards against cleartext transmission of CUI when data leaves organizational boundaries to external systems. |
SA-9 | External System Services | SA | Explicit controls and continuous oversight on external system services prevent cleartext transmission of sensitive information over provider-managed channels. |
Show 5 more broadly-applicable controls
SC-23 | Session Authenticity | SC | Eliminates cleartext exposure of session identifiers or tokens that would allow hijacking. |
SC-37 | Out-of-band Channels | SC | Sensitive values are moved off the primary channel, avoiding cleartext transmission risks associated with that channel. |
SC-40 | Wireless Link Protection | SC | Mandates cryptographic protection of the wireless medium, eliminating cleartext transmission of sensitive information over the air. |
SC-8 | Transmission Confidentiality and Integrity | SC | The control explicitly requires confidentiality protection for transmitted information, preventing cleartext exposure of sensitive data. |
SC-9 | Transmission Confidentiality | SC | Directly prevents cleartext transmission of sensitive information by requiring encryption or equivalent confidentiality protections during transit. |
Top CVEs of this weakness type, ranked by Risk Priority
| CVE | Risk | CVSS | EPSS | Published |
|---|---|---|---|---|
CVE-2024-25735 | 7.2 | 9.1 | 0.9036 | 2024-03-27 |
CVE-2024-37393 | 6.6 | 7.5 | 0.8466 | 2024-06-10 |
CVE-2016-5649 | 6.0 | 9.8 | 0.6719 | 2018-07-24 |
CVE-2023-32784 | 6.0 | 7.5 | 0.7550 | 2023-05-15 |
CVE-2017-5259 | 5.7 | 8.8 | 0.6634 | 2017-12-20 |
CVE-2018-12710 | 5.1 | 8.0 | 0.5847 | 2018-08-29 |
CVE-2021-39341 | 4.3 | 8.2 | 0.4432 | 2021-11-01 |
CVE-2023-33960 | 4.0 | 7.5 | 0.4160 | 2023-06-01 |
CVE-2018-1297 | 3.0 | 9.8 | 0.1799 | 2018-02-13 |
CVE-2014-5380 | 2.6 | 7.5 | 0.1898 | 2020-01-13 |
CVE-2019-3993 | 2.2 | 7.5 | 0.1161 | 2019-12-17 |
CVE-2018-13140 | 2.1 | 8.1 | 0.0877 | 2018-09-24 |
CVE-2021-20623 | 2.1 | 9.8 | 0.0208 | 2021-02-05 |
CVE-2023-33730 | 2.1 | 9.8 | 0.0155 | 2023-05-31 |
CVE-2023-6248 | 2.1 | 10.0 | 0.0168 | 2023-11-21 |
CVE-2025-26199 | 2.1 | 9.8 | 0.0303 | 2025-06-18 |
CVE-2017-15999 | 2.0 | 9.8 | 0.0015 | 2017-10-29 |
CVE-2018-7259 | 2.0 | 9.8 | 0.0018 | 2018-02-20 |
CVE-2018-6295 | 2.0 | 9.8 | 0.0024 | 2018-03-13 |
CVE-2018-7246 | 2.0 | 9.8 | 0.0015 | 2018-04-18 |
CVE-2018-8855 | 2.0 | 9.8 | 0.0015 | 2018-07-24 |
CVE-2018-11749 | 2.0 | 9.8 | 0.0015 | 2018-08-24 |
CVE-2019-6526 | 2.0 | 9.8 | 0.0012 | 2019-04-15 |
CVE-2019-3793 | 2.0 | 9.8 | 0.0025 | 2019-04-24 |
CVE-2019-3801 | 2.0 | 9.8 | 0.0007 | 2019-04-25 |