CWE · MITRE source
CWE-319Cleartext Transmission of Sensitive Information
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Last updated: 20 August 2026 20:22 UTC
Cumulative inbound coverage
How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.
Collective: partial · 4 mapping(s) from 1 framework(s): CAPEC 4 (partial)
OWASP Top 10 for Web (2025)
This weakness contributes to A04:2025 Cryptographic Failures.
Control responseHuman-reviewed
Answering this weakness across the control lifecycle, from our framework cross-walks.
NIST 800-53 r5 controls that address this weakness (15)AI-assisted
Showing the 10 most specific. Generic controls that address many weakness types are collapsed below.
| Control | Title | Family | Why it addresses this CWE |
|---|---|---|---|
SC-12 | Cryptographic Key Establishment and Management | SC | Key-establishment procedures specify secure distribution channels that preclude cleartext transmission of key material. |
SC-13 | Cryptographic Protection | SC | Requires cryptography for transmission uses, eliminating cleartext exposure of sensitive data in transit. |
SC-19 | Voice Over Internet Protocol | SC | Usage restrictions and technology-specific guidance routinely mandate encryption (SRTP, TLS) for voice streams that carry sensitive information. |
CM-13 | Data Action Mapping | CM | Mapping transmission actions in data flows helps prevent cleartext transmission of sensitive information. |
CM-6 | Configuration Settings | CM | Settings can enforce secure transmission protocols to prevent cleartext transmission of sensitive data. |
AT-3 | Role-based Training | AT | Role-based training covers secure transmission methods, mitigating cleartext transmission of sensitive data. |
CA-3 | Information Exchange | CA | By requiring documented security controls for information exchanges, the control reduces the risk of cleartext transmission of sensitive data. |
MP-1 | Policy and Procedures | MP | Policy addresses secure transport and handling of media to avoid cleartext transmission of sensitive information. |
PM-17 | Protecting Controlled Unclassified Information on External Systems | PM | Enforces safeguards against cleartext transmission of CUI when data leaves organizational boundaries to external systems. |
SA-9 | External System Services | SA | Explicit controls and continuous oversight on external system services prevent cleartext transmission of sensitive information over provider-managed channels. |
Show 5 more broadly-applicable controls
SC-23 | Session Authenticity | SC | Eliminates cleartext exposure of session identifiers or tokens that would allow hijacking. |
SC-37 | Out-of-band Channels | SC | Sensitive values are moved off the primary channel, avoiding cleartext transmission risks associated with that channel. |
SC-40 | Wireless Link Protection | SC | Mandates cryptographic protection of the wireless medium, eliminating cleartext transmission of sensitive information over the air. |
SC-8 | Transmission Confidentiality and Integrity | SC | The control explicitly requires confidentiality protection for transmitted information, preventing cleartext exposure of sensitive data. |
SC-9 | Transmission Confidentiality | SC | Directly prevents cleartext transmission of sensitive information by requiring encryption or equivalent confidentiality protections during transit. |
Top CVEs of this weakness type, ranked by Risk Priority
| CVE | Risk | CVSS | EPSS | Published |
|---|---|---|---|---|
CVE-2024-25735 UPD | 8.9 | 9.1 | 0.5062 | 2024-03-27 |
CVE-2016-5649 UPD | 8.7 | 9.8 | 0.2443 | 2018-07-24 |
CVE-2018-12710 UPD | 8.6 | 8.0 | 0.7651 | 2018-08-29 |
CVE-2017-5259 UPD | 8.3 | 8.8 | 0.3918 | 2017-12-20 |
CVE-2018-1297 UPD | 8.2 | 9.8 | 0.0991 | 2018-02-13 |
CVE-2019-3993 UPD | 7.8 | 7.5 | 0.4570 | 2019-12-17 |
CVE-2021-20623 UPD | 7.8 | 9.8 | 0.0282 | 2021-02-05 |
CVE-2019-12503 UPD | 7.7 | 9.8 | 0.0200 | 2019-12-02 |
CVE-2015-0987 UPD | 7.6 | 10.0 | 0.0117 | 2015-10-06 |
CVE-2019-17393 UPD | 7.6 | 9.8 | 0.0184 | 2019-10-18 |
CVE-2019-18852 UPD | 7.6 | 9.8 | 0.0154 | 2019-11-11 |
CVE-2019-16672 UPD | 7.6 | 9.8 | 0.0128 | 2019-12-06 |
CVE-2020-6198 UPD | 7.6 | 9.8 | 0.0138 | 2020-03-10 |
CVE-2020-5594 UPD | 7.6 | 9.8 | 0.0130 | 2020-06-23 |
CVE-2022-21829 UPD | 7.6 | 9.8 | 0.0172 | 2022-06-24 |
CVE-2023-25437 UPD | 7.6 | 8.8 | 0.1411 | 2023-04-27 |
CVE-2023-6248 UPD | 7.6 | 10.0 | 0.0122 | 2023-11-21 |
CVE-2018-7259 UPD | 7.5 | 9.8 | 0.0100 | 2018-02-20 |
CVE-2019-6526 UPD | 7.5 | 9.8 | 0.0100 | 2019-04-15 |
CVE-2019-3793 UPD | 7.5 | 9.8 | 0.0105 | 2019-04-24 |
CVE-2018-11421 UPD | 7.5 | 9.8 | 0.0091 | 2019-07-03 |
CVE-2018-11422 UPD | 7.5 | 9.8 | 0.0102 | 2019-07-03 |
CVE-2020-9477 UPD | 7.5 | 9.8 | 0.0126 | 2020-03-04 |
CVE-2020-10376 UPD | 7.5 | 9.8 | 0.0106 | 2020-03-11 |
CVE-2020-11542 UPD | 7.5 | 9.8 | 0.0098 | 2020-04-04 |