risk
Credentials and sensitive data transmitted in clear text
Authentication credentials or sensitive system communications transmitted unencrypted over networks, and absence of mutual sender/receiver authentication, enable interception, credential theft, and spoofing.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- category
- cyber_security
- domain
- Cryptography & Key Management
- Network & Communications Security
- taxonomy
- iso-27005-vulnerability
- inherent_rating
- high
Details
- risk_id
- crypto-cleartext-credential-transfer
- category
- cyber_security
- likelihood
- medium
- impact
- high
- inherent_rating
- high
- treatment
- mitigate
- taxonomies
- iso-27005-vulnerability
Source
No record-specific source URL is provided.
Connections
- UC-NET-03 — Provide trusted channels and control session lifecycle mitigates Credentials and sensitive data transmitted in clear text
- strength
- primary
- rationale
- Out-of-band delivery of credentials/keys plus mutually authenticated trusted paths prevent credential capture and spoofing.
- UC-CRYPTO-01 — Encrypt data at rest and in transit mitigates Credentials and sensitive data transmitted in clear text
- strength
- primary
- rationale
- Mandates strong encryption of data in transit over all public/external networks and rejects fallback to insecure protocols, directly preventing credentials and sensitive comms from crossing the wire in clear text.
- UC-NET-02 — Authorize and secure remote, wireless, and mobile access mitigates Credentials and sensitive data transmitted in clear text
- strength
- primary
- rationale
- Mandatory mutual authentication and encryption on remote/wireless links prevent credential interception and spoofing on those channels.