VYPR

CWE-256

Plaintext Storage of a Password

BaseIncompleteLikelihood: High

Description

The product stores a password in plaintext within resources such as memory or files.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (286)

page 11 of 15
  • CVE-2025-12680MedFeb 2, 2026
    risk 0.32cvss 4.9epss 0.00

    Brocade SANnav before Brocade SANnav 2.4.0b logs database passwords in clear text in the standby SANnav server, after disaster recovery failover. The vulnerability could allow a remote authenticated attacker with admin privilege able to access the SANnav logs or the supportsave…

  • CVE-2024-49370MedOct 23, 2024
    risk 0.32cvss 4.9epss 0.01

    Pimcore is an open source data and experience management platform. When a PortalUserObject is connected to a PimcoreUser and "Use Pimcore Backend Password" is set to true, the change password function in Portal Profile sets the new password. Prior to Pimcore portal engine…

  • CVE-2022-27548MedJul 6, 2022
    risk 0.32cvss 4.9epss 0.00

    HCL Launch stores user credentials in plain clear text which can be read by a local user.

  • CVE-2020-26079MedNov 18, 2020
    risk 0.32cvss 4.9epss 0.01

    A vulnerability in the web UI of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to obtain hashes of user passwords on an affected device. The vulnerability is due to insufficient protection of user credentials. An attacker could exploit this…

  • CVE-2026-6500MedMay 4, 2026
    risk 0.31cvss —epss 0.00

    Plaintext storage of a password vulnerability in ILM Informatique OpenConcerto allows Retrieve Embedded Sensitive Data. This issue affects OpenConcerto: 1.7.5.

  • CVE-2024-6833MedJul 17, 2024
    risk 0.31cvss 5.9epss 0.00

    A vulnerability in Zowe CLI allows local, privileged actors to store previously entered secure credentials in a plaintext file as part of an auto-init operation.

  • CVE-2026-36174MedJun 4, 2026
    risk 0.30cvss 4.6epss 0.00

    GNCC GP5 v7.1.76 was discovered to store sensitive wireless network information in plaintext during routine operations to the serial console. This issue allows physically-proximate attackers to obtain sensitive information, including network credentials, via monitoring the…

  • CVE-2024-44815MedSep 10, 2024
    risk 0.30cvss 4.6epss 0.01

    Vulnerability in Hathway Skyworth Router CM5100 v.4.1.1.24 allows a physically proximate attacker to obtain user credentials via SPI flash Firmware W25Q64JV.

  • CVE-2024-39922MedAug 13, 2024
    risk 0.30cvss 4.6epss 0.00

    A vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA1) (All versions), LOGO! 12/24RCEo (6ED1052-2MD08-0BA1) (All versions), LOGO! 230RCE (6ED1052-1FB08-0BA1) (All versions), LOGO! 230RCEo (6ED1052-2FB08-0BA1) (All versions), LOGO! 24CE (6ED1052-1CC08-0BA1)…

  • CVE-2026-22285MedMar 4, 2026
    risk 0.29cvss 4.4epss 0.00

    Dell Device Management Agent (DDMA), versions prior to 26.02, contain a Plaintext Storage of Password vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized Access.

  • CVE-2023-50956MedDec 18, 2024
    risk 0.29cvss 4.4epss 0.00

    IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9 could allow a privileged user to obtain highly sensitive user credentials from secret keys that are stored in clear text.

  • CVE-2024-25052MedJun 13, 2024
    risk 0.29cvss 4.4epss 0.00

    IBM Jazz Reporting Service 7.0.3 stores user credentials in plain clear text which can be read by an admin user. IBM X-Force ID: 283363.

  • CVE-2024-22312MedFeb 10, 2024
    risk 0.29cvss 4.4epss 0.00

    IBM Storage Defender - Resiliency Service 2.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 278748.

  • CVE-2022-3261MedSep 15, 2023
    risk 0.29cvss 4.4epss 0.00

    A flaw was found in OpenStack. Multiple components show plain-text passwords in /var/log/messages during the OpenStack overcloud update run, leading to a disclosure of sensitive information problem.

  • CVE-2022-3644MedOct 25, 2022
    risk 0.29cvss 5.5epss 0.00

    The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the API () instead of marking it as write only.

  • CVE-2021-21681MedAug 31, 2021
    risk 0.29cvss 5.5epss 0.00

    Jenkins Nomad Plugin 0.7.4 and earlier stores Docker passwords unencrypted in the global config.xml file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.

  • CVE-2019-10345MedJul 31, 2019
    risk 0.29cvss 5.5epss 0.00

    Jenkins Configuration as Code Plugin 1.20 and earlier did not treat the proxy password as a secret to be masked when logging or encrypted for export.

  • CVE-2026-57302MedJun 24, 2026
    risk 0.28cvss 4.3epss 0.00

    Jenkins FitNesse Plugin 1.36 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Extended Read permission or access to the Jenkins controller file system.

  • CVE-2025-14183MedDec 7, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in SGAI Space1 NAS N1211DS up to 1.0.915. This issue affects the function GET_FACTORY_INFO/GET_USER_INFO of the file /cgi-bin/JSONAPI of the component gsaiagent. The manipulation results in unprotected storage of credentials. The attack can be launched…

  • CVE-2025-53669MedJul 9, 2025
    risk 0.28cvss 4.3epss 0.00

    Jenkins VAddy Plugin 1.2.8 and earlier does not mask Vaddy API Auth Keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.