VYPR

CWE-256

Plaintext Storage of a Password

BaseIncompleteLikelihood: High

Description

The product stores a password in plaintext within resources such as memory or files.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (286)

page 2 of 15
  • CVE-2025-3758HigMay 8, 2025
    risk 0.57cvss —epss 0.00

    WF2220 exposes endpoint /cgi-bin-igd/netcore_get.cgi that returns configuration of the device to unauthorized users. Returned configuration includes cleartext password. The vendor was contacted early about this disclosure but did not respond in any way.

  • CVE-2023-41610HigSep 18, 2024
    risk 0.57cvss 8.8epss 0.00

    Victure PC420 1.1.39 was discovered to contain a hardcoded root password which is stored in plaintext.

  • CVE-2024-3622HigApr 25, 2024
    risk 0.57cvss 8.8epss 0.01

    A flaw was found when using mirror-registry to install Quay. It uses a default secret, which is stored in plain-text format in one of the configuration template files. This issue may lead to all instances of Quay deployed using mirror-registry to have the same secret key. This…

  • CVE-2024-26165HigMar 12, 2024
    risk 0.57cvss 8.8epss 0.02

    Visual Studio Code Elevation of Privilege Vulnerability

  • CVE-2023-4918HigSep 12, 2023
    risk 0.57cvss 8.8epss 0.01

    A flaw was found in the Keycloak package, more specifically org.keycloak.userprofile. When a user registers itself through registration flow, the "password" and "password-confirm" field from the form will occur as regular user attributes. All users and clients with proper rights…

  • CVE-2022-43757CriFeb 7, 2023
    risk 0.57cvss 9.9epss 0.01

    A Cleartext Storage of Sensitive Information vulnerability in SUSE Rancher allows users on managed clusters to gain access to credentials. The impact depends on the credentials exposed This issue affects: SUSE Rancher Rancher versions prior to 2.5.17; Rancher versions prior to…

  • CVE-2020-5315HigJul 19, 2021
    risk 0.57cvss 8.8epss 0.00

    Dell EMC Repository Manager (DRM) version 3.2 contains a plain-text password storage vulnerability. Proxy server user password is stored in a plain text in a local database. A local authenticated malicious user with access to the local file system may use the exposed password to…

  • CVE-2020-5374HigJul 14, 2020
    risk 0.57cvss 8.8epss 0.01

    Dell EMC OpenManage Integration for Microsoft System Center (OMIMSSC) for SCCM and SCVMM versions prior to 7.2.1 contain a hard-coded cryptographic key vulnerability. A remote unauthenticated attacker may exploit this vulnerability to gain access to the appliance data for…

  • CVE-2024-20489HigSep 11, 2024
    risk 0.55cvss 8.4epss 0.00

    A vulnerability in the storage method of the PON Controller configuration file could allow an authenticated, local attacker with low privileges to obtain the MongoDB credentials. This vulnerability is due to improper storage of the unencrypted database credentials on the…

  • CVE-2021-38489HigSep 3, 2026
    risk 0.53cvss 8.2epss 0.00

    HDD password plaintext is stored in a UEFI variable.

  • CVE-2021-47961HigApr 10, 2026
    risk 0.53cvss 8.1epss 0.00

    A plaintext storage of a password vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access or influence the user's PIN code due to insecure storage. This may lead to unauthorized VPN configuration and potential interception of subsequent VPN…

  • CVE-2025-52164HigJul 18, 2025
    risk 0.53cvss 8.2epss 0.00

    Software GmbH Agorum core open v11.9.2 & v11.10.1 was discovered to store credentials in plaintext.

  • CVE-2024-36460HigAug 12, 2024
    risk 0.53cvss 8.1epss 0.01

    The front-end audit log allows viewing of unprotected plaintext passwords, where the passwords are displayed in plain text.

  • CVE-2024-40116HigJul 26, 2024
    risk 0.53cvss 8.1epss 0.00

    An issue in Solar-Log 1000 before v2.8.2 and build 52-23.04.2013 was discovered to store plaintext passwords in the export.html, email.html, and sms.html files -- fixed with 3.0.0-60 11.10.2013 for SL 200, 500, 1000 / not existing for SL 250, 300, 1200, 2000, SL 50 Gateway, SL…

  • CVE-2022-22554HigJan 24, 2022
    risk 0.53cvss 8.2epss 0.00

    Dell EMC System Update, version 1.9.2 and prior, contain an Unprotected Storage of Credentials vulnerability. A local attacker with user privleges could potentially exploit this vulnerability leading to the disclosure of user passwords.

  • CVE-2026-46488CriSep 15, 2026
    risk 0.52cvss —epss 0.00

    motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection. Prior to 0.44.0, motionEye accepts the client-controlled meye_username and meye_password_hash cookies as authentication material without…

  • CVE-2024-22432HigJan 25, 2024
    risk 0.51cvss 7.8epss 0.00

    Networker 19.9 and all prior versions contains a Plain-text Password stored in temporary config file during backup duration in NMDA MySQL Database backups. User has low privilege access to Networker Client system could potentially exploit this vulnerability, leading to the…

  • CVE-2020-25184HigMar 18, 2022
    risk 0.51cvss 7.8epss 0.00

    Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x stores the password in plaintext in a file that is in the same directory as the executable file. ISaGRAF Runtime reads the file and saves the data in a variable without any additional modification. A local, unauthenticated…

  • CVE-2019-0032HigApr 10, 2019
    risk 0.51cvss 7.8epss 0.00

    A password management issue exists where the Organization authentication username and password were stored in plaintext in log files. A locally authenticated attacker who is able to access these stored plaintext credentials can use them to login to the Organization. Affected…

  • CVE-2019-10329HigMay 31, 2019
    risk 0.50cvss 8.8epss 0.02

    Jenkins InfluxDB Plugin 1.21 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.