VYPR

CWE-256

Plaintext Storage of a Password

BaseIncompleteLikelihood: High

Description

The product stores a password in plaintext within resources such as memory or files.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (279)

page 8 of 14
  • CVE-2023-4400MedSep 13, 2023
    risk 0.40cvss 6.2epss 0.00

    A password management vulnerability in Skyhigh Secure Web Gateway (SWG) in main releases 11.x prior to 11.2.14, 10.x prior to 10.2.25 and controlled release 12.x prior to 12.2.1, allows some authentication information stored in configuration files to be extracted through SWG…

  • CVE-2023-39227MedSep 11, 2023
    risk 0.40cvss 6.1epss 0.00

    ​Softneta MedDream PACS stores usernames and passwords in plaintext. The plaintext storage could be abused by attackers to leak legitimate user’s credentials.

  • CVE-2022-4308MedApr 19, 2023
    risk 0.40cvss 6.1epss 0.00

    Plaintext Storage of a Password vulnerability in Secomea GateManager (USB wizard) allows Authentication abuse on SiteManager, if the generated file is leaked.

  • CVE-2022-41732MedNov 28, 2022
    risk 0.40cvss 6.2epss 0.00

    IBM Maximo Mobile 8.7 and 8.8 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 237407.

  • CVE-2019-19105MedApr 22, 2020
    risk 0.40cvss 6.2epss 0.00

    The backup function in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway saves the current settings and configuration of the application, including credentials of existing user accounts and other configuration's credentials in plaintext.

  • CVE-2025-66910MedDec 19, 2025
    risk 0.39cvss 6.0epss 0.00

    Turms Server v0.10.0-SNAPSHOT and earlier contains a plaintext password storage vulnerability in the administrator authentication system. The BaseAdminService class caches administrator passwords in plaintext within AdminInfo objects to optimize authentication performance. Upon…

  • CVE-2024-45283MedSep 10, 2024
    risk 0.39cvss 6.0epss 0.00

    SAP NetWeaver AS for Java allows an authorized attacker to obtain sensitive information. The attacker could obtain the username and password when creating an RFC destination. After successful exploitation, an attacker can read the sensitive information but cannot modify or…

  • CVE-2021-43590MedMar 4, 2022
    risk 0.39cvss 6.0epss 0.00

    Dell EMC Enterprise Storage Analytics for vRealize Operations, versions 4.0.1 to 6.2.1, contain a Plain-text password storage vulnerability. A local high privileged malicious user may potentially exploit this vulnerability, leading to the disclosure of certain user credentials.…

  • CVE-2024-29978MedNov 26, 2024
    risk 0.38cvss 5.9epss 0.01

    User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved from the coredump file. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors…

  • CVE-2023-43777MedOct 17, 2023
    risk 0.38cvss 5.9epss 0.00

    Eaton easySoft software is used to program easy controllers and displays for configuring, programming and defining parameters for all the intelligent relays. This software has a password protection functionality to secure the project file from unauthorized access. This password…

  • CVE-2025-46809MedJul 31, 2025
    risk 0.37cvss 5.7epss 0.00

    A Plaintext Storage of a Password vulnerability in SUSE exposes the credentials for the HTTP proxy in the log files. This issue affects Container suse/manager/4.3/proxy-httpd:4.3.16.9.67.1: from ? before 4.3.33-150400.3.55.2; Container suse/manager/5.0/x86_64/proxy-httpd:5.0.5.7…

  • CVE-2024-52361MedDec 18, 2024
    risk 0.37cvss 5.7epss 0.01

    IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9  stores user credentials in plain text which can be read by an authenticated user with access to the pod.

  • CVE-2023-48700MedNov 21, 2023
    risk 0.37cvss 5.7epss 0.00

    The Nautobot Device Onboarding plugin uses the netmiko and NAPALM libraries to simplify the onboarding process of a new device into Nautobot down to, in many cases, an IP Address and a Location. Starting in version 2.0.0 and prior to version 3.0.0, credentials provided to…

  • CVE-2023-22389MedJan 30, 2023
    risk 0.37cvss 5.7epss 0.00

    Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior store passwords in a plaintext file when the device configuration is exported via Save/Restore–>Backup Settings, which could be read by any user accessing the file.  

  • CVE-2024-42197MedDec 11, 2025
    risk 0.36cvss 5.5epss 0.00

    HCL Workload Scheduler stores user credentials in plain text which can be read by a local user.

  • CVE-2025-11193MedNov 3, 2025
    risk 0.36cvss 5.5epss 0.00

    A potential vulnerability was reported in some Lenovo Tablets that could allow a local authenticated user or application to gain access to sensitive device specific information.

  • CVE-2025-36002MedOct 16, 2025
    risk 0.36cvss 5.5epss 0.00

    IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5, and 6.2.1.0 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5, and 6.2.1.0 stores user credentials in configuration files which can be read by a local user.

  • CVE-2025-34210MedOct 2, 2025
    risk 0.36cvss 5.5epss 0.00

    Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA/SaaS deployments) store a large number of sensitive credentials (database passwords, MySQL root password, SaaS keys, Portainer admin password, etc.) in cleartext files that are world-readable. Any…

  • CVE-2024-49351MedNov 26, 2024
    risk 0.36cvss 5.5epss 0.00

    IBM Workload Scheduler 9.5, 10.1, and 10.2 stores user credentials in plain text which can be read by a local user.

  • CVE-2024-25024MedAug 15, 2024
    risk 0.36cvss 5.5epss 0.00

    IBM QRadar Suite Software 1.10.12.0 through 1.10.23.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 281430.