VYPR

CWE-260

Password in Configuration File

BaseIncomplete

Description

The product stores a password in a configuration file that might be accessible to actors who do not know the password.

This can result in compromise of the system for which the password is used. An attacker could gain access to this file and learn the stored password or worse yet, change the password to one of their choosing.

Hierarchy (View 1000)

CVEs mapped to this weakness (24)

page 2 of 2
  • CVE-2025-15151LowDec 28, 2025
    risk 0.24cvss 3.7epss 0.00

    A vulnerability was determined in TaleLin Lin-CMS up to 0.6.0. This affects an unknown part of the file /tests/config.py of the component Tests Folder. This manipulation of the argument username/password causes password in configuration file. The attack is possible to be carried…

  • CVE-2023-2790LowMay 18, 2023
    risk 0.15cvss 2.3epss 0.00

    A vulnerability classified as problematic has been found in TOTOLINK N200RE 9.3.5u.6255_B20211224. Affected is an unknown function of the file /squashfs-root/etc_ro/custom.conf of the component Telnet Service. The manipulation leads to password in configuration file. It is…

  • CVE-2016-7043MedMay 15, 2019
    risk 0.00cvss 5.9epss 0.02

    It has been reported that KIE server and Busitess Central before version 7.21.0.Final contain username and password as plaintext Java properties. Any app deployed on the same server would have access to these properties, thus granting access to ther services.

  • CVE-2014-5400Apr 3, 2015
    risk 0.00cvss epss 0.00

    The installation component in Hospira MedNet before 6.1 places cleartext credentials in configuration files, which allows local users to obtain sensitive information by reading a file.