CWE-260
Password in Configuration File
Description
The product stores a password in a configuration file that might be accessible to actors who do not know the password.
Hierarchy (View 1000)
CVEs mapped to this weakness (24)
page 2 of 2| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-15151 | Low | 0.24 | 3.7 | 0.00 | Dec 28, 2025 | A vulnerability was determined in TaleLin Lin-CMS up to 0.6.0. This affects an unknown part of the file /tests/config.py of the component Tests Folder. This manipulation of the argument username/password causes password in configuration file. The attack is possible to be carried… | ||
| CVE-2023-2790 | Low | 0.15 | 2.3 | 0.00 | May 18, 2023 | A vulnerability classified as problematic has been found in TOTOLINK N200RE 9.3.5u.6255_B20211224. Affected is an unknown function of the file /squashfs-root/etc_ro/custom.conf of the component Telnet Service. The manipulation leads to password in configuration file. It is… | ||
| CVE-2016-7043 | Med | 0.00 | 5.9 | 0.02 | May 15, 2019 | It has been reported that KIE server and Busitess Central before version 7.21.0.Final contain username and password as plaintext Java properties. Any app deployed on the same server would have access to these properties, thus granting access to ther services. | ||
| CVE-2014-5400 | 0.00 | — | 0.00 | Apr 3, 2015 | The installation component in Hospira MedNet before 6.1 places cleartext credentials in configuration files, which allows local users to obtain sensitive information by reading a file. |
- risk 0.24cvss 3.7epss 0.00
A vulnerability was determined in TaleLin Lin-CMS up to 0.6.0. This affects an unknown part of the file /tests/config.py of the component Tests Folder. This manipulation of the argument username/password causes password in configuration file. The attack is possible to be carried…
- risk 0.15cvss 2.3epss 0.00
A vulnerability classified as problematic has been found in TOTOLINK N200RE 9.3.5u.6255_B20211224. Affected is an unknown function of the file /squashfs-root/etc_ro/custom.conf of the component Telnet Service. The manipulation leads to password in configuration file. It is…
- risk 0.00cvss 5.9epss 0.02
It has been reported that KIE server and Busitess Central before version 7.21.0.Final contain username and password as plaintext Java properties. Any app deployed on the same server would have access to these properties, thus granting access to ther services.
- CVE-2014-5400Apr 3, 2015risk 0.00cvss —epss 0.00
The installation component in Hospira MedNet before 6.1 places cleartext credentials in configuration files, which allows local users to obtain sensitive information by reading a file.