CWE-312
Cleartext Storage of Sensitive Information
Description
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-37
CVEs mapped to this weakness (848)
page 10 of 43| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-22584 | Hig | 0.49 | 7.5 | 0.00 | Jun 11, 2023 | The Danfoss AK-EM100 stores login credentials in cleartext. | ||
| CVE-2023-29480 | Hig | 0.49 | 7.5 | 0.00 | Apr 24, 2023 | Ribose RNP before 0.16.3 sometimes lets secret keys remain unlocked after use. | ||
| CVE-2023-31043 | Hig | 0.49 | 7.5 | 0.00 | Apr 23, 2023 | EnterpriseDB EDB Postgres Advanced Server (EPAS) before 14.6.0 logs unredacted passwords in situations where optional parameters are used with CREATE/ALTER USER/GROUP/ROLE, and redacting was configured with edb_filter_log.redact_password_commands. The fixed versions are… | ||
| CVE-2023-26760 | Hig | 0.49 | 7.5 | 0.01 | Feb 27, 2023 | Sme.UP ERP TOKYO V6R1M220406 was discovered to contain an information disclosure vulnerability via the /debug endpoint. This vulnerability allows attackers to access cleartext credentials needed to authenticate to the AS400 system. | ||
| CVE-2022-48073 | Hig | 0.49 | 7.5 | 0.00 | Jan 27, 2023 | Phicomm K2G v22.6.3.20 was discovered to store the root and admin passwords in plaintext. | ||
| CVE-2022-48071 | Hig | 0.49 | 7.5 | 0.00 | Jan 27, 2023 | Phicomm K2 v22.6.534.263 was discovered to store the root and admin passwords in plaintext. | ||
| CVE-2022-38112 | Hig | 0.49 | 7.5 | 0.00 | Jan 20, 2023 | In DPA 2022.4 and older releases, generated heap memory dumps contain sensitive information in cleartext. | ||
| CVE-2022-37785 | Hig | 0.49 | 7.5 | 0.01 | Jan 1, 2023 | An issue was discovered in WeCube Platform 3.2.2. Cleartext passwords are displayed in the configuration for terminal plugins. | ||
| CVE-2022-24188 | Hig | 0.49 | 7.5 | 0.00 | Nov 28, 2022 | The /device/signin end-point for the Ourphoto App version 1.4.1 discloses clear-text password information for functionality within the picture frame devices. The deviceVideoCallPassword and mqttPassword are returned in clear-text. The lack of sessions management and presence of… | ||
| CVE-2022-43958 | Hig | 0.49 | 7.6 | 0.00 | Nov 8, 2022 | A vulnerability has been identified in QMS Automotive (All versions < V12.39), QMS Automotive (All versions < V12.39). User credentials are stored in plaintext in the database without any hashing mechanism. This could allow an attacker to gain access to credentials and… | ||
| CVE-2022-42956 | Hig | 0.49 | 7.5 | 0.00 | Nov 7, 2022 | The PassWork extension 5.0.9 for Chrome and other browsers allows an attacker to obtain the cleartext master password. | ||
| CVE-2022-42955 | Hig | 0.49 | 7.5 | 0.00 | Nov 7, 2022 | The PassWork extension 5.0.9 for Chrome and other browsers allows an attacker to obtain cleartext cached credentials. | ||
| CVE-2022-37857 | Hig | 0.49 | 7.5 | 0.00 | Sep 8, 2022 | bilde2910 Hauk v1.6.1 requires a hardcoded password which by default is blank. This hardcoded password is hashed but stored within the config.php file server-side as well as in clear-text on the android client device by default. | ||
| CVE-2022-34924 | Hig | 0.49 | 7.5 | 0.01 | Aug 2, 2022 | Lanling OA Landray Office Automation (OA) internal patch number #133383/#137780 contains an arbitrary file read vulnerability via the component /sys/ui/extend/varkind/custom.jsp. | ||
| CVE-2022-31205 | Hig | 0.49 | 7.5 | 0.01 | Jul 26, 2022 | In Omron CS series, CJ series, and CP series PLCs through 2022-05-18, the password for access to the Web UI is stored in memory area D1449...D1452 and can be read out using the Omron FINS protocol without any further authentication. | ||
| CVE-2022-30275 | Hig | 0.49 | 7.5 | 0.01 | Jul 26, 2022 | The Motorola MOSCAD Toolbox software through 2022-05-02 relies on a cleartext password. It utilizes an MDLC driver to communicate with MOSCAD/ACE RTUs for engineering purposes. Access to these communications is protected by a password stored in cleartext in the wmdlcdrv.ini… | ||
| CVE-2022-24660 | Hig | 0.49 | 7.5 | 0.01 | Jul 20, 2022 | The debug interface of Goldshell ASIC Miners v2.2.1 and below was discovered to be exposed publicly on the web interface, allowing attackers to access passwords and other sensitive information in plaintext. | ||
| CVE-2021-45025 | Hig | 0.49 | 7.5 | 0.01 | Jun 17, 2022 | ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to Cleartext Storage of Sensitive Information in a Cookie. | ||
| CVE-2022-31004 | Hig | 0.49 | 7.5 | 0.01 | Jun 2, 2022 | CVEProject/cve-services is an open source project used to operate the CVE services API. A conditional in 'data.js' has potential for production secrets to be written to disk. The affected method writes the generated randomKey to disk if the environment is not development. If… | ||
| CVE-2021-27757 | Hig | 0.49 | 7.5 | 0.01 | Mar 4, 2022 | " Insecure password storage issue.The application stores sensitive information in cleartext within a resource that might be accessible to another control sphere.Since the information is stored in cleartext, attackers could potentially read it and gain access to sensitive… |
- risk 0.49cvss 7.5epss 0.00
The Danfoss AK-EM100 stores login credentials in cleartext.
- risk 0.49cvss 7.5epss 0.00
Ribose RNP before 0.16.3 sometimes lets secret keys remain unlocked after use.
- risk 0.49cvss 7.5epss 0.00
EnterpriseDB EDB Postgres Advanced Server (EPAS) before 14.6.0 logs unredacted passwords in situations where optional parameters are used with CREATE/ALTER USER/GROUP/ROLE, and redacting was configured with edb_filter_log.redact_password_commands. The fixed versions are…
- risk 0.49cvss 7.5epss 0.01
Sme.UP ERP TOKYO V6R1M220406 was discovered to contain an information disclosure vulnerability via the /debug endpoint. This vulnerability allows attackers to access cleartext credentials needed to authenticate to the AS400 system.
- risk 0.49cvss 7.5epss 0.00
Phicomm K2G v22.6.3.20 was discovered to store the root and admin passwords in plaintext.
- risk 0.49cvss 7.5epss 0.00
Phicomm K2 v22.6.534.263 was discovered to store the root and admin passwords in plaintext.
- risk 0.49cvss 7.5epss 0.00
In DPA 2022.4 and older releases, generated heap memory dumps contain sensitive information in cleartext.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in WeCube Platform 3.2.2. Cleartext passwords are displayed in the configuration for terminal plugins.
- risk 0.49cvss 7.5epss 0.00
The /device/signin end-point for the Ourphoto App version 1.4.1 discloses clear-text password information for functionality within the picture frame devices. The deviceVideoCallPassword and mqttPassword are returned in clear-text. The lack of sessions management and presence of…
- risk 0.49cvss 7.6epss 0.00
A vulnerability has been identified in QMS Automotive (All versions < V12.39), QMS Automotive (All versions < V12.39). User credentials are stored in plaintext in the database without any hashing mechanism. This could allow an attacker to gain access to credentials and…
- risk 0.49cvss 7.5epss 0.00
The PassWork extension 5.0.9 for Chrome and other browsers allows an attacker to obtain the cleartext master password.
- risk 0.49cvss 7.5epss 0.00
The PassWork extension 5.0.9 for Chrome and other browsers allows an attacker to obtain cleartext cached credentials.
- risk 0.49cvss 7.5epss 0.00
bilde2910 Hauk v1.6.1 requires a hardcoded password which by default is blank. This hardcoded password is hashed but stored within the config.php file server-side as well as in clear-text on the android client device by default.
- risk 0.49cvss 7.5epss 0.01
Lanling OA Landray Office Automation (OA) internal patch number #133383/#137780 contains an arbitrary file read vulnerability via the component /sys/ui/extend/varkind/custom.jsp.
- risk 0.49cvss 7.5epss 0.01
In Omron CS series, CJ series, and CP series PLCs through 2022-05-18, the password for access to the Web UI is stored in memory area D1449...D1452 and can be read out using the Omron FINS protocol without any further authentication.
- risk 0.49cvss 7.5epss 0.01
The Motorola MOSCAD Toolbox software through 2022-05-02 relies on a cleartext password. It utilizes an MDLC driver to communicate with MOSCAD/ACE RTUs for engineering purposes. Access to these communications is protected by a password stored in cleartext in the wmdlcdrv.ini…
- risk 0.49cvss 7.5epss 0.01
The debug interface of Goldshell ASIC Miners v2.2.1 and below was discovered to be exposed publicly on the web interface, allowing attackers to access passwords and other sensitive information in plaintext.
- risk 0.49cvss 7.5epss 0.01
ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to Cleartext Storage of Sensitive Information in a Cookie.
- risk 0.49cvss 7.5epss 0.01
CVEProject/cve-services is an open source project used to operate the CVE services API. A conditional in 'data.js' has potential for production secrets to be written to disk. The affected method writes the generated randomKey to disk if the environment is not development. If…
- risk 0.49cvss 7.5epss 0.01
" Insecure password storage issue.The application stores sensitive information in cleartext within a resource that might be accessible to another control sphere.Since the information is stored in cleartext, attackers could potentially read it and gain access to sensitive…