VYPR

CWE-312

Cleartext Storage of Sensitive Information

BaseDraft

Description

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-37

CVEs mapped to this weakness (886)

page 10 of 45
  • CVE-2023-39144HigAug 3, 2023
    risk 0.49cvss 7.5epss 0.01

    Element55 KnowMore appliances version 21 and older was discovered to store passwords in plaintext.

  • CVE-2023-33742HigJul 27, 2023
    risk 0.49cvss 7.5epss 0.01

    TeleAdapt RoomCast TA-2400 1.0 through 3.1 suffers from Cleartext Storage of Sensitive Information: RSA private key in Update.exe.

  • CVE-2023-30367HigJul 26, 2023
    risk 0.49cvss 7.5epss 0.00

    Multi-Remote Next Generation Connection Manager (mRemoteNG) is free software that enables users to store and manage multi-protocol connection configurations to remotely connect to systems. mRemoteNG configuration files can be stored in an encrypted state on disk. mRemoteNG…

  • CVE-2023-31821HigJul 13, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue found in ALBIS Co. ALBIS v.13.6.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp ALBIS function.

  • CVE-2023-27243HigJun 21, 2023
    risk 0.49cvss 7.5epss 0.00

    An access control issue in Makves DCAP v3.0.0.122 allows unauthenticated attackers to obtain cleartext credentials via a crafted web request to the product API.

  • CVE-2023-22584HigJun 11, 2023
    risk 0.49cvss 7.5epss 0.00

    The Danfoss AK-EM100 stores login credentials in cleartext.

  • CVE-2023-29480HigApr 24, 2023
    risk 0.49cvss 7.5epss 0.00

    Ribose RNP before 0.16.3 sometimes lets secret keys remain unlocked after use.

  • CVE-2023-31043HigApr 23, 2023
    risk 0.49cvss 7.5epss 0.00

    EnterpriseDB EDB Postgres Advanced Server (EPAS) before 14.6.0 logs unredacted passwords in situations where optional parameters are used with CREATE/ALTER USER/GROUP/ROLE, and redacting was configured with edb_filter_log.redact_password_commands. The fixed versions are…

  • CVE-2023-26760HigFeb 27, 2023
    risk 0.49cvss 7.5epss 0.01

    Sme.UP ERP TOKYO V6R1M220406 was discovered to contain an information disclosure vulnerability via the /debug endpoint. This vulnerability allows attackers to access cleartext credentials needed to authenticate to the AS400 system.

  • CVE-2022-48073HigJan 27, 2023
    risk 0.49cvss 7.5epss 0.00

    Phicomm K2G v22.6.3.20 was discovered to store the root and admin passwords in plaintext.

  • CVE-2022-48071HigJan 27, 2023
    risk 0.49cvss 7.5epss 0.00

    Phicomm K2 v22.6.534.263 was discovered to store the root and admin passwords in plaintext.

  • CVE-2022-38112HigJan 20, 2023
    risk 0.49cvss 7.5epss 0.00

    In DPA 2022.4 and older releases, generated heap memory dumps contain sensitive information in cleartext.

  • CVE-2022-37785HigJan 1, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in WeCube Platform 3.2.2. Cleartext passwords are displayed in the configuration for terminal plugins.

  • CVE-2022-24188HigNov 28, 2022
    risk 0.49cvss 7.5epss 0.00

    The /device/signin end-point for the Ourphoto App version 1.4.1 discloses clear-text password information for functionality within the picture frame devices. The deviceVideoCallPassword and mqttPassword are returned in clear-text. The lack of sessions management and presence of…

  • CVE-2022-43958HigNov 8, 2022
    risk 0.49cvss 7.6epss 0.00

    A vulnerability has been identified in QMS Automotive (All versions < V12.39), QMS Automotive (All versions < V12.39). User credentials are stored in plaintext in the database without any hashing mechanism. This could allow an attacker to gain access to credentials and…

  • CVE-2022-42956HigNov 7, 2022
    risk 0.49cvss 7.5epss 0.00

    The PassWork extension 5.0.9 for Chrome and other browsers allows an attacker to obtain the cleartext master password.

  • CVE-2022-42955HigNov 7, 2022
    risk 0.49cvss 7.5epss 0.00

    The PassWork extension 5.0.9 for Chrome and other browsers allows an attacker to obtain cleartext cached credentials.

  • CVE-2022-37857HigSep 8, 2022
    risk 0.49cvss 7.5epss 0.00

    bilde2910 Hauk v1.6.1 requires a hardcoded password which by default is blank. This hardcoded password is hashed but stored within the config.php file server-side as well as in clear-text on the android client device by default.

  • CVE-2022-34924HigAug 2, 2022
    risk 0.49cvss 7.5epss 0.01

    Lanling OA Landray Office Automation (OA) internal patch number #133383/#137780 contains an arbitrary file read vulnerability via the component /sys/ui/extend/varkind/custom.jsp.

  • CVE-2022-31205HigJul 26, 2022
    risk 0.49cvss 7.5epss 0.01

    In Omron CS series, CJ series, and CP series PLCs through 2022-05-18, the password for access to the Web UI is stored in memory area D1449...D1452 and can be read out using the Omron FINS protocol without any further authentication.