CWE-312
Cleartext Storage of Sensitive Information
Description
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-37
CVEs mapped to this weakness (886)
page 10 of 45| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-39144 | Hig | 0.49 | 7.5 | 0.01 | Aug 3, 2023 | Element55 KnowMore appliances version 21 and older was discovered to store passwords in plaintext. | ||
| CVE-2023-33742 | Hig | 0.49 | 7.5 | 0.01 | Jul 27, 2023 | TeleAdapt RoomCast TA-2400 1.0 through 3.1 suffers from Cleartext Storage of Sensitive Information: RSA private key in Update.exe. | ||
| CVE-2023-30367 | Hig | 0.49 | 7.5 | 0.00 | Jul 26, 2023 | Multi-Remote Next Generation Connection Manager (mRemoteNG) is free software that enables users to store and manage multi-protocol connection configurations to remotely connect to systems. mRemoteNG configuration files can be stored in an encrypted state on disk. mRemoteNG… | ||
| CVE-2023-31821 | Hig | 0.49 | 7.5 | 0.01 | Jul 13, 2023 | An issue found in ALBIS Co. ALBIS v.13.6.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp ALBIS function. | ||
| CVE-2023-27243 | Hig | 0.49 | 7.5 | 0.00 | Jun 21, 2023 | An access control issue in Makves DCAP v3.0.0.122 allows unauthenticated attackers to obtain cleartext credentials via a crafted web request to the product API. | ||
| CVE-2023-22584 | Hig | 0.49 | 7.5 | 0.00 | Jun 11, 2023 | The Danfoss AK-EM100 stores login credentials in cleartext. | ||
| CVE-2023-29480 | Hig | 0.49 | 7.5 | 0.00 | Apr 24, 2023 | Ribose RNP before 0.16.3 sometimes lets secret keys remain unlocked after use. | ||
| CVE-2023-31043 | Hig | 0.49 | 7.5 | 0.00 | Apr 23, 2023 | EnterpriseDB EDB Postgres Advanced Server (EPAS) before 14.6.0 logs unredacted passwords in situations where optional parameters are used with CREATE/ALTER USER/GROUP/ROLE, and redacting was configured with edb_filter_log.redact_password_commands. The fixed versions are… | ||
| CVE-2023-26760 | Hig | 0.49 | 7.5 | 0.01 | Feb 27, 2023 | Sme.UP ERP TOKYO V6R1M220406 was discovered to contain an information disclosure vulnerability via the /debug endpoint. This vulnerability allows attackers to access cleartext credentials needed to authenticate to the AS400 system. | ||
| CVE-2022-48073 | Hig | 0.49 | 7.5 | 0.00 | Jan 27, 2023 | Phicomm K2G v22.6.3.20 was discovered to store the root and admin passwords in plaintext. | ||
| CVE-2022-48071 | Hig | 0.49 | 7.5 | 0.00 | Jan 27, 2023 | Phicomm K2 v22.6.534.263 was discovered to store the root and admin passwords in plaintext. | ||
| CVE-2022-38112 | Hig | 0.49 | 7.5 | 0.00 | Jan 20, 2023 | In DPA 2022.4 and older releases, generated heap memory dumps contain sensitive information in cleartext. | ||
| CVE-2022-37785 | Hig | 0.49 | 7.5 | 0.01 | Jan 1, 2023 | An issue was discovered in WeCube Platform 3.2.2. Cleartext passwords are displayed in the configuration for terminal plugins. | ||
| CVE-2022-24188 | Hig | 0.49 | 7.5 | 0.00 | Nov 28, 2022 | The /device/signin end-point for the Ourphoto App version 1.4.1 discloses clear-text password information for functionality within the picture frame devices. The deviceVideoCallPassword and mqttPassword are returned in clear-text. The lack of sessions management and presence of… | ||
| CVE-2022-43958 | Hig | 0.49 | 7.6 | 0.00 | Nov 8, 2022 | A vulnerability has been identified in QMS Automotive (All versions < V12.39), QMS Automotive (All versions < V12.39). User credentials are stored in plaintext in the database without any hashing mechanism. This could allow an attacker to gain access to credentials and… | ||
| CVE-2022-42956 | Hig | 0.49 | 7.5 | 0.00 | Nov 7, 2022 | The PassWork extension 5.0.9 for Chrome and other browsers allows an attacker to obtain the cleartext master password. | ||
| CVE-2022-42955 | Hig | 0.49 | 7.5 | 0.00 | Nov 7, 2022 | The PassWork extension 5.0.9 for Chrome and other browsers allows an attacker to obtain cleartext cached credentials. | ||
| CVE-2022-37857 | Hig | 0.49 | 7.5 | 0.00 | Sep 8, 2022 | bilde2910 Hauk v1.6.1 requires a hardcoded password which by default is blank. This hardcoded password is hashed but stored within the config.php file server-side as well as in clear-text on the android client device by default. | ||
| CVE-2022-34924 | Hig | 0.49 | 7.5 | 0.01 | Aug 2, 2022 | Lanling OA Landray Office Automation (OA) internal patch number #133383/#137780 contains an arbitrary file read vulnerability via the component /sys/ui/extend/varkind/custom.jsp. | ||
| CVE-2022-31205 | Hig | 0.49 | 7.5 | 0.01 | Jul 26, 2022 | In Omron CS series, CJ series, and CP series PLCs through 2022-05-18, the password for access to the Web UI is stored in memory area D1449...D1452 and can be read out using the Omron FINS protocol without any further authentication. |
- risk 0.49cvss 7.5epss 0.01
Element55 KnowMore appliances version 21 and older was discovered to store passwords in plaintext.
- risk 0.49cvss 7.5epss 0.01
TeleAdapt RoomCast TA-2400 1.0 through 3.1 suffers from Cleartext Storage of Sensitive Information: RSA private key in Update.exe.
- risk 0.49cvss 7.5epss 0.00
Multi-Remote Next Generation Connection Manager (mRemoteNG) is free software that enables users to store and manage multi-protocol connection configurations to remotely connect to systems. mRemoteNG configuration files can be stored in an encrypted state on disk. mRemoteNG…
- risk 0.49cvss 7.5epss 0.01
An issue found in ALBIS Co. ALBIS v.13.6.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp ALBIS function.
- risk 0.49cvss 7.5epss 0.00
An access control issue in Makves DCAP v3.0.0.122 allows unauthenticated attackers to obtain cleartext credentials via a crafted web request to the product API.
- risk 0.49cvss 7.5epss 0.00
The Danfoss AK-EM100 stores login credentials in cleartext.
- risk 0.49cvss 7.5epss 0.00
Ribose RNP before 0.16.3 sometimes lets secret keys remain unlocked after use.
- risk 0.49cvss 7.5epss 0.00
EnterpriseDB EDB Postgres Advanced Server (EPAS) before 14.6.0 logs unredacted passwords in situations where optional parameters are used with CREATE/ALTER USER/GROUP/ROLE, and redacting was configured with edb_filter_log.redact_password_commands. The fixed versions are…
- risk 0.49cvss 7.5epss 0.01
Sme.UP ERP TOKYO V6R1M220406 was discovered to contain an information disclosure vulnerability via the /debug endpoint. This vulnerability allows attackers to access cleartext credentials needed to authenticate to the AS400 system.
- risk 0.49cvss 7.5epss 0.00
Phicomm K2G v22.6.3.20 was discovered to store the root and admin passwords in plaintext.
- risk 0.49cvss 7.5epss 0.00
Phicomm K2 v22.6.534.263 was discovered to store the root and admin passwords in plaintext.
- risk 0.49cvss 7.5epss 0.00
In DPA 2022.4 and older releases, generated heap memory dumps contain sensitive information in cleartext.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in WeCube Platform 3.2.2. Cleartext passwords are displayed in the configuration for terminal plugins.
- risk 0.49cvss 7.5epss 0.00
The /device/signin end-point for the Ourphoto App version 1.4.1 discloses clear-text password information for functionality within the picture frame devices. The deviceVideoCallPassword and mqttPassword are returned in clear-text. The lack of sessions management and presence of…
- risk 0.49cvss 7.6epss 0.00
A vulnerability has been identified in QMS Automotive (All versions < V12.39), QMS Automotive (All versions < V12.39). User credentials are stored in plaintext in the database without any hashing mechanism. This could allow an attacker to gain access to credentials and…
- risk 0.49cvss 7.5epss 0.00
The PassWork extension 5.0.9 for Chrome and other browsers allows an attacker to obtain the cleartext master password.
- risk 0.49cvss 7.5epss 0.00
The PassWork extension 5.0.9 for Chrome and other browsers allows an attacker to obtain cleartext cached credentials.
- risk 0.49cvss 7.5epss 0.00
bilde2910 Hauk v1.6.1 requires a hardcoded password which by default is blank. This hardcoded password is hashed but stored within the config.php file server-side as well as in clear-text on the android client device by default.
- risk 0.49cvss 7.5epss 0.01
Lanling OA Landray Office Automation (OA) internal patch number #133383/#137780 contains an arbitrary file read vulnerability via the component /sys/ui/extend/varkind/custom.jsp.
- risk 0.49cvss 7.5epss 0.01
In Omron CS series, CJ series, and CP series PLCs through 2022-05-18, the password for access to the Web UI is stored in memory area D1449...D1452 and can be read out using the Omron FINS protocol without any further authentication.