VYPR

CWE-312

Cleartext Storage of Sensitive Information

BaseDraft

Description

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-37

CVEs mapped to this weakness (848)

page 10 of 43
  • CVE-2023-22584HigJun 11, 2023
    risk 0.49cvss 7.5epss 0.00

    The Danfoss AK-EM100 stores login credentials in cleartext.

  • CVE-2023-29480HigApr 24, 2023
    risk 0.49cvss 7.5epss 0.00

    Ribose RNP before 0.16.3 sometimes lets secret keys remain unlocked after use.

  • CVE-2023-31043HigApr 23, 2023
    risk 0.49cvss 7.5epss 0.00

    EnterpriseDB EDB Postgres Advanced Server (EPAS) before 14.6.0 logs unredacted passwords in situations where optional parameters are used with CREATE/ALTER USER/GROUP/ROLE, and redacting was configured with edb_filter_log.redact_password_commands. The fixed versions are…

  • CVE-2023-26760HigFeb 27, 2023
    risk 0.49cvss 7.5epss 0.01

    Sme.UP ERP TOKYO V6R1M220406 was discovered to contain an information disclosure vulnerability via the /debug endpoint. This vulnerability allows attackers to access cleartext credentials needed to authenticate to the AS400 system.

  • CVE-2022-48073HigJan 27, 2023
    risk 0.49cvss 7.5epss 0.00

    Phicomm K2G v22.6.3.20 was discovered to store the root and admin passwords in plaintext.

  • CVE-2022-48071HigJan 27, 2023
    risk 0.49cvss 7.5epss 0.00

    Phicomm K2 v22.6.534.263 was discovered to store the root and admin passwords in plaintext.

  • CVE-2022-38112HigJan 20, 2023
    risk 0.49cvss 7.5epss 0.00

    In DPA 2022.4 and older releases, generated heap memory dumps contain sensitive information in cleartext.

  • CVE-2022-37785HigJan 1, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in WeCube Platform 3.2.2. Cleartext passwords are displayed in the configuration for terminal plugins.

  • CVE-2022-24188HigNov 28, 2022
    risk 0.49cvss 7.5epss 0.00

    The /device/signin end-point for the Ourphoto App version 1.4.1 discloses clear-text password information for functionality within the picture frame devices. The deviceVideoCallPassword and mqttPassword are returned in clear-text. The lack of sessions management and presence of…

  • CVE-2022-43958HigNov 8, 2022
    risk 0.49cvss 7.6epss 0.00

    A vulnerability has been identified in QMS Automotive (All versions < V12.39), QMS Automotive (All versions < V12.39). User credentials are stored in plaintext in the database without any hashing mechanism. This could allow an attacker to gain access to credentials and…

  • CVE-2022-42956HigNov 7, 2022
    risk 0.49cvss 7.5epss 0.00

    The PassWork extension 5.0.9 for Chrome and other browsers allows an attacker to obtain the cleartext master password.

  • CVE-2022-42955HigNov 7, 2022
    risk 0.49cvss 7.5epss 0.00

    The PassWork extension 5.0.9 for Chrome and other browsers allows an attacker to obtain cleartext cached credentials.

  • CVE-2022-37857HigSep 8, 2022
    risk 0.49cvss 7.5epss 0.00

    bilde2910 Hauk v1.6.1 requires a hardcoded password which by default is blank. This hardcoded password is hashed but stored within the config.php file server-side as well as in clear-text on the android client device by default.

  • CVE-2022-34924HigAug 2, 2022
    risk 0.49cvss 7.5epss 0.01

    Lanling OA Landray Office Automation (OA) internal patch number #133383/#137780 contains an arbitrary file read vulnerability via the component /sys/ui/extend/varkind/custom.jsp.

  • CVE-2022-31205HigJul 26, 2022
    risk 0.49cvss 7.5epss 0.01

    In Omron CS series, CJ series, and CP series PLCs through 2022-05-18, the password for access to the Web UI is stored in memory area D1449...D1452 and can be read out using the Omron FINS protocol without any further authentication.

  • CVE-2022-30275HigJul 26, 2022
    risk 0.49cvss 7.5epss 0.01

    The Motorola MOSCAD Toolbox software through 2022-05-02 relies on a cleartext password. It utilizes an MDLC driver to communicate with MOSCAD/ACE RTUs for engineering purposes. Access to these communications is protected by a password stored in cleartext in the wmdlcdrv.ini…

  • CVE-2022-24660HigJul 20, 2022
    risk 0.49cvss 7.5epss 0.01

    The debug interface of Goldshell ASIC Miners v2.2.1 and below was discovered to be exposed publicly on the web interface, allowing attackers to access passwords and other sensitive information in plaintext.

  • CVE-2021-45025HigJun 17, 2022
    risk 0.49cvss 7.5epss 0.01

    ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to Cleartext Storage of Sensitive Information in a Cookie.

  • CVE-2022-31004HigJun 2, 2022
    risk 0.49cvss 7.5epss 0.01

    CVEProject/cve-services is an open source project used to operate the CVE services API. A conditional in 'data.js' has potential for production secrets to be written to disk. The affected method writes the generated randomKey to disk if the environment is not development. If…

  • CVE-2021-27757HigMar 4, 2022
    risk 0.49cvss 7.5epss 0.01

    " Insecure password storage issue.The application stores sensitive information in cleartext within a resource that might be accessible to another control sphere.Since the information is stored in cleartext, attackers could potentially read it and gain access to sensitive…