VYPR

CWE-312

Cleartext Storage of Sensitive Information

BaseDraft

Description

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-37

CVEs mapped to this weakness (848)

page 11 of 43
  • CVE-2021-27757HigMar 4, 2022
    risk 0.49cvss 7.5epss 0.01

    " Insecure password storage issue.The application stores sensitive information in cleartext within a resource that might be accessible to another control sphere.Since the information is stored in cleartext, attackers could potentially read it and gain access to sensitive…

  • CVE-2021-42642HigFeb 2, 2022
    risk 0.49cvss 7.5epss 0.01

    PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an unauthenticated attacker to disclose the plaintext console username and password for a printer.

  • CVE-2021-45077HigDec 30, 2021
    risk 0.49cvss 7.5epss 0.01

    Netgear Nighthawk R6700 version 1.0.4.120 stores sensitive information in plaintext. All usernames and passwords for the device's associated services are stored in plaintext on the device. For example, the admin password is stored in plaintext in the primary configuration file…

  • CVE-2021-20827HigDec 24, 2021
    risk 0.49cvss 7.5epss 0.01

    Plaintext storage of a password vulnerability in IDEC PLCs (FC6A Series MICROSmart All-in-One CPU module v2.32 and earlier, FC6A Series MICROSmart Plus CPU module v1.91 and earlier, WindLDR v8.19.1 and earlier, WindEDIT Lite v1.3.1 and earlier, and Data File Manager v2.12.1 and…

  • CVE-2021-43388HigDec 14, 2021
    risk 0.49cvss 7.5epss 0.01

    Unisys Cargo Mobile Application before 1.2.29 uses cleartext to store sensitive information, which might be revealed in a backup. The issue is addressed by ensuring that the allowBackup flag (in the manifest) is False.

  • CVE-2021-42370HigNov 8, 2021
    risk 0.49cvss 7.5epss 0.01

    A password mismanagement situation exists in XoruX LPAR2RRD and STOR2RRD before 7.30 because cleartext information is present in HTML password input fields in the device properties. (Viewing the passwords requires configuring a web browser to display HTML password input fields.)

  • CVE-2021-42763HigNov 2, 2021
    risk 0.49cvss 7.5epss 0.01

    Couchbase Server before 6.6.3 and 7.x before 7.0.2 stores Sensitive Information in Cleartext. The issue occurs when the cluster manager forwards a HTTP request from the pluggable UI (query workbench etc) to the specific service. In the backtrace, the Basic Auth Header included…

  • CVE-2021-37842HigNov 2, 2021
    risk 0.49cvss 7.5epss 0.01

    metakv in Couchbase Server 7.0.0 uses Cleartext for Storage of Sensitive Information. Remote Cluster XDCR credentials can get leaked in debug logs. Config key tombstone purging was added in Couchbase Server 7.0.0. This issue happens when a config key, which is being logged, has…

  • CVE-2020-19137HigSep 8, 2021
    risk 0.49cvss 7.5epss 0.01

    Incorrect Access Control in Autumn v1.0.4 and earlier allows remote attackers to obtain clear-text login credentials via the component "autumn-cms/user/getAllUser/?page=1&limit=10".

  • CVE-2021-30997HigAug 24, 2021
    risk 0.49cvss 7.5epss 0.01

    A S/MIME issue existed in the handling of encrypted email. This issue was addressed by not automatically loading some MIME parts. This issue is fixed in iOS 15.2 and iPadOS 15.2. An attacker may be able to recover plaintext contents of an S/MIME-encrypted e-mail.

  • CVE-2021-31820HigAug 18, 2021
    risk 0.49cvss 7.5epss 0.01

    In Octopus Server after version 2018.8.2 if the Octopus Server Web Request Proxy is configured with authentication, the password is shown in plaintext in the UI.

  • CVE-2020-18759HigAug 13, 2021
    risk 0.49cvss 7.5epss 0.01

    An information disclosure vulnerability exists in the EPA protocol of Dut Computer Control Engineering Co.'s PLC MAC1100.

  • CVE-2021-37548HigAug 6, 2021
    risk 0.49cvss 7.5epss 0.01

    In JetBrains TeamCity before 2021.1, passwords in cleartext sometimes could be stored in VCS.

  • CVE-2021-33323HigAug 3, 2021
    risk 0.49cvss 7.5epss 0.01

    The Dynamic Data Mapping module in Liferay Portal 7.1.0 through 7.3.2, and Liferay DXP 7.1 before fix pack 19, and 7.2 before fix pack 7, autosaves form values for unauthenticated users, which allows remote attackers to view the autosaved values by viewing the form as an…

  • CVE-2020-22741HigJul 19, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Xuperchain 3.6.0 that allows for attackers to recover any arbitrary users' private key after obtaining the partial signature in multisignature.

  • CVE-2020-12731HigJul 15, 2021
    risk 0.49cvss 7.5epss 0.01

    The MagicMotion Flamingo 2 application for Android stores data on an sdcard under com.vt.magicmotion/files/Pictures, whence it can be read by other applications.

  • CVE-2021-31817HigJul 8, 2021
    risk 0.49cvss 7.5epss 0.01

    When configuring Octopus Server if it is configured with an external SQL database, on initial configuration the database password is written to the OctopusServer.txt log file in plaintext.

  • CVE-2021-31816HigJul 8, 2021
    risk 0.49cvss 7.5epss 0.01

    When configuring Octopus Server if it is configured with an external SQL database, on initial configuration the database password is written to the OctopusServer.txt log file in plaintext.

  • CVE-2021-29950HigJun 24, 2021
    risk 0.49cvss 7.5epss 0.01

    Thunderbird unprotects a secret OpenPGP key prior to using it for a decryption, signing or key import task. If the task runs into a failure, the secret key may remain in memory in its unprotected state. This vulnerability affects Thunderbird < 78.8.1.

  • CVE-2020-29324HigJun 4, 2021
    risk 0.49cvss 7.5epss 0.01

    The DLink Router DIR-895L MFC v1.21b05 is vulnerable to credentials disclosure in telnet service through decompilation of firmware, that allows an unauthenticated attacker to gain access to the firmware and to extract sensitive data.