VYPR

CWE-312

Cleartext Storage of Sensitive Information

BaseDraft

Description

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-37

CVEs mapped to this weakness (848)

page 12 of 43
  • CVE-2021-25644HigMay 19, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Couchbase Server 5.x and 6.x through 6.6.1 and 7.0.0 Beta. Incorrect commands to the REST API can result in leaked authentication information being stored in cleartext in the debug.log and info.log files, and is also shown in the UI visible to…

  • CVE-2021-30183HigMay 14, 2021
    risk 0.49cvss 7.5epss 0.01

    Cleartext storage of sensitive information in multiple versions of Octopus Server where in certain situations when running import or export processes, the password used to encrypt and decrypt sensitive values would be written to the logs in plaintext.

  • CVE-2021-31791HigApr 23, 2021
    risk 0.49cvss 7.5epss 0.01

    In Hardware Sentry KM before 10.0.01 for BMC PATROL, a cleartext password may be discovered after a failure or timeout of a command.

  • CVE-2021-25898HigApr 23, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in svc-login.php in Void Aural Rec Monitor 9.0.0.1. Passwords are stored in unencrypted source-code text files. This was noted when accessing the svc-login.php file. The value is used to authenticate a high-privileged user upon authenticating with the…

  • CVE-2021-28937HigMar 29, 2021
    risk 0.49cvss 7.5epss 0.04

    The /password.html page of the Web management interface of the Acexy Wireless-N WiFi Repeater REV 1.0 (28.08.06.1) contains the administrator account password in plaintext. The page can be intercepted on HTTP.

  • CVE-2019-18630HigMar 4, 2021
    risk 0.49cvss 7.5epss 0.01

    On Xerox AltaLink B8045/B8055/B8065/B8075/B8090 and C8030/C8035/C8045/C8055/C8070 multifunction printers with software releases before 101.00x.099.28200, portions of the drive containing executable code were not encrypted thus leaving it open to potential cryptographic…

  • CVE-2020-5018HigJan 8, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may include sensitive information in its URLs increasing the risk of such information being caputured by an attacker. IBM X-Force ID: 193654.

  • CVE-2020-29502HigJan 5, 2021
    risk 0.49cvss 7.5epss 0.00

    Dell EMC PowerStore versions prior to 1.0.3.0.5.007 contain a Plain-Text Password Storage Vulnerability in PowerStore X & T environments. A locally authenticated attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The…

  • CVE-2020-29500HigJan 5, 2021
    risk 0.49cvss 7.5epss 0.00

    Dell EMC PowerStore versions prior to 1.0.3.0.5.007 contain a Plain-Text Password Storage Vulnerability in PowerStore T environments. A locally authenticated attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The…

  • CVE-2018-19941HigDec 31, 2020
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been reported to affect QNAP NAS. If exploited, this vulnerability allows an attacker to access sensitive information stored in cleartext inside cookies via certain widely-available tools. QNAP have already fixed this vulnerability in the following versions:…

  • CVE-2020-29550HigDec 23, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in URVE Build 24.03.2020. The password of an integration user account (used for the connection of the MS Office 365 Integration Service) is stored in cleartext in configuration files as well as in the database. The following files contain the password in…

  • CVE-2020-26551HigNov 17, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Aviatrix Controller before R5.3.1151. Encrypted key values are stored in a readable file.

  • CVE-2020-8225HigSep 18, 2020
    risk 0.49cvss 7.5epss 0.01

    A cleartext storage of sensitive information in Nextcloud Desktop Client 2.6.4 gave away information about used proxies and their authentication credentials.

  • CVE-2020-15484HigAug 26, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered on Nescomed Multipara Monitor M1000 devices. The internal storage of the underlying Linux system stores data in cleartext, without integrity protection against tampering.

  • CVE-2020-14017HigJun 24, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Navigate CMS 2.9 r1433. Sessions, as well as associated information such as CSRF tokens, are stored in cleartext files in the directory /private/sessions. An unauthenticated user could use a brute-force approach to attempt to identify existing…

  • CVE-2020-10273HigJun 24, 2020
    risk 0.49cvss 7.5epss 0.01

    MiR controllers across firmware versions 2.8.1.1 and before do not encrypt or protect in any way the intellectual property artifacts installed in the robots. This flaw allows attackers with access to the robot or the robot network (while in combination with other flaws) to…

  • CVE-2020-13637HigJun 17, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in the stashcat app through 3.9.2 for macOS, Windows, Android, iOS, and possibly other platforms. It stores the client_key, the device_id, and the public key for end-to-end encryption in cleartext, enabling an attacker (by copying or having access to the…

  • CVE-2020-7513HigJun 16, 2020
    risk 0.49cvss 7.5epss 0.01

    A CWE-312: Cleartext Storage of Sensitive Information vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to intercept traffic and read configuration data.

  • CVE-2020-13783HigJun 3, 2020
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-865L Ax 1.20B01 Beta devices have Cleartext Storage of Sensitive Information.

  • CVE-2020-11826HigApr 16, 2020
    risk 0.49cvss 7.5epss 0.01

    Users can lock their notes with a password in Memono version 3.8. Thus, users needs to know a password to read notes. However, these notes are stored in a database without encryption and an attacker can read the password-protected notes without having the password. Notes are…