VYPR

CWE-312

Cleartext Storage of Sensitive Information

BaseDraft

Description

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-37

CVEs mapped to this weakness (885)

page 12 of 45
  • CVE-2021-31817HigJul 8, 2021
    risk 0.49cvss 7.5epss 0.01

    When configuring Octopus Server if it is configured with an external SQL database, on initial configuration the database password is written to the OctopusServer.txt log file in plaintext.

  • CVE-2021-31816HigJul 8, 2021
    risk 0.49cvss 7.5epss 0.01

    When configuring Octopus Server if it is configured with an external SQL database, on initial configuration the database password is written to the OctopusServer.txt log file in plaintext.

  • CVE-2021-29950HigJun 24, 2021
    risk 0.49cvss 7.5epss 0.01

    Thunderbird unprotects a secret OpenPGP key prior to using it for a decryption, signing or key import task. If the task runs into a failure, the secret key may remain in memory in its unprotected state. This vulnerability affects Thunderbird < 78.8.1.

  • CVE-2020-29324HigJun 4, 2021
    risk 0.49cvss 7.5epss 0.01

    The DLink Router DIR-895L MFC v1.21b05 is vulnerable to credentials disclosure in telnet service through decompilation of firmware, that allows an unauthenticated attacker to gain access to the firmware and to extract sensitive data.

  • CVE-2021-25644HigMay 19, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Couchbase Server 5.x and 6.x through 6.6.1 and 7.0.0 Beta. Incorrect commands to the REST API can result in leaked authentication information being stored in cleartext in the debug.log and info.log files, and is also shown in the UI visible to…

  • CVE-2021-30183HigMay 14, 2021
    risk 0.49cvss 7.5epss 0.01

    Cleartext storage of sensitive information in multiple versions of Octopus Server where in certain situations when running import or export processes, the password used to encrypt and decrypt sensitive values would be written to the logs in plaintext.

  • CVE-2021-31791HigApr 23, 2021
    risk 0.49cvss 7.5epss 0.01

    In Hardware Sentry KM before 10.0.01 for BMC PATROL, a cleartext password may be discovered after a failure or timeout of a command.

  • CVE-2021-25898HigApr 23, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in svc-login.php in Void Aural Rec Monitor 9.0.0.1. Passwords are stored in unencrypted source-code text files. This was noted when accessing the svc-login.php file. The value is used to authenticate a high-privileged user upon authenticating with the…

  • CVE-2021-28937HigMar 29, 2021
    risk 0.49cvss 7.5epss 0.04

    The /password.html page of the Web management interface of the Acexy Wireless-N WiFi Repeater REV 1.0 (28.08.06.1) contains the administrator account password in plaintext. The page can be intercepted on HTTP.

  • CVE-2019-18630HigMar 4, 2021
    risk 0.49cvss 7.5epss 0.01

    On Xerox AltaLink B8045/B8055/B8065/B8075/B8090 and C8030/C8035/C8045/C8055/C8070 multifunction printers with software releases before 101.00x.099.28200, portions of the drive containing executable code were not encrypted thus leaving it open to potential cryptographic…

  • CVE-2020-5018HigJan 8, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may include sensitive information in its URLs increasing the risk of such information being caputured by an attacker. IBM X-Force ID: 193654.

  • CVE-2020-29502HigJan 5, 2021
    risk 0.49cvss 7.5epss 0.00

    Dell EMC PowerStore versions prior to 1.0.3.0.5.007 contain a Plain-Text Password Storage Vulnerability in PowerStore X & T environments. A locally authenticated attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The…

  • CVE-2020-29500HigJan 5, 2021
    risk 0.49cvss 7.5epss 0.00

    Dell EMC PowerStore versions prior to 1.0.3.0.5.007 contain a Plain-Text Password Storage Vulnerability in PowerStore T environments. A locally authenticated attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The…

  • CVE-2018-19941HigDec 31, 2020
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been reported to affect QNAP NAS. If exploited, this vulnerability allows an attacker to access sensitive information stored in cleartext inside cookies via certain widely-available tools. QNAP have already fixed this vulnerability in the following versions:…

  • CVE-2020-29550HigDec 23, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in URVE Build 24.03.2020. The password of an integration user account (used for the connection of the MS Office 365 Integration Service) is stored in cleartext in configuration files as well as in the database. The following files contain the password in…

  • CVE-2020-26551HigNov 17, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Aviatrix Controller before R5.3.1151. Encrypted key values are stored in a readable file.

  • CVE-2020-8225HigSep 18, 2020
    risk 0.49cvss 7.5epss 0.01

    A cleartext storage of sensitive information in Nextcloud Desktop Client 2.6.4 gave away information about used proxies and their authentication credentials.

  • CVE-2020-15484HigAug 26, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered on Nescomed Multipara Monitor M1000 devices. The internal storage of the underlying Linux system stores data in cleartext, without integrity protection against tampering.

  • CVE-2020-14017HigJun 24, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Navigate CMS 2.9 r1433. Sessions, as well as associated information such as CSRF tokens, are stored in cleartext files in the directory /private/sessions. An unauthenticated user could use a brute-force approach to attempt to identify existing…

  • CVE-2020-10273HigJun 24, 2020
    risk 0.49cvss 7.5epss 0.01

    MiR controllers across firmware versions 2.8.1.1 and before do not encrypt or protect in any way the intellectual property artifacts installed in the robots. This flaw allows attackers with access to the robot or the robot network (while in combination with other flaws) to…