VYPR

CWE-312

Cleartext Storage of Sensitive Information

BaseDraft

Description

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-37

CVEs mapped to this weakness (848)

page 15 of 43
  • CVE-2021-23878HigFeb 10, 2021
    risk 0.47cvss 7.3epss 0.01

    Clear text storage of sensitive Information in memory vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Update allows a local user to view ENS settings and credentials via accessing process memory after the ENS administrator has performed…

  • CVE-2020-29001HigJan 26, 2021
    risk 0.47cvss 7.2epss 0.01

    An issue was discovered on Geeni GNC-CW028 Camera 2.7.2, Geeni GNC-CW025 Doorbell 2.9.5, Merkury MI-CW024 Doorbell 2.9.6, and Merkury MI-CW017 Camera 2.9.6 devices. A vulnerability exists in the RESTful Services API that allows a remote attacker to take full control of the…

  • CVE-2018-19981HigApr 4, 2019
    risk 0.47cvss 7.2epss 0.02

    Amazon AWS SDK <=2.8.5 for Android uses Android SharedPreferences to store plain text AWS STS Temporary Credentials retrieved by AWS Cognito Identity Service. An attacker can use these credentials to create authenticated and/or authorized requests. Note that the attacker must…

  • CVE-2019-6549HigFeb 12, 2019
    risk 0.47cvss 7.2epss 0.01

    An attacker could retrieve plain-text credentials stored in a XML file on PR100088 Modbus gateway versions prior to Release R02 (or Software Version 1.1.13166) through FTP.

  • CVE-2026-46622HigJun 11, 2026
    risk 0.46cvss 8.1epss 0.00

    SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, API tokens used to authenticate all REST API requests are stored as plaintext strings in the api_tokens database table. Any attacker who obtains read access to the database — through SQL injection, a…

  • CVE-2026-36176HigJun 4, 2026
    risk 0.46cvss 7.1epss 0.00

    GNCC GP5 v7.1.76 was discovered to store pre-signed Backblaze B2 upload URLs (PUT requests) in plaintext to the serial console. This allows physically-proximate attackers to extract these active tokens to perform unauthorized operations via monitoring the serial UART interface.

  • CVE-2025-59105HigJan 26, 2026
    risk 0.46cvss epss 0.00

    With physical access to the device and enough time an attacker can desolder the flash memory, modify it and then reinstall it because of missing encryption. Thus, essential files, such as "/etc/passwd", as well as stored certificates, cryptographic keys, stored PINs and so on…

  • CVE-2025-21061HigOct 10, 2025
    risk 0.46cvss 7.1epss 0.00

    Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local attackers to access sensitive data. User interaction is required for triggering this vulnerability.

  • CVE-2025-54464HigAug 13, 2025
    risk 0.46cvss epss 0.00

    This vulnerability exists in ZKTeco WL20 due to storage of admin and user credentials without encryption in the device firmware. An attacker with physical access could exploit this vulnerability by extracting the firmware and reverse engineer the binary data to access the…

  • CVE-2025-7397HigJul 17, 2025
    risk 0.46cvss 7.1epss 0.00

    A vulnerability in the ascgshell, of Brocade ASCG before 3.3.0 stores any command executed in the Command Line Interface (CLI) in plain text within the command history. A local authenticated user that can access sensitive information like passwords within the CLI history…

  • CVE-2025-3395HigApr 30, 2025
    risk 0.46cvss 7.1epss 0.00

    Incorrect Permission Assignment for Critical Resource, Cleartext Storage of Sensitive Information vulnerability in ABB Automation Builder.This issue affects Automation Builder: through 2.8.0.

  • CVE-2024-23942HigMar 18, 2025
    risk 0.46cvss 7.1epss 0.00

    A local user may find a configuration file on the client workstation with unencrypted sensitive data. This allows an attacker to impersonate the device or prevent the device from accessing the cloud portal which leads to a DoS.

  • CVE-2024-53979HigNov 29, 2024
    risk 0.46cvss 8.2epss 0.00

    ibm.ibm_zhmc is an Ansible collection for the IBM Z HMC. The Ansible collection "ibm.ibm_zhmc" writes password-like properties in clear text into its log file and into the output returned by some of its Ansible module in the following cases: 1. The 'boot_ftp_password' and…

  • CVE-2024-53865HigNov 29, 2024
    risk 0.46cvss 8.2epss 0.00

    zhmcclient is a pure Python client library for the IBM Z HMC Web Services API. In affected versions the Python package "zhmcclient" writes password-like properties in clear text into its HMC and API logs in the following cases: 1. The 'boot-ftp-password' and 'ssc-master-pw'…

  • CVE-2024-9991HigOct 25, 2024
    risk 0.46cvss epss 0.00

    This vulnerability exists in Philips lighting devices due to storage of Wi-Fi credentials in plain text within the device firmware. An attacker with physical access could exploit this by extracting the firmware and analyzing the binary data to obtain the plaintext Wi-Fi…

  • CVE-2023-27706HigJun 9, 2023
    risk 0.46cvss 7.1epss 0.01

    Bitwarden Windows desktop application versions prior to v2023.4.0 store biometric keys in Windows Credential Manager, accessible to other local unprivileged processes.

  • CVE-2022-34388HigFeb 11, 2023
    risk 0.46cvss 7.1epss 0.00

    Dell SupportAssist for Home PCs (version 3.11.4 and prior) and  SupportAssist for Business PCs (version 3.2.0 and prior) contain information disclosure vulnerability. A local malicious user with low privileges could exploit this vulnerability to view and modify sensitive…

  • CVE-2022-2513HigNov 22, 2022
    risk 0.46cvss 7.1epss 0.00

    A vulnerability exists in the Intelligent Electronic Device (IED) Connectivity Package (ConnPack) credential storage function in Hitachi Energy’s PCM600 product included in the versions listed below, where IEDs credentials are stored in a cleartext format in the PCM600…

  • CVE-2018-11242MedMay 20, 2018
    risk 0.46cvss 6.5epss 0.04

    An issue was discovered in the MakeMyTrip application 7.2.4 for Android. The databases (locally stored) are not encrypted and have cleartext that might lead to sensitive information disclosure, as demonstrated by data/com.makemytrip/databases and data/com.makemytrip/Cache SQLite…

  • CVE-2018-8947HigMar 25, 2018
    risk 0.46cvss 7.5epss 0.11

    rap2hpoutre Laravel Log Viewer before v0.13.0 relies on Base64 encoding for l, dl, and del requests, which makes it easier for remote attackers to bypass intended access restrictions, as demonstrated by reading arbitrary files via a dl request.