VYPR

CWE-312

Cleartext Storage of Sensitive Information

BaseDraft

Description

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-37

CVEs mapped to this weakness (848)

page 16 of 43
  • CVE-2026-21080MedAug 10, 2026
    risk 0.45cvss epss 0.00

    Cleartext storage of sensitive information in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data.

  • CVE-2024-9432MedJan 30, 2026
    risk 0.45cvss epss 0.00

    Cleartext Storage of Sensitive Information vulnerability in OpenText™ Vertica allows Retrieve Embedded Sensitive Data.   The vulnerability could read Vertica agent plaintext apikey.This issue affects Vertica versions: 23.X, 24.X, 25.X.

  • CVE-2025-59102MedJan 26, 2026
    risk 0.45cvss epss 0.00

    The web server of the Access Manager offers a functionality to download a backup of the local database stored on the device. This database contains the whole configuration. This includes encrypted MIFARE keys, card data, user PINs and much more. The PINs are even stored…

  • CVE-2025-2909MedMar 28, 2025
    risk 0.45cvss epss 0.00

    The lack of encryption in the DuoxMe (formerly Blue) application binary in versions prior to 3.3.1 for iOS devices allows an attacker to gain unauthorised access to the application code and discover sensitive information.

  • CVE-2026-66016MedAug 12, 2026
    risk 0.44cvss 6.7epss 0.00

    Under specific self-hosted Helm configurations, generated TLS private keys may be retained in rendered manifests accessible to highly privileged local users.

  • CVE-2026-8804MedJul 3, 2026
    risk 0.44cvss epss 0.00

    Puppet resource_api (shipped in Puppet Core 8.x and Puppet Enterprise 2023.8.x and 2025.x) does not preserve the sensitive flag on parameters defined via the resource-api, causing values such as passwords to be stored in cleartext in the agent's local transaction state cache.…

  • CVE-2026-41520HigMay 8, 2026
    risk 0.44cvss 7.9epss 0.00

    Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.17.15, 1.18.9, and 1.19.3, the output of cilium-bugtool can contain sensitive data when the tool is run against Cilium deployments with WireGuard encryption enabled.…

  • CVE-2026-4346MedMar 26, 2026
    risk 0.44cvss 6.8epss 0.00

    The vulnerability affecting TL-WR850N v3 allows cleartext storage of administrative and Wi-Fi credentials in a region of the device’s flash memory while the serial interface remains enabled and protected by weak authentication. An attacker with physical access and the ability…

  • CVE-2025-48428MedOct 23, 2025
    risk 0.44cvss 6.7epss 0.00

    Cleartext Storage of Sensitive Information (CWE-312) in the Gallagher Morpho integration could allow an authenticated user with access to the Command Centre Server to export a specific signing key while in use allowing them to deploy a compromised or counterfeit device on that…

  • CVE-2025-4394MedJul 24, 2025
    risk 0.44cvss 6.8epss 0.00

    Medtronic MyCareLink Patient Monitor uses an unencrypted filesystem on internal storage, which allows an attacker with physical access to read and modify files. This issue affects MyCareLink Patient Monitor models 24950 and 24952: before June 25, 2025

  • CVE-2025-4053MedMay 26, 2025
    risk 0.44cvss epss 0.00

    The data stored in Be-Tech Mifare Classic card is stored in cleartext. An attacker having access to a Be-Tech hotel guest Mifare Classic card can create a master key card that unlocks all the locks in the building. This issue affects all Be-Tech Mifare Classic card…

  • CVE-2024-34891MedNov 4, 2024
    risk 0.44cvss 6.8epss 0.00

    Insufficiently protected credentials in DAV server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to read Exchange account passwords via HTTP GET request.

  • CVE-2023-41096MedOct 26, 2023
    risk 0.44cvss 6.8epss 0.00

    Missing Encryption of Security Keys vulnerability in Silicon Labs Ember ZNet SDK on 32 bit, ARM (SecureVault High modules) allows potential modification or extraction of network credentials stored in flash. This issue affects Silicon Labs Ember ZNet SDK: 7.3.1 and earlier.

  • CVE-2023-41095MedOct 26, 2023
    risk 0.44cvss 6.8epss 0.00

    Missing Encryption of Security Keys vulnerability in Silicon Labs OpenThread SDK on 32 bit, ARM (SecureVault High modules) allows potential modification or extraction of network credentials stored in flash. This issue affects Silicon Labs OpenThread SDK: 2.3.1 and earlier.

  • CVE-2022-24410MedFeb 10, 2023
    risk 0.44cvss 6.8epss 0.00

    Dell BIOS contains an information exposure vulnerability. An unauthenticated local attacker with physical access to the system and knowledge of the system configuration could potentially exploit this vulnerability to read system information via debug interfaces.

  • CVE-2022-29826MedNov 25, 2022
    risk 0.44cvss 6.8epss 0.01

    Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.087R and Motion Control Setting(GX Works3 related software) versions from 1.000A to 1.042U allows a remote unauthenticated attacker to disclose sensitive…

  • CVE-2021-22206MedMay 6, 2021
    risk 0.44cvss 6.8epss 0.01

    An issue has been discovered in GitLab affecting all versions starting from 11.6. Pull mirror credentials are exposed that allows other maintainers to be able to view the credentials in plain-text,

  • CVE-2020-35454MedMar 17, 2021
    risk 0.44cvss 6.8epss 0.00

    The Taidii Diibear Android application 2.4.0 and all its derivatives allow attackers to obtain user credentials from an Android backup because of insecure application configuration.

  • CVE-2018-20008MedMay 28, 2019
    risk 0.44cvss 6.8epss 0.00

    iBall Baton iB-WRB302N20122017 devices have improper access control over the UART interface, allowing physical attackers to discover Wi-Fi credentials (plain text) and the web-console password (base64) via the debugging console.

  • CVE-2017-2723MedNov 22, 2017
    risk 0.44cvss 6.7epss 0.00

    The Files APP 7.1.1.308 and earlier versions in some Huawei mobile phones has a vulnerability of plaintext storage of users' Safe passwords. An attacker with the root privilege of an Android system could forge the Safe to read users' plaintext Safe passwords, leading to…