VYPR

CWE-312

Cleartext Storage of Sensitive Information

BaseDraft

Description

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-37

CVEs mapped to this weakness (885)

page 17 of 45
  • CVE-2023-41095MedOct 26, 2023
    risk 0.44cvss 6.8epss 0.00

    Missing Encryption of Security Keys vulnerability in Silicon Labs OpenThread SDK on 32 bit, ARM (SecureVault High modules) allows potential modification or extraction of network credentials stored in flash. This issue affects Silicon Labs OpenThread SDK: 2.3.1 and earlier.

  • CVE-2022-24410MedFeb 10, 2023
    risk 0.44cvss 6.8epss 0.00

    Dell BIOS contains an information exposure vulnerability. An unauthenticated local attacker with physical access to the system and knowledge of the system configuration could potentially exploit this vulnerability to read system information via debug interfaces.

  • CVE-2022-29826MedNov 25, 2022
    risk 0.44cvss 6.8epss 0.01

    Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.087R and Motion Control Setting(GX Works3 related software) versions from 1.000A to 1.042U allows a remote unauthenticated attacker to disclose sensitive…

  • CVE-2021-22206MedMay 6, 2021
    risk 0.44cvss 6.8epss 0.01

    An issue has been discovered in GitLab affecting all versions starting from 11.6. Pull mirror credentials are exposed that allows other maintainers to be able to view the credentials in plain-text,

  • CVE-2020-35454MedMar 17, 2021
    risk 0.44cvss 6.8epss 0.00

    The Taidii Diibear Android application 2.4.0 and all its derivatives allow attackers to obtain user credentials from an Android backup because of insecure application configuration.

  • CVE-2018-20008MedMay 28, 2019
    risk 0.44cvss 6.8epss 0.00

    iBall Baton iB-WRB302N20122017 devices have improper access control over the UART interface, allowing physical attackers to discover Wi-Fi credentials (plain text) and the web-console password (base64) via the debugging console.

  • CVE-2017-2723MedNov 22, 2017
    risk 0.44cvss 6.7epss 0.00

    The Files APP 7.1.1.308 and earlier versions in some Huawei mobile phones has a vulnerability of plaintext storage of users' Safe passwords. An attacker with the root privilege of an Android system could forge the Safe to read users' plaintext Safe passwords, leading to…

  • CVE-2026-43824HigMay 2, 2026
    risk 0.43cvss 7.7epss 0.00

    In Argo CD 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9, ServerSideDiff allows reading cleartext Kubernetes Secret data.

  • CVE-2026-34214HigMar 31, 2026
    risk 0.43cvss 7.7epss 0.00

    Trino is a distributed SQL query engine for big data analytics. From version 439 to before version 480, Iceberg connector REST catalog static credentials (access key) or vended credentials (temporary access key) are accessible to users that have write privilege on SQL level.…

  • CVE-2024-52284HigSep 2, 2025
    risk 0.43cvss 7.7epss 0.00

    Unauthorized disclosure of sensitive data: Any user with `GET` or `LIST` permissions on `BundleDeployment` resources could retrieve Helm values containing credentials or other secrets.

  • CVE-2024-9466MedOct 9, 2024
    risk 0.43cvss 6.5epss 0.14

    A cleartext storage of sensitive information vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to reveal firewall usernames, passwords, and API keys generated using those credentials.

  • CVE-2024-28810MedSep 30, 2024
    risk 0.43cvss 6.6epss 0.00

    An issue was discovered in Infinera hiT 7300 5.60.50. Sensitive information inside diagnostic files (exported by the @CT application) allows an attacker to achieve loss of confidentiality by analyzing these files.

  • CVE-2024-23584MedApr 8, 2024
    risk 0.43cvss 6.6epss 0.00

    The NMAP Importer service​ may expose data store credentials to authorized users of the Windows Registry.

  • CVE-2021-32942MedJun 9, 2021
    risk 0.43cvss 6.6epss 0.00

    The vulnerability could expose cleartext credentials from AVEVA InTouch Runtime 2020 R2 and all prior versions (WindowViewer) if an authorized, privileged user creates a diagnostic memory dump of the process and saves it to a non-protected location.

  • CVE-2020-26288HigDec 30, 2020
    risk 0.43cvss 7.7epss 0.01

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. It is an npm package "parse-server". In Parse Server before version 4.5.0, user passwords involved in LDAP authentication are stored in cleartext. This is fixed in version…

  • CVE-2026-93764MedSep 18, 2026
    risk 0.42cvss 6.5epss 0.00

    Mongoid may omit encryption rules for fields declared on embedded models when generating the client-side field-level encryption schema. Applications that enable this feature can therefore store values intended to be encrypted in readable form, with no error or warning. A party…

  • CVE-2026-93763MedSep 18, 2026
    risk 0.42cvss 6.5epss 0.00

    A protection mechanism failure in the object-document mapper's encryption configuration generation can cause fields that an application declared for client-side field-level encryption to be written and kept in cleartext, without any error or warning. A party holding ordinary…

  • CVE-2026-77975MedAug 31, 2026
    risk 0.42cvss 6.5epss 0.00

    The affected Ebyte product exports administrative credentials and other sensitive configuration information without adequate protection. An unauthenticated attacker on the adjacent network who can obtain an exported configuration file could recover valid credentials and use…

  • CVE-2026-59244MedAug 12, 2026
    risk 0.42cvss 6.5epss 0.00

    Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered Templates UI — the dict value failed an `isinstance(str)` guard — so a secret stored as a JSON Variable and referenced in a template via `var.json` was displayed in…

  • CVE-2026-19391MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in insights-core where the password redaction layer fails to recognize credentials not keyed under the literal string 'password'. This allows SSSD LDAP bind passwords (ldap_default_authtok) and Pacemaker fence device credentials to be included in cleartext in…