VYPR

CWE-312

Cleartext Storage of Sensitive Information

BaseDraft

Description

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-37

CVEs mapped to this weakness (848)

page 2 of 43
  • CVE-2019-9873CriJul 3, 2019
    risk 0.64cvss 9.8epss 0.02

    In several versions of JetBrains IntelliJ IDEA Ultimate, creating Task Servers configurations leads to saving a cleartext unencrypted record of the server credentials in the IDE configuration files. The issue has been fixed in the following versions: 2019.1, 2018.3.5, 2018.2.8,…

  • CVE-2019-9823CriJul 3, 2019
    risk 0.64cvss 9.8epss 0.02

    In several JetBrains IntelliJ IDEA versions, creating remote run configurations of JavaEE application servers leads to saving a cleartext record of the server credentials in the IDE configuration files. The issue has been fixed in the following versions: 2018.3.5, 2018.2.8,…

  • CVE-2019-11384CriApr 22, 2019
    risk 0.64cvss 9.8epss 0.01

    The Zalora application 6.15.1 for Android stores confidential information insecurely on the system (i.e. plain text), which allows a non-root user to find out the username/password of a valid user via /data/data/com.zalora.android/shared_prefs/login_data.xml.

  • CVE-2014-5433CriMar 26, 2019
    risk 0.64cvss 9.8epss 0.02

    An unauthenticated remote attacker may be able to execute commands to view wireless account credentials that are stored in cleartext on Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) version 16, which may allow an attacker…

  • CVE-2018-18641CriDec 4, 2018
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It has Cleartext Storage of Sensitive Information.

  • CVE-2018-18394CriOct 19, 2018
    risk 0.64cvss 9.8epss 0.01

    Sensitive Information Stored in Clear Text in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.

  • CVE-2017-5250CriFeb 22, 2018
    risk 0.64cvss 9.8epss 0.01

    In version 1.9.7 and prior of Insteon's Insteon for Hub Android app, the OAuth token used by the app to authorize user access is not stored in an encrypted and secure manner.

  • CVE-2017-5249CriFeb 22, 2018
    risk 0.64cvss 9.8epss 0.01

    In version 6.1.0.19 and prior of Wink Labs's Wink - Smart Home Android app, the OAuth token used by the app to authorize user access is not stored in an encrypted and secure manner.

  • CVE-2008-0174CriJan 29, 2008
    risk 0.64cvss 9.8epss 0.02

    GE Fanuc Proficy Real-Time Information Portal 2.6 and earlier uses HTTP Basic Authentication, which transmits usernames and passwords in base64-encoded cleartext and allows remote attackers to steal the passwords and gain privileges.

  • CVE-2001-1481CriDec 31, 2001
    risk 0.64cvss 9.8epss 0.03

    Xitami 2.4 through 2.5 b4 stores the Administrator password in plaintext in the default.aut file, whose default permissions are world-readable, which allows remote attackers to gain privileges.

  • CVE-2023-1897CriJun 12, 2023
    risk 0.61cvss 9.4epss 0.00

    Atlas Copco Power Focus 6000 web server does not sanitize the login information stored by the authenticated user’s browser, which could allow an attacker with access to the user’s computer to gain credential information of the controller.

  • CVE-2025-14815CriApr 8, 2026
    risk 0.60cvss epss 0.00

    Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric ICONICS Suite versions 10.97.3 and prior, Mitsubishi Electric MobileHMI versions 10.97.3 and prior, Mitsubishi Electric Hyper Historian…

  • CVE-2025-7426CriAug 25, 2025
    risk 0.60cvss epss 0.00

    Information disclosure and exposure of authentication FTP credentials over the debug port 1604 in the MINOVA TTA service. This allows unauthenticated remote access to an active FTP account containing sensitive internal data and import structures. In environments where this FTP…

  • CVE-2025-63729CriNov 25, 2025
    risk 0.59cvss 9.0epss 0.00

    An issue was discovered in Syrotech SY-GPON-1110-WDONT SYRO_3.7L_3.1.02-240517 allowing attackers to exctract the SSL Private Key, CA Certificate, SSL Certificate, and Client Certificates in .pem format in firmware in etc folder.

  • CVE-2025-55443CriAug 26, 2025
    risk 0.59cvss 9.1epss 0.00

    Telpo MDM 1.4.6 thru 1.4.9 for Android contains sensitive administrator credentials and MQTT server connection details (IP/port) that are stored in plaintext within log files on the device's external storage. This allows attackers with access to these logs to: 1. Authenticate to…

  • CVE-2025-22896HigFeb 13, 2025
    risk 0.59cvss 8.6epss 0.03

    mySCADA myPRO Manager stores credentials in cleartext, which could allow an attacker to obtain sensitive information.

  • CVE-2024-46505CriJan 9, 2025
    risk 0.59cvss 9.1epss 0.00

    Infoblox BloxOne v2.4 was discovered to contain a business logic flaw due to thick client vulnerabilities.

  • CVE-2024-9798CriOct 10, 2024
    risk 0.59cvss 9.0epss 0.00

    The health endpoint is public so everybody can see a list of all services. It is potentially valuable information for attackers.

  • CVE-2024-40457CriSep 12, 2024
    risk 0.59cvss 9.1epss 0.01

    No-IP Dynamic Update Client (DUC) v3.x uses cleartext credentials that may occur on a command line or in a file. NOTE: the vendor's position is that cleartext in /etc/default/noip-duc is recommended and is the intentional behavior.

  • CVE-2024-36497CriJun 24, 2024
    risk 0.59cvss 9.1epss 0.00

    The decrypted configuration file contains the password in cleartext which is used to configure WINSelect. It can be used to remove the existing restrictions and disable WINSelect entirely.