VYPR

CWE-312

Cleartext Storage of Sensitive Information

BaseDraft

Description

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-37

CVEs mapped to this weakness (848)

page 22 of 43
  • CVE-2017-2672MedJun 21, 2018
    risk 0.42cvss 6.5epss 0.01

    A flaw was found in foreman before version 1.15 in the logging of adding and registering images. An attacker with access to the foreman log file would be able to view passwords for provisioned systems in the log file, allowing them to access those systems.

  • CVE-2017-14990MedOct 3, 2017
    risk 0.42cvss 6.5epss 0.02

    WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which might make it easier for remote attackers to hijack unactivated user accounts by leveraging database read access (such as access…

  • CVE-2024-20448MedOct 2, 2024
    risk 0.41cvss 6.3epss 0.00

    A vulnerability in the Cisco Nexus Dashboard Fabric Controller (NDFC) software, formerly Cisco Data Center Network Manager (DCNM), could allow an attacker with access to a backup file to view sensitive information. This vulnerability is due to the improper storage of…

  • CVE-2024-31415MedSep 13, 2024
    risk 0.41cvss 6.3epss 0.00

    The Eaton Foreseer software provides the feasibility for the user to configure external servers for multiple purposes such as network management, user management, etc. The software uses encryption to store these configurations securely on the host machine. However, the keys used…

  • CVE-2022-3089MedFeb 13, 2023
    risk 0.41cvss 6.3epss 0.00

    Echelon SmartServer 2.2 with i.LON Vision 2.2 stores cleartext credentials in a file, which could allow an attacker to obtain cleartext usernames and passwords of the SmartServer. If the attacker obtains the file, then the credentials could be used to control the web user…

  • CVE-2022-30626MedJul 18, 2022
    risk 0.41cvss 6.3epss 0.00

    Browsing the path: http://ip/wifi_ap_pata_get.cmd, will show in the name of the existing access point on the component, and a password in clear text.

  • CVE-2021-35526MedSep 8, 2021
    risk 0.41cvss 6.3epss 0.00

    Backup file without encryption vulnerability is found in Hitachi ABB Power Grids System Data Manager – SDM600 allows attacker to gain access to sensitive information. This issue affects: Hitachi ABB Power Grids System Data Manager – SDM600 1.2 versions prior to FP2 HF6…

  • CVE-2020-10706MedMay 12, 2020
    risk 0.41cvss 6.3epss 0.00

    A flaw was found in OpenShift Container Platform where OAuth tokens are not encrypted when the encryption of data at rest is enabled. This flaw allows an attacker with access to a backup to obtain OAuth tokens and then use them to log into the cluster as any user who logged into…

  • CVE-2026-8596HigMay 14, 2026
    risk 0.40cvss 7.2epss 0.00

    Cleartext storage of sensitive information in the ModelBuilder/Serve component in Amazon SageMaker Python SDK before v2.257.2 and v3 before v3.8.0 might allow a remote authenticated actor to extract the HMAC signing key from SageMaker API responses and forge valid integrity…

  • CVE-2026-7163MedApr 30, 2026
    risk 0.40cvss 6.1epss 0.00

    A vulnerability in the assisted-service REST API, an optional Assisted Installer (assisted-service) component in the Multicluster Engine (MCE), allows an authenticated user with minimal namespace-scoped privileges to obtain administrative credentials for arbitrary clusters…

  • CVE-2025-55334MedOct 14, 2025
    risk 0.40cvss 6.2epss 0.00

    Cleartext storage of sensitive information in Windows Kernel allows an unauthorized attacker to bypass a security feature locally.

  • CVE-2025-40753MedAug 12, 2025
    risk 0.40cvss 6.2epss 0.00

    A vulnerability has been identified in POWER METER SICAM Q100 (7KG9501-0AA01-0AA1) (All versions >= V2.60 < V2.62), POWER METER SICAM Q100 (7KG9501-0AA01-2AA1) (All versions >= V2.60 < V2.62), POWER METER SICAM Q100 (7KG9501-0AA31-0AA1) (All versions >= V2.60 < V2.62), POWER…

  • CVE-2025-40752MedAug 12, 2025
    risk 0.40cvss 6.2epss 0.00

    A vulnerability has been identified in POWER METER SICAM Q100 (7KG9501-0AA01-0AA1) (All versions >= V2.60 < V2.62), POWER METER SICAM Q100 (7KG9501-0AA01-2AA1) (All versions >= V2.60 < V2.62), POWER METER SICAM Q100 (7KG9501-0AA31-0AA1) (All versions >= V2.60 < V2.62), POWER…

  • CVE-2024-24915MedJun 29, 2025
    risk 0.40cvss 6.1epss 0.00

    Credentials are not cleared from memory after being used. A user with Administrator permissions can execute memory dump for SmartConsole process and fetch them.

  • CVE-2025-4737MedMay 15, 2025
    risk 0.40cvss 6.2epss 0.00

    Insufficient encryption vulnerability in the mobile application (com.transsion.aivoiceassistant) may lead to the risk of sensitive information leakage.

  • CVE-2024-39674MedJul 25, 2024
    risk 0.40cvss 6.2epss 0.00

    Plaintext vulnerability in the Gallery search module. Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2024-32474HigApr 18, 2024
    risk 0.40cvss 7.3epss 0.00

    Sentry is an error tracking and performance monitoring platform. Prior to 24.4.1, when authenticating as a superuser to Sentry with a username and password, the password is leaked as cleartext in logs under the _event_: `auth-index.validate_superuser`. An attacker with access to…

  • CVE-2023-5384HigDec 18, 2023
    risk 0.40cvss 7.2epss 0.01

    A flaw was found in Infinispan. When serializing the configuration for a cache to XML/JSON/YAML, which contains credentials (JDBC store with connection pooling, remote store), the credentials are returned in clear text as part of the configuration.

  • CVE-2023-4400MedSep 13, 2023
    risk 0.40cvss 6.2epss 0.00

    A password management vulnerability in Skyhigh Secure Web Gateway (SWG) in main releases 11.x prior to 11.2.14, 10.x prior to 10.2.25 and controlled release 12.x prior to 12.2.1, allows some authentication information stored in configuration files to be extracted through SWG…

  • CVE-2023-22878MedMay 19, 2023
    risk 0.40cvss 6.2epss 0.00

    IBM InfoSphere Information Server 11.7 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 244373.