VYPR

CWE-312

Cleartext Storage of Sensitive Information

BaseDraft

Description

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-37

CVEs mapped to this weakness (848)

page 24 of 43
  • CVE-2024-29146MedNov 26, 2024
    risk 0.38cvss 5.9epss 0.01

    User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved from the coredump file. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors…

  • CVE-2024-29954MedJun 26, 2024
    risk 0.38cvss 5.9epss 0.00

    A vulnerability in a password management API in Brocade Fabric OS versions before v9.2.1, v9.2.0b, v9.1.1d, and v8.2.3e prints sensitive information in log files. This could allow an authenticated user to view the server passwords for protocols such as scp and sftp. Detail.…

  • CVE-2024-28065MedApr 5, 2024
    risk 0.38cvss 5.9epss 0.00

    In Unify CP IP Phone firmware 1.10.4.3, files are not encrypted and contain sensitive information such as the root password hash.

  • CVE-2023-39903MedAug 7, 2023
    risk 0.38cvss 5.9epss 0.00

    An issue was discovered in Fujitsu Software Infrastructure Manager (ISM) before 2.8.0.061. The ismsnap component (in this specific case at /var/log/fujitsu/ServerViewSuite/ism/FirmwareManagement/FirmwareManagement.log) allows insecure collection and storage of authorization…

  • CVE-2022-34351MedFeb 17, 2023
    risk 0.38cvss 5.9epss 0.00

    IBM QRadar SIEM 7.4 and 7.5 is vulnerable to information exposure allowing a non-tenant user with a specific domain security profile assigned to see some data from other domains. IBM X-Force ID: 230402.

  • CVE-2017-20040MedJun 11, 2022
    risk 0.38cvss 5.9epss 0.00

    A vulnerability was found in SICUNET Access Controller 0.32-05z. It has been declared as problematic. This vulnerability affects unknown code of the component Password Storage. The manipulation leads to weak encryption. Attacking locally is a requirement.

  • CVE-2022-25160MedApr 1, 2022
    risk 0.38cvss 5.9epss 0.01

    Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U(C) CPU all versions, Mitsubishi Electric MELSEC iQ-F series FX5UJ CPU all versions, Mitsubishi Electric MELSEC iQ-R series R00/01/02CPU all versions, Mitsubishi Electric…

  • CVE-2021-36158MedJul 5, 2021
    risk 0.38cvss 5.9epss 0.00

    In the xrdp package (in branches through 3.14) for Alpine Linux, RDP sessions are vulnerable to man-in-the-middle attacks because pre-generated RSA certificates and private keys are used.

  • CVE-2021-21339MedMar 23, 2021
    risk 0.38cvss 5.9epss 0.01

    TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 6.2.57, 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1 user session identifiers were stored in cleartext - without processing of additional cryptographic hashing algorithms. This vulnerability…

  • CVE-2026-55885MedJul 10, 2026
    risk 0.37cvss 6.8epss 0.00

    Grav is a file-based Web platform. Prior to 1.7.53, an authenticated administrator with backup permissions can download a ZIP archive containing the full Grav installation root, including user/accounts/admin.yaml with the administrator password hash and user/config with site…

  • CVE-2025-47147MedMar 3, 2026
    risk 0.37cvss 5.7epss 0.00

    Cleartext Storage of Sensitive Information (CWE-312) in the Command Centre Mobile Client on Android and iOS could allow an attacker with access to a logged-in Operator's mobile device to extract the session token and exploit access for a limited duration. This issue affects…

  • CVE-2025-58401MedSep 5, 2025
    risk 0.37cvss 6.8epss 0.00

    Obsidian GitHub Copilot Plugin versions prior to 1.1.7 store Github API token in cleartext form. As a result, an attacker may perform unauthorized operations on the linked Github account.

  • CVE-2023-28912MedJun 28, 2025
    risk 0.37cvss 5.7epss 0.00

    The MIB3 unit stores the synchronized phone contact book in clear-text, allowing an attacker with either code execution privilege on the system or physical access to the system to obtain vehicle owner's contact data. The vulnerability was originally discovered in Skoda Superb…

  • CVE-2025-32752MedMay 29, 2025
    risk 0.37cvss 5.7epss 0.00

    Dell ThinOS 2502 and prior contain a Cleartext Storage of Sensitive Information vulnerability. A high privileged attacker with physical access could potentially exploit this vulnerability, leading to Information Disclosure.

  • CVE-2024-55582MedDec 9, 2024
    risk 0.37cvss 5.7epss 0.00

    Oxide before 6 has unencrypted Control Plane datastores.

  • CVE-2024-21993MedJul 9, 2024
    risk 0.37cvss 5.7epss 0.00

    SnapCenter versions prior to 5.0p1 are susceptible to a vulnerability which could allow an authenticated attacker to discover plaintext credentials.

  • CVE-2023-27370MedMay 3, 2024
    risk 0.37cvss 5.7epss 0.00

    NETGEAR RAX30 Device Configuration Cleartext Storage Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR RAX30 routers. Although authentication is required to exploit…

  • CVE-2023-50770MedDec 13, 2023
    risk 0.37cvss 6.7epss 0.00

    Jenkins OpenId Connect Authentication Plugin 2.6 and earlier stores a password of a local user account used as an anti-lockout feature in a recoverable format, allowing attackers with access to the Jenkins controller file system to recover the plain text password of that…

  • CVE-2023-48700MedNov 21, 2023
    risk 0.37cvss 5.7epss 0.00

    The Nautobot Device Onboarding plugin uses the netmiko and NAPALM libraries to simplify the onboarding process of a new device into Nautobot down to, in many cases, an IP Address and a Location. Starting in version 2.0.0 and prior to version 3.0.0, credentials provided to…

  • CVE-2023-31423MedAug 31, 2023
    risk 0.37cvss 5.7epss 0.00

    Possible information exposure through log file vulnerability where sensitive fields are recorded in the configuration log without masking on Brocade SANnav before v2.3.0 and 2.2.2a. Notes: To access the logs, the local attacker must have access to an already collected…