VYPR

CWE-312

Cleartext Storage of Sensitive Information

BaseDraft

Description

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-37

CVEs mapped to this weakness (885)

page 25 of 45
  • CVE-2021-36158MedJul 5, 2021
    risk 0.38cvss 5.9epss 0.00

    In the xrdp package (in branches through 3.14) for Alpine Linux, RDP sessions are vulnerable to man-in-the-middle attacks because pre-generated RSA certificates and private keys are used.

  • CVE-2021-21339MedMar 23, 2021
    risk 0.38cvss 5.9epss 0.01

    TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 6.2.57, 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1 user session identifiers were stored in cleartext - without processing of additional cryptographic hashing algorithms. This vulnerability…

  • CVE-2026-44940MedSep 17, 2026
    risk 0.37cvss 5.7epss 0.00

    The rancher-extension-stackstate extension in SUSE Observability exposes service tokens in plain configuration or insecure locations rather than managing them securely. An attacker with minimal access could obtain the token to gain unauthorized access or escalate privileges…

  • CVE-2026-5224MedAug 18, 2026
    risk 0.37cvss 5.7epss 0.00

    Cleartext storage of sensitive information vulnerability in Kriptok Crypto and Information Technologies Industry Trade Inc. Cryptosim allows Retrieve Embedded Sensitive Data. This issue affects Cryptosim: before 3.1.0.229.

  • CVE-2026-55885MedJul 10, 2026
    risk 0.37cvss 6.8epss 0.00

    Grav is a file-based Web platform. Prior to 1.7.53, an authenticated administrator with backup permissions can download a ZIP archive containing the full Grav installation root, including user/accounts/admin.yaml with the administrator password hash and user/config with site…

  • CVE-2025-47147MedMar 3, 2026
    risk 0.37cvss 5.7epss 0.00

    Cleartext Storage of Sensitive Information (CWE-312) in the Command Centre Mobile Client on Android and iOS could allow an attacker with access to a logged-in Operator's mobile device to extract the session token and exploit access for a limited duration. This issue affects…

  • CVE-2025-58401MedSep 5, 2025
    risk 0.37cvss 6.8epss 0.00

    Obsidian GitHub Copilot Plugin versions prior to 1.1.7 store Github API token in cleartext form. As a result, an attacker may perform unauthorized operations on the linked Github account.

  • CVE-2023-28912MedJun 28, 2025
    risk 0.37cvss 5.7epss 0.00

    The MIB3 unit stores the synchronized phone contact book in clear-text, allowing an attacker with either code execution privilege on the system or physical access to the system to obtain vehicle owner's contact data. The vulnerability was originally discovered in Skoda Superb…

  • CVE-2025-32752MedMay 29, 2025
    risk 0.37cvss 5.7epss 0.00

    Dell ThinOS 2502 and prior contain a Cleartext Storage of Sensitive Information vulnerability. A high privileged attacker with physical access could potentially exploit this vulnerability, leading to Information Disclosure.

  • CVE-2024-55582MedDec 9, 2024
    risk 0.37cvss 5.7epss 0.00

    Oxide before 6 has unencrypted Control Plane datastores.

  • CVE-2024-21993MedJul 9, 2024
    risk 0.37cvss 5.7epss 0.00

    SnapCenter versions prior to 5.0p1 are susceptible to a vulnerability which could allow an authenticated attacker to discover plaintext credentials.

  • CVE-2023-27370MedMay 3, 2024
    risk 0.37cvss 5.7epss 0.00

    NETGEAR RAX30 Device Configuration Cleartext Storage Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR RAX30 routers. Although authentication is required to exploit…

  • CVE-2023-50770MedDec 13, 2023
    risk 0.37cvss 6.7epss 0.00

    Jenkins OpenId Connect Authentication Plugin 2.6 and earlier stores a password of a local user account used as an anti-lockout feature in a recoverable format, allowing attackers with access to the Jenkins controller file system to recover the plain text password of that…

  • CVE-2023-48700MedNov 21, 2023
    risk 0.37cvss 5.7epss 0.00

    The Nautobot Device Onboarding plugin uses the netmiko and NAPALM libraries to simplify the onboarding process of a new device into Nautobot down to, in many cases, an IP Address and a Location. Starting in version 2.0.0 and prior to version 3.0.0, credentials provided to…

  • CVE-2023-31423MedAug 31, 2023
    risk 0.37cvss 5.7epss 0.00

    Possible information exposure through log file vulnerability where sensitive fields are recorded in the configuration log without masking on Brocade SANnav before v2.3.0 and 2.2.2a. Notes: To access the logs, the local attacker must have access to an already collected…

  • CVE-2021-22194MedMar 26, 2021
    risk 0.37cvss 5.7epss 0.00

    In all versions of GitLab, marshalled session keys were being stored in Redis.

  • CVE-2026-80058MedSep 7, 2026
    risk 0.36cvss 5.5epss 0.00

    Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Cleartext Storage of Sensitive Information vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading…

  • CVE-2026-73834MedAug 18, 2026
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. Certain ACM wrapper Custom Resources that embed Secret data are collected without redaction. When an administrator runs must-gather, credentials and tokens are captured in…

  • CVE-2026-61928MedAug 11, 2026
    risk 0.36cvss 5.5epss 0.00

    Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally.

  • CVE-2026-34490MedJul 31, 2026
    risk 0.36cvss 5.5epss 0.00

    Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attacker on a jailbroken or otherwise compromised device to Retrieve Sensitive Data. This issue affects XAAP Application: before 1.53.