VYPR

CWE-312

Cleartext Storage of Sensitive Information

BaseDraft

Description

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-37

CVEs mapped to this weakness (848)

page 25 of 43
  • CVE-2021-22194MedMar 26, 2021
    risk 0.37cvss 5.7epss 0.00

    In all versions of GitLab, marshalled session keys were being stored in Redis.

  • CVE-2026-61928MedAug 11, 2026
    risk 0.36cvss 5.5epss 0.00

    Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally.

  • CVE-2026-34490MedJul 31, 2026
    risk 0.36cvss 5.5epss 0.00

    Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attacker on a jailbroken or otherwise compromised device to Retrieve Sensitive Data. This issue affects XAAP Application: before 1.53.

  • CVE-2026-43942MedMay 8, 2026
    risk 0.36cvss 5.5epss 0.00

    electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In versions 3.8.15 and prior, the getConstants() IPC handler in src/app/lib/ipc-sync.js serialises the entire process.env object and sends it to the renderer. The data is stored as…

  • CVE-2026-24311MedMar 10, 2026
    risk 0.36cvss 5.6epss 0.00

    The SAP Customer Checkout application exhibits certain design characteristics that involve locally storing operational data using reversible protection mechanisms. Access to this data, combined with user?initiated interaction, may allow modifications to occur without validation.…

  • CVE-2026-22276MedJan 23, 2026
    risk 0.36cvss 5.5epss 0.00

    Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains a Cleartext Storage of Sensitive Information vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information…

  • CVE-2025-3784MedNov 27, 2025
    risk 0.36cvss 5.5epss 0.00

    Cleartext Storage of Sensitive Information Vulnerability in GX Works2 all versions allows an attacker to disclose credential information stored in plaintext from project files. As a result, the attacker may be able to open project files protected by user authentication using…

  • CVE-2025-21060MedOct 10, 2025
    risk 0.36cvss 5.5epss 0.00

    Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local attackers to access backup data from applications. User interaction is required for triggering this vulnerability.

  • CVE-2025-2182MedAug 13, 2025
    risk 0.36cvss epss 0.00

    A problem with the implementation of the MACsec protocol in Palo Alto Networks PAN-OS® results in the cleartext exposure of the connectivity association key (CAK). This issue is only applicable to PA-7500 Series devices which are in an NGFW cluster. A user who possesses this…

  • CVE-2025-54538MedJul 28, 2025
    risk 0.36cvss 5.5epss 0.00

    In JetBrains TeamCity before 2025.07 password exposure was possible via command line in the "hg pull" command

  • CVE-2025-54537MedJul 28, 2025
    risk 0.36cvss 5.5epss 0.00

    In JetBrains TeamCity before 2025.07 user credentials were stored in plain text in memory snapshots

  • CVE-2025-41458MedJul 21, 2025
    risk 0.36cvss 5.5epss 0.00

    Unencrypted storage in the database in Two App Studio Journey v5.5.9 for iOS allows local attackers to extract sensitive data via direct access to the app’s filesystem.

  • CVE-2025-41647MedJun 25, 2025
    risk 0.36cvss 5.5epss 0.00

    A local, low-privileged attacker can learn the password of the connected controller in PLC Designer V4 due to an incorrect implementation that results in the password being displayed in plain text under special conditions.

  • CVE-2024-56428MedMay 21, 2025
    risk 0.36cvss 5.5epss 0.00

    The local iLabClient database in itech iLabClient 3.7.1 allows local attackers to read cleartext credentials (from the CONFIGS table) for their servers configured in the client.

  • CVE-2025-31727MedApr 2, 2025
    risk 0.36cvss 5.5epss 0.00

    Jenkins AsakusaSatellite Plugin 0.1.1 and earlier stores AsakusaSatellite API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.

  • CVE-2025-31726MedApr 2, 2025
    risk 0.36cvss 5.5epss 0.00

    Jenkins Stack Hammer Plugin 1.0.6 and earlier stores Stack Hammer API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.

  • CVE-2025-31725MedApr 2, 2025
    risk 0.36cvss 5.5epss 0.00

    Jenkins monitor-remote-job Plugin 1.0 stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.

  • CVE-2024-10404MedFeb 14, 2025
    risk 0.36cvss 5.5epss 0.00

    CalInvocationHandler in Brocade SANnav before 2.3.1b logs sensitive information in clear text. The vulnerability could allow an authenticated, local attacker to view Brocade Fabric OS switch sensitive information in clear text. An attacker with administrative privileges…

  • CVE-2024-6785MedSep 21, 2024
    risk 0.36cvss 5.5epss 0.00

    The configuration file stores credentials in cleartext. An attacker with local access rights can read or modify the configuration file, potentially resulting in the service being abused due to sensitive information exposure.

  • CVE-2024-41629MedSep 12, 2024
    risk 0.36cvss 5.5epss 0.00

    An issue in Texas Instruments Fusion Digital Power Designer v.7.10.1 allows a local attacker to obtain sensitive information via the plaintext storage of credentials