CWE-312
Cleartext Storage of Sensitive Information
Description
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-37
CVEs mapped to this weakness (885)
page 29 of 45| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-40454 | Med | 0.36 | 5.5 | 0.01 | Oct 13, 2021 | Rich Text Edit Control Information Disclosure Vulnerability | ||
| CVE-2021-29904 | Med | 0.36 | 5.5 | 0.00 | Sep 23, 2021 | IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI displays user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 207610. | ||
| CVE-2021-37452 | Med | 0.36 | 5.5 | 0.00 | Jul 25, 2021 | NCH Quorum v2.03 and earlier allows local users to discover cleartext login information relating to users by reading the local .dat configuration files. | ||
| CVE-2021-27487 | Med | 0.36 | 5.5 | 0.00 | Jun 16, 2021 | ZOLL Defibrillator Dashboard, v prior to 2.2, The affected products contain credentials stored in plaintext. This could allow an attacker to gain access to sensitive information. | ||
| CVE-2021-28858 | Med | 0.36 | 5.5 | 0.00 | Jun 15, 2021 | TP-Link's TL-WPA4220 4.0.2 Build 20180308 Rel.37064 does not use SSL by default. Attacker on the local network can monitor traffic and capture the cookie and other sensitive information. | ||
| CVE-2018-16498 | Med | 0.36 | 5.5 | 0.00 | May 26, 2021 | In Versa Director, the unencrypted backup files stored on the Versa deployment contain credentials stored within configuration files. These credentials are for various application components such as SNMP, and SSL and Trust keystores. | ||
| CVE-2021-31539 | Med | 0.36 | 5.5 | 0.00 | Apr 23, 2021 | Wowza Streaming Engine before 4.8.8.01 (in a default installation) has cleartext passwords stored in the conf/admin.password file. A regular local user is able to read usernames and passwords. | ||
| CVE-2020-11924 | Med | 0.36 | 5.5 | 0.00 | Apr 2, 2021 | An issue was discovered in WiZ Colors A60 1.14.0. Wi-Fi credentials are stored in cleartext in flash memory, which presents an information-disclosure risk for a discarded or resold device. | ||
| CVE-2020-11923 | Med | 0.36 | 5.5 | 0.00 | Apr 2, 2021 | An issue was discovered in WiZ Colors A60 1.14.0. API credentials are locally logged. | ||
| CVE-2020-4944 | Med | 0.36 | 5.5 | 0.00 | Mar 30, 2021 | IBM UrbanCode Deploy (UCD) 7.0.3.0, 7.0.4.0, 7.0.5.3, 7.0.5.4, 7.1.0.0, 7.1.1.0, 7.1.1.1, and 7.1.1.2, stores keystore passwords in plain text after a manual edit, which can be read by a local user. IBM X-Force ID: 191944. | ||
| CVE-2020-4884 | Med | 0.36 | 5.5 | 0.00 | Mar 30, 2021 | IBM UrbanCode Deploy (UCD) 6.2.7.9, 7.0.5.4, and 7.1.1.1 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 190908. | ||
| CVE-2021-23827 | Med | 0.36 | 5.5 | 0.00 | Feb 23, 2021 | Keybase Desktop Client before 5.6.0 on Windows and macOS, and before 5.6.1 on Linux, allows an attacker to obtain potentially sensitive media (such as private pictures) in the Cache and uploadtemps directories. It fails to effectively clear cached pictures, even after deletion… | ||
| CVE-2021-20408 | Med | 0.36 | 5.5 | 0.00 | Feb 12, 2021 | IBM Security Verify Information Queue 1.0.6 and 1.0.7 could disclose highly sensitive information to a local user due to inproper storage of a plaintext cryptographic key. IBM X-Force ID: 198187. | ||
| CVE-2021-27205 | Med | 0.36 | 5.5 | 0.00 | Feb 12, 2021 | Telegram before 7.4 (212543) Stable on macOS stores the local copy of self-destructed messages in a sandbox path, leading to sensitive information disclosure. | ||
| CVE-2021-27204 | Med | 0.36 | 5.5 | 0.00 | Feb 12, 2021 | Telegram before 7.4 (212543) Stable on macOS stores the local passcode in cleartext, leading to information disclosure. | ||
| CVE-2021-26550 | Med | 0.36 | 5.5 | 0.00 | Feb 9, 2021 | An issue was discovered in SmartFoxServer 2.17.0. Cleartext password disclosure can occur via /config/server.xml. | ||
| CVE-2020-13473 | Med | 0.36 | 5.5 | 0.00 | Dec 28, 2020 | NCH Express Accounts 8.24 and earlier allows local users to discover the cleartext password by reading the configuration file. | ||
| CVE-2020-25677 | Med | 0.36 | 5.5 | 0.00 | Dec 8, 2020 | A flaw was found in Ceph-ansible v4.0.41 where it creates an /etc/ceph/iscsi-gateway.conf with insecure default permissions. This flaw allows any user on the system to read sensitive information within this file. The highest threat from this vulnerability is to confidentiality. | ||
| CVE-2020-8276 | Med | 0.36 | 5.5 | 0.00 | Nov 9, 2020 | The implementation of Brave Desktop's privacy-preserving analytics system (P3A) between 1.1 and 1.18.35 logged the timestamp of when the user last opened an incognito window, including Tor windows. The intended behavior was to log the timestamp for incognito windows excluding… | ||
| CVE-2020-2274 | Med | 0.36 | 5.5 | 0.00 | Sep 16, 2020 | Jenkins ElasTest Plugin 1.2.1 and earlier stores its server password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system. |
- risk 0.36cvss 5.5epss 0.01
Rich Text Edit Control Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.00
IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI displays user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 207610.
- risk 0.36cvss 5.5epss 0.00
NCH Quorum v2.03 and earlier allows local users to discover cleartext login information relating to users by reading the local .dat configuration files.
- risk 0.36cvss 5.5epss 0.00
ZOLL Defibrillator Dashboard, v prior to 2.2, The affected products contain credentials stored in plaintext. This could allow an attacker to gain access to sensitive information.
- risk 0.36cvss 5.5epss 0.00
TP-Link's TL-WPA4220 4.0.2 Build 20180308 Rel.37064 does not use SSL by default. Attacker on the local network can monitor traffic and capture the cookie and other sensitive information.
- risk 0.36cvss 5.5epss 0.00
In Versa Director, the unencrypted backup files stored on the Versa deployment contain credentials stored within configuration files. These credentials are for various application components such as SNMP, and SSL and Trust keystores.
- risk 0.36cvss 5.5epss 0.00
Wowza Streaming Engine before 4.8.8.01 (in a default installation) has cleartext passwords stored in the conf/admin.password file. A regular local user is able to read usernames and passwords.
- risk 0.36cvss 5.5epss 0.00
An issue was discovered in WiZ Colors A60 1.14.0. Wi-Fi credentials are stored in cleartext in flash memory, which presents an information-disclosure risk for a discarded or resold device.
- risk 0.36cvss 5.5epss 0.00
An issue was discovered in WiZ Colors A60 1.14.0. API credentials are locally logged.
- risk 0.36cvss 5.5epss 0.00
IBM UrbanCode Deploy (UCD) 7.0.3.0, 7.0.4.0, 7.0.5.3, 7.0.5.4, 7.1.0.0, 7.1.1.0, 7.1.1.1, and 7.1.1.2, stores keystore passwords in plain text after a manual edit, which can be read by a local user. IBM X-Force ID: 191944.
- risk 0.36cvss 5.5epss 0.00
IBM UrbanCode Deploy (UCD) 6.2.7.9, 7.0.5.4, and 7.1.1.1 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 190908.
- risk 0.36cvss 5.5epss 0.00
Keybase Desktop Client before 5.6.0 on Windows and macOS, and before 5.6.1 on Linux, allows an attacker to obtain potentially sensitive media (such as private pictures) in the Cache and uploadtemps directories. It fails to effectively clear cached pictures, even after deletion…
- risk 0.36cvss 5.5epss 0.00
IBM Security Verify Information Queue 1.0.6 and 1.0.7 could disclose highly sensitive information to a local user due to inproper storage of a plaintext cryptographic key. IBM X-Force ID: 198187.
- risk 0.36cvss 5.5epss 0.00
Telegram before 7.4 (212543) Stable on macOS stores the local copy of self-destructed messages in a sandbox path, leading to sensitive information disclosure.
- risk 0.36cvss 5.5epss 0.00
Telegram before 7.4 (212543) Stable on macOS stores the local passcode in cleartext, leading to information disclosure.
- risk 0.36cvss 5.5epss 0.00
An issue was discovered in SmartFoxServer 2.17.0. Cleartext password disclosure can occur via /config/server.xml.
- risk 0.36cvss 5.5epss 0.00
NCH Express Accounts 8.24 and earlier allows local users to discover the cleartext password by reading the configuration file.
- risk 0.36cvss 5.5epss 0.00
A flaw was found in Ceph-ansible v4.0.41 where it creates an /etc/ceph/iscsi-gateway.conf with insecure default permissions. This flaw allows any user on the system to read sensitive information within this file. The highest threat from this vulnerability is to confidentiality.
- risk 0.36cvss 5.5epss 0.00
The implementation of Brave Desktop's privacy-preserving analytics system (P3A) between 1.1 and 1.18.35 logged the timestamp of when the user last opened an incognito window, including Tor windows. The intended behavior was to log the timestamp for incognito windows excluding…
- risk 0.36cvss 5.5epss 0.00
Jenkins ElasTest Plugin 1.2.1 and earlier stores its server password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.