VYPR

CWE-312

Cleartext Storage of Sensitive Information

BaseDraft

Description

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-37

CVEs mapped to this weakness (885)

page 29 of 45
  • CVE-2021-40454MedOct 13, 2021
    risk 0.36cvss 5.5epss 0.01

    Rich Text Edit Control Information Disclosure Vulnerability

  • CVE-2021-29904MedSep 23, 2021
    risk 0.36cvss 5.5epss 0.00

    IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI displays user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 207610.

  • CVE-2021-37452MedJul 25, 2021
    risk 0.36cvss 5.5epss 0.00

    NCH Quorum v2.03 and earlier allows local users to discover cleartext login information relating to users by reading the local .dat configuration files.

  • CVE-2021-27487MedJun 16, 2021
    risk 0.36cvss 5.5epss 0.00

    ZOLL Defibrillator Dashboard, v prior to 2.2, The affected products contain credentials stored in plaintext. This could allow an attacker to gain access to sensitive information.

  • CVE-2021-28858MedJun 15, 2021
    risk 0.36cvss 5.5epss 0.00

    TP-Link's TL-WPA4220 4.0.2 Build 20180308 Rel.37064 does not use SSL by default. Attacker on the local network can monitor traffic and capture the cookie and other sensitive information.

  • CVE-2018-16498MedMay 26, 2021
    risk 0.36cvss 5.5epss 0.00

    In Versa Director, the unencrypted backup files stored on the Versa deployment contain credentials stored within configuration files. These credentials are for various application components such as SNMP, and SSL and Trust keystores.

  • CVE-2021-31539MedApr 23, 2021
    risk 0.36cvss 5.5epss 0.00

    Wowza Streaming Engine before 4.8.8.01 (in a default installation) has cleartext passwords stored in the conf/admin.password file. A regular local user is able to read usernames and passwords.

  • CVE-2020-11924MedApr 2, 2021
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in WiZ Colors A60 1.14.0. Wi-Fi credentials are stored in cleartext in flash memory, which presents an information-disclosure risk for a discarded or resold device.

  • CVE-2020-11923MedApr 2, 2021
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in WiZ Colors A60 1.14.0. API credentials are locally logged.

  • CVE-2020-4944MedMar 30, 2021
    risk 0.36cvss 5.5epss 0.00

    IBM UrbanCode Deploy (UCD) 7.0.3.0, 7.0.4.0, 7.0.5.3, 7.0.5.4, 7.1.0.0, 7.1.1.0, 7.1.1.1, and 7.1.1.2, stores keystore passwords in plain text after a manual edit, which can be read by a local user. IBM X-Force ID: 191944.

  • CVE-2020-4884MedMar 30, 2021
    risk 0.36cvss 5.5epss 0.00

    IBM UrbanCode Deploy (UCD) 6.2.7.9, 7.0.5.4, and 7.1.1.1 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 190908.

  • CVE-2021-23827MedFeb 23, 2021
    risk 0.36cvss 5.5epss 0.00

    Keybase Desktop Client before 5.6.0 on Windows and macOS, and before 5.6.1 on Linux, allows an attacker to obtain potentially sensitive media (such as private pictures) in the Cache and uploadtemps directories. It fails to effectively clear cached pictures, even after deletion…

  • CVE-2021-20408MedFeb 12, 2021
    risk 0.36cvss 5.5epss 0.00

    IBM Security Verify Information Queue 1.0.6 and 1.0.7 could disclose highly sensitive information to a local user due to inproper storage of a plaintext cryptographic key. IBM X-Force ID: 198187.

  • CVE-2021-27205MedFeb 12, 2021
    risk 0.36cvss 5.5epss 0.00

    Telegram before 7.4 (212543) Stable on macOS stores the local copy of self-destructed messages in a sandbox path, leading to sensitive information disclosure.

  • CVE-2021-27204MedFeb 12, 2021
    risk 0.36cvss 5.5epss 0.00

    Telegram before 7.4 (212543) Stable on macOS stores the local passcode in cleartext, leading to information disclosure.

  • CVE-2021-26550MedFeb 9, 2021
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in SmartFoxServer 2.17.0. Cleartext password disclosure can occur via /config/server.xml.

  • CVE-2020-13473MedDec 28, 2020
    risk 0.36cvss 5.5epss 0.00

    NCH Express Accounts 8.24 and earlier allows local users to discover the cleartext password by reading the configuration file.

  • CVE-2020-25677MedDec 8, 2020
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in Ceph-ansible v4.0.41 where it creates an /etc/ceph/iscsi-gateway.conf with insecure default permissions. This flaw allows any user on the system to read sensitive information within this file. The highest threat from this vulnerability is to confidentiality.

  • CVE-2020-8276MedNov 9, 2020
    risk 0.36cvss 5.5epss 0.00

    The implementation of Brave Desktop's privacy-preserving analytics system (P3A) between 1.1 and 1.18.35 logged the timestamp of when the user last opened an incognito window, including Tor windows. The intended behavior was to log the timestamp for incognito windows excluding…

  • CVE-2020-2274MedSep 16, 2020
    risk 0.36cvss 5.5epss 0.00

    Jenkins ElasTest Plugin 1.2.1 and earlier stores its server password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.