VYPR

CWE-312

Cleartext Storage of Sensitive Information

BaseDraft

Description

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-37

CVEs mapped to this weakness (848)

page 32 of 43
  • CVE-2022-41248MedSep 21, 2022
    risk 0.34cvss 5.3epss 0.00

    Jenkins BigPanda Notifier Plugin 1.4.0 and earlier does not mask the BigPanda API key on the global configuration form, increasing the potential for attackers to observe and capture it.

  • CVE-2022-2739MedSep 1, 2022
    risk 0.34cvss 5.3epss 0.00

    The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrect version of podman missing the fix for CVE-2020-14370, which was previously fixed via RHSA-2020:5056. This issue could possibly allow an attacker to gain…

  • CVE-2022-26778MedMar 10, 2022
    risk 0.34cvss 5.3epss 0.00

    Veritas System Recovery (VSR) 18 and 21 stores a network destination password in the Windows registry during configuration of the backup configuration. This could allow a Windows user (who has sufficient privileges) to access a network file system that they were not authorized…

  • CVE-2021-36165MedSep 28, 2021
    risk 0.34cvss 5.3epss 0.01

    RICON Industrial Cellular Router S9922L 16.10.3(3794) is affected by cleartext storage of sensitive information and sends username and password as base64.

  • CVE-2021-36096MedSep 6, 2021
    risk 0.34cvss 5.2epss 0.00

    Generated Support Bundles contains private S/MIME and PGP keys if containing folder is not hidden. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.28 and prior versions; 8.0.x version 8.0.15 and prior…

  • CVE-2021-31989MedAug 25, 2021
    risk 0.34cvss 5.3epss 0.00

    A user with permission to log on to the machine hosting the AXIS Device Manager client could under certain conditions extract a memory dump from the built-in Windows Task Manager application. The memory dump may potentially contain credentials of connected Axis devices.

  • CVE-2020-15384MedJun 9, 2021
    risk 0.34cvss 5.3epss 0.01

    Brocade SANNav before version 2.1.1 contains an information disclosure vulnerability. Successful exploitation of internal server information in the initial login response header.

  • CVE-2021-20995MedMay 13, 2021
    risk 0.34cvss 5.3epss 0.01

    In multiple managed switches by WAGO in different versions the webserver cookies of the web based UI contain user credentials.

  • CVE-2019-4687MedJan 13, 2021
    risk 0.34cvss 5.3epss 0.00

    IBM Security Guardium Data Encryption (GDE) 3.0.0.2 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 171823.

  • CVE-2020-35658MedDec 23, 2020
    risk 0.34cvss 5.3epss 0.01

    SpamTitan before 7.09 allows attackers to tamper with backups, because backups are not encrypted.

  • CVE-2020-6648MedOct 21, 2020
    risk 0.34cvss 5.3epss 0.01

    A cleartext storage of sensitive information vulnerability in FortiOS command line interface in versions 6.2.4 and earlier and FortiProxy 2.0.0, 1.2.9 and earlier may allow an authenticated attacker to obtain sensitive information such as users passwords by connecting to…

  • CVE-2020-15784MedSep 9, 2020
    risk 0.34cvss 5.3epss 0.01

    A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP8). Insecure storage of sensitive information in the configuration files could allow the retrieval of user names.

  • CVE-2020-9407MedFeb 26, 2020
    risk 0.34cvss 5.3epss 0.01

    IBL Online Weather before 4.3.5a allows attackers to obtain sensitive information by reading the IWEBSERVICE_JSONRPC_COOKIE cookie.

  • CVE-2025-11009MedDec 17, 2025
    risk 0.33cvss 5.1epss 0.00

    Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GT Designer3 Version1 (GOT2000) all versions and Mitsubishi Electric GT Designer3 Version1 (GOT1000) all versions allows a local unauthenticated attacker to obtain plaintext credentials from the…

  • CVE-2025-53758MedJul 16, 2025
    risk 0.33cvss epss 0.00

    This vulnerability exists in Digisol DG-GR6821AC Router due to use of default admin credentials at its web management interface. An attacker with physical access could exploit this vulnerability by extracting the firmware and reverse engineer the binary data to access the…

  • CVE-2025-53755MedJul 16, 2025
    risk 0.33cvss epss 0.00

    This vulnerability exists in Digisol DG-GR6821AC Router due to storage of credentials and PINS without encryption in the device firmware. An attacker with physical access could exploit this vulnerability by extracting the firmware and reverse engineer the binary data to access…

  • CVE-2024-47056MedMay 28, 2025
    risk 0.33cvss 5.1epss 0.00

    SummaryThis advisory addresses a security vulnerability in Mautic where sensitive .env configuration files may be directly accessible via a web browser. This exposure could lead to the disclosure of sensitive information, including database credentials, API keys, and other…

  • CVE-2025-2189MedMar 11, 2025
    risk 0.33cvss epss 0.00

    This vulnerability exists in the Tinxy smart devices due to storage of credentials in plaintext within the device firmware. An attacker with physical access could exploit this by extracting the firmware and analyzing the binary data to obtain the plaintext credentials stored on…

  • CVE-2024-50570MedDec 18, 2024
    risk 0.33cvss 5.0epss 0.00

    A Cleartext Storage of Sensitive Information vulnerability [CWE-312] in FortiClientWindows 7.4.0 through 7.4.1, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13 and FortiClientLinux 7.4.0 through 7.4.2, 7.2.0 through 7.2.7, 7.0.0 through 7.0.13 may permit a local authenticated user to…

  • CVE-2023-31002MedFeb 7, 2024
    risk 0.33cvss 5.1epss 0.00

    IBM Security Access Manager Container 10.0.0.0 through 10.0.6.1 temporarily stores sensitive information in files that could be accessed by a local user. IBM X-Force ID: 254657.