VYPR

CWE-312

Cleartext Storage of Sensitive Information

BaseDraft

Description

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-37

CVEs mapped to this weakness (848)

page 34 of 43
  • CVE-2020-23249MedJan 5, 2021
    risk 0.31cvss 4.7epss 0.00

    GigaVUE-OS (GVOS) 5.4 - 5.9 stores a Redis database password in plaintext.

  • CVE-2018-1882MedApr 8, 2019
    risk 0.31cvss 4.7epss 0.00

    In a certain atypical IBM Spectrum Protect 7.1 and 8.1 configurations, the node password could be displayed in plain text in the IBM Spectrum Protect client trace file. IBM X-Force ID: 151968.

  • CVE-2024-53651MedFeb 11, 2025
    risk 0.30cvss 4.6epss 0.00

    A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 6MD85 (CP300) (All versions), SIPROTEC 5 6MD86 (CP200) (All versions), SIPROTEC 5 6MD86 (CP300) (All versions), SIPROTEC 5 6MD89 (CP300) (All…

  • CVE-2024-45718MedFeb 11, 2025
    risk 0.30cvss 4.6epss 0.00

    Sensitive data could be exposed to non- privileged users in a configuration file. Local access to the computer with a low- privileged account is required to access the configuration file containing the sensitive data.

  • CVE-2024-10523MedNov 4, 2024
    risk 0.30cvss 4.6epss 0.00

    This vulnerability exists in TP-Link IoT Smart Hub due to storage of Wi-Fi credentials in plain text within the device firmware. An attacker with physical access could exploit this by extracting the firmware and analyzing the binary data to obtain the Wi-Fi credentials stored on…

  • CVE-2024-41691MedJul 26, 2024
    risk 0.30cvss 4.6epss 0.00

    This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to storing of FTP credentials in plaintext within the SquashFS-root filesystem associated with the router's firmware. An attacker with physical access could exploit this by extracting the firmware and reverse…

  • CVE-2024-41690MedJul 26, 2024
    risk 0.30cvss 4.6epss 0.00

    This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to storing of default username and password credentials in plaintext within the router's firmware/ database. An attacker with physical access could exploit this by extracting the firmware and reverse engineer…

  • CVE-2024-41689MedJul 26, 2024
    risk 0.30cvss 4.6epss 0.00

    This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to unencrypted storing of WPA/ WPS credentials within the router's firmware/ database. An attacker with physical access could exploit this by extracting the firmware and reverse engineer the binary data to…

  • CVE-2024-41688MedJul 26, 2024
    risk 0.30cvss 4.6epss 0.00

    This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due lack of encryption in storing of usernames and passwords within the router's firmware/ database. An attacker with physical access could exploit this by extracting the firmware and reverse engineer the binary…

  • CVE-2024-38280MedJun 13, 2024
    risk 0.30cvss 4.6epss 0.00

    An unauthorized user is able to gain access to sensitive data, including credentials, by physically retrieving the hard disk of the product as the data is stored in clear text.

  • CVE-2023-28345MedMay 31, 2023
    risk 0.30cvss 4.6epss 0.00

    An issue was discovered in Faronics Insight 10.0.19045 on Windows. The Insight Teacher Console application exposes the teacher's Console password in cleartext via an API endpoint accessible from localhost. Attackers with physical access to the Teacher Console can open a web…

  • CVE-2023-23776MedMar 7, 2023
    risk 0.30cvss 4.6epss 0.00

    An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in FortiAnalyzer versions 7.2.0 through 7.2.1, 7.0.0 through 7.0.4 and 6.4.0 through 6.4.10 may allow a remote authenticated attacker to read the client machine password in plain text in a…

  • CVE-2022-41740MedJan 5, 2023
    risk 0.30cvss 4.6epss 0.00

    IBM Robotic Process Automation 20.12 through 21.0.6 could allow an attacker with physical access to the system to obtain highly sensitive information from system memory. IBM X-Force ID: 238053.

  • CVE-2022-24120MedDec 26, 2022
    risk 0.30cvss 4.6epss 0.00

    Certain General Electric Renewable Energy products store cleartext credentials in flash memory. This affects iNET and iNET II before 8.3.0.

  • CVE-2022-20660MedJan 14, 2022
    risk 0.30cvss 4.6epss 0.00

    A vulnerability in the information storage architecture of several Cisco IP Phone models could allow an unauthenticated, physical attacker to obtain confidential information from an affected device. This vulnerability is due to unencrypted storage of confidential information on…

  • CVE-2021-25692MedApr 6, 2021
    risk 0.30cvss 4.6epss 0.00

    Sensitive smart card data is logged in default INFO logs by Teradici's PCoIP Connection Manager and Security Gateway prior to version 21.01.3.

  • CVE-2019-18254MedJun 29, 2020
    risk 0.30cvss 4.6epss 0.00

    BIOTRONIK CardioMessenger II, The affected products do not encrypt sensitive information while at rest. An attacker with physical access to the CardioMessenger can disclose medical measurement data and the serial number from the implanted cardiac device the CardioMessenger is…

  • CVE-2018-18984MedDec 14, 2018
    risk 0.30cvss 4.6epss 0.00

    Medtronic CareLink and Encore Programmers do not encrypt or do not sufficiently encrypt sensitive PII and PHI information while at rest .

  • CVE-2026-42408MedMay 13, 2026
    risk 0.29cvss 4.4epss 0.00

    When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed TMOS Shell (tmsh) command that may allow a highly privileged authenticated attacker to view sensitive information.  Note: Software versions which have reached End of Technical Support (EoTS) are not…

  • CVE-2026-28758MedMay 13, 2026
    risk 0.29cvss 4.4epss 0.00

    When BIG-IP DNS is provisioned, a vulnerability exists in the gtm_add and bigip_add iControl REST commands that return the ssh-password parameter in cleartext in the iControl REST response and is also logged in the audit log. This may allow a highly privileged, authenticated…