VYPR

CWE-312

Cleartext Storage of Sensitive Information

BaseDraft

Description

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-37

CVEs mapped to this weakness (886)

page 35 of 45
  • CVE-2021-27233MedFeb 16, 2021
    risk 0.32cvss 4.9epss 0.01

    An issue was discovered in Mutare Voice (EVM) 3.x before 3.3.8. On the admin portal of the web application, password information for external systems is visible in cleartext. The Settings.asp page is affected by this issue.

  • CVE-2020-11415MedApr 27, 2020
    risk 0.32cvss 4.9epss 0.01

    An issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.17 and 3.x before 3.22.1. Admin users can retrieve the LDAP server system username/password (as configured in nxrm) in cleartext.

  • CVE-2019-18615MedDec 19, 2019
    risk 0.32cvss 4.9epss 0.00

    In CloudVision Portal (CVP) for all releases in the 2018.2 Train, under certain conditions, the application logs user passwords in plain text for certain API calls, potentially leading to user password exposure. This only affects CVP environments where: 1. Devices have enable…

  • CVE-2019-13947MedDec 12, 2019
    risk 0.32cvss 4.9epss 0.01

    A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The user configuration menu in the web interface of the Control Center Server (CCS) transfers user passwords in clear to the client (browser). An attacker with administrative privileges…

  • CVE-2026-63406MedSep 18, 2026
    risk 0.31cvss 5.9epss 0.00

    AnyCable is a realtime server for reliable two-way communication that supports any backend. Prior to 1.6.15, the telemetry subsystem in telemetry/config.go enables tracking with a hardcoded public authToken, while clusterFingerprint in telemetry/telemetry.go reads the full…

  • CVE-2026-77970MedAug 30, 2026
    risk 0.31cvss —epss 0.00

    Cleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover sensitive values nested inside embedded resources, unions, or lists. sensitive_attributes :redact and :ignore…

  • CVE-2026-75847MedAug 30, 2026
    risk 0.31cvss —epss 0.00

    Cleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover the plaintext of sensitive? attributes. AshPaperTrail stores the values of tracked sensitive? attributes in…

  • CVE-2025-53103MedJul 1, 2025
    risk 0.31cvss 5.8epss 0.00

    JUnit is a testing framework for Java and the JVM. From version 5.12.0 to 5.13.1, JUnit's support for writing Open Test Reporting XML files can leak Git credentials. The impact depends on the level of the access token exposed through the OpenTestReportGeneratingListener. If…

  • CVE-2020-23249MedJan 5, 2021
    risk 0.31cvss 4.7epss 0.00

    GigaVUE-OS (GVOS) 5.4 - 5.9 stores a Redis database password in plaintext.

  • CVE-2018-1882MedApr 8, 2019
    risk 0.31cvss 4.7epss 0.00

    In a certain atypical IBM Spectrum Protect 7.1 and 8.1 configurations, the node password could be displayed in plain text in the IBM Spectrum Protect client trace file. IBM X-Force ID: 151968.

  • CVE-2024-53651MedFeb 11, 2025
    risk 0.30cvss 4.6epss 0.00

    A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 6MD85 (CP300) (All versions), SIPROTEC 5 6MD86 (CP200) (All versions), SIPROTEC 5 6MD86 (CP300) (All versions), SIPROTEC 5 6MD89 (CP300) (All…

  • CVE-2024-45718MedFeb 11, 2025
    risk 0.30cvss 4.6epss 0.00

    Sensitive data could be exposed to non- privileged users in a configuration file. Local access to the computer with a low- privileged account is required to access the configuration file containing the sensitive data.

  • CVE-2024-10523MedNov 4, 2024
    risk 0.30cvss 4.6epss 0.00

    This vulnerability exists in TP-Link IoT Smart Hub due to storage of Wi-Fi credentials in plain text within the device firmware. An attacker with physical access could exploit this by extracting the firmware and analyzing the binary data to obtain the Wi-Fi credentials stored on…

  • CVE-2024-41691MedJul 26, 2024
    risk 0.30cvss 4.6epss 0.00

    This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to storing of FTP credentials in plaintext within the SquashFS-root filesystem associated with the router's firmware. An attacker with physical access could exploit this by extracting the firmware and reverse…

  • CVE-2024-41690MedJul 26, 2024
    risk 0.30cvss 4.6epss 0.00

    This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to storing of default username and password credentials in plaintext within the router's firmware/ database. An attacker with physical access could exploit this by extracting the firmware and reverse engineer…

  • CVE-2024-41689MedJul 26, 2024
    risk 0.30cvss 4.6epss 0.00

    This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to unencrypted storing of WPA/ WPS credentials within the router's firmware/ database. An attacker with physical access could exploit this by extracting the firmware and reverse engineer the binary data to…

  • CVE-2024-41688MedJul 26, 2024
    risk 0.30cvss 4.6epss 0.00

    This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due lack of encryption in storing of usernames and passwords within the router's firmware/ database. An attacker with physical access could exploit this by extracting the firmware and reverse engineer the binary…

  • CVE-2024-38280MedJun 13, 2024
    risk 0.30cvss 4.6epss 0.00

    An unauthorized user is able to gain access to sensitive data, including credentials, by physically retrieving the hard disk of the product as the data is stored in clear text.

  • CVE-2023-28345MedMay 31, 2023
    risk 0.30cvss 4.6epss 0.00

    An issue was discovered in Faronics Insight 10.0.19045 on Windows. The Insight Teacher Console application exposes the teacher's Console password in cleartext via an API endpoint accessible from localhost. Attackers with physical access to the Teacher Console can open a web…

  • CVE-2023-23776MedMar 7, 2023
    risk 0.30cvss 4.6epss 0.00

    An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in FortiAnalyzer versions 7.2.0 through 7.2.1, 7.0.0 through 7.0.4 and 6.4.0 through 6.4.10 may allow a remote authenticated attacker to read the client machine password in plain text in a…