VYPR

CWE-312

Cleartext Storage of Sensitive Information

BaseDraft

Description

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-37

CVEs mapped to this weakness (848)

page 4 of 43
  • CVE-2023-3489HigAug 31, 2023
    risk 0.56cvss 8.6epss 0.00

    The firmwaredownload command on Brocade Fabric OS v9.2.0 could log the FTP/SFTP/SCP server password in clear text in the SupportSave file when performing a downgrade from Fabric OS v9.2.0 to any earlier version of Fabric OS.

  • CVE-2022-25164HigNov 25, 2022
    risk 0.56cvss 8.6epss 0.01

    Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.095Z and Mitsubishi Electric MX OPC UA Module Configurator-R versions 1.08J and prior allows a remote unauthenticated attacker to disclose sensitive information.…

  • CVE-2021-40527HigOct 25, 2021
    risk 0.56cvss 8.6epss 0.01

    Exposure of senstive information to an unauthorised actor in the "com.onepeloton.erlich" mobile application up to and including version 1.7.22 allows a remote attacker to access developer files stored in an AWS S3 bucket, by reading credentials stored in plain text within the…

  • CVE-2020-3921HigMar 27, 2020
    risk 0.56cvss 8.6epss 0.01

    UltraLog Express device management software stores user’s information in cleartext. Any user can obtain accounts information through a specific page.

  • CVE-2024-8070HigOct 13, 2024
    risk 0.55cvss 8.5epss 0.00

    CWE-312: Cleartext Storage of Sensitive Information vulnerability exists that exposes test credentials in the firmware binary

  • CVE-2024-28327HigApr 26, 2024
    risk 0.55cvss 8.4epss 0.00

    Asus RT-N12+ B1 router stores user passwords in plaintext, which could allow local attackers to obtain unauthorized access and modify router settings.

  • CVE-2022-29090HigAug 10, 2022
    risk 0.55cvss 8.5epss 0.00

    Dell Wyse Management Suite 3.6.1 and below contains a Sensitive Data Exposure vulnerability. A low privileged malicious user could potentially exploit this vulnerability in order to obtain credentials. The attacker may be able to use the exposed credentials to access the target…

  • CVE-2020-27613HigOct 21, 2020
    risk 0.55cvss 8.4epss 0.00

    The installation procedure in BigBlueButton before 2.2.28 (or earlier) uses ClueCon as the FreeSWITCH password, which allows local users to achieve unintended FreeSWITCH access.

  • CVE-2019-14890HigNov 26, 2019
    risk 0.55cvss 8.4epss 0.00

    A vulnerability was found in Ansible Tower before 3.6.1 where an attacker with low privilege could retrieve usernames and passwords credentials from the new RHSM saved in plain text into the database at '/api/v2/config' when applying the Ansible Tower license.

  • CVE-2025-32353HigJul 16, 2025
    risk 0.53cvss 8.2epss 0.00

    Kaseya Rapid Fire Tools Network Detective 2.0.16.0 has Unencrypted Credentials (for privileged access) stored in the collector.txt configuration file.

  • CVE-2025-46634HigMay 1, 2025
    risk 0.53cvss 8.2epss 0.00

    Cleartext transmission of sensitive information in the web management portal of the Tenda RX2 Pro 16.03.30.14 may allow an unauthenticated attacker to authenticate to the web management portal by collecting credentials from observed/collected traffic. It implements encryption,…

  • CVE-2025-46633HigMay 1, 2025
    risk 0.53cvss 8.2epss 0.00

    Cleartext transmission of sensitive information in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an attacker to decrypt traffic between the client and server by collecting the symmetric AES key from collected and/or observed traffic. The AES key in sent in…

  • CVE-2025-23215CriJan 31, 2025
    risk 0.53cvss epss 0.00

    PMD is an extensible multilanguage static code analyzer. The passphrase for the PMD and PMD Designer release signing keys are included in jar published to Maven Central. The private key itself is not known to have been compromised itself, but given its passphrase is, it must…

  • CVE-2024-41716HigSep 4, 2024
    risk 0.53cvss 8.1epss 0.00

    Cleartext storage of sensitive information vulnerability exists in WindLDR and WindO/I-NV4. If this vulnerability is exploited, an attacker who obtained the product's project file may obtain user credentials of the PLC or Operator Interfaces. As a result, an attacker may be able…

  • CVE-2021-22509HigAug 28, 2024
    risk 0.53cvss 8.1epss 0.00

    A vulnerability identified in storing and reusing information in Advance Authentication. This issue can lead to leakage of sensitive data to unauthorized user. The issue affects NetIQ Advance Authentication before 6.3.5.1

  • CVE-2024-38877HigAug 2, 2024
    risk 0.53cvss 8.2epss 0.00

    A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 Domain Controller R9.2 (All versions), Omnivise T3000 Network Intrusion Detection System (NIDS) R9.2 (All versions), Omnivise T3000 Product Data Management (PDM) R9.2…

  • CVE-2023-28713HigJun 1, 2023
    risk 0.53cvss 8.1epss 0.00

    Plaintext storage of a password exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. Because account information of the database is saved in a local file in plaintext, a user who can access the PC where the affected product is installed can obtain the information. As a…

  • CVE-2022-0835HigApr 11, 2022
    risk 0.53cvss 8.1epss 0.00

    AVEVA System Platform 2020 stores sensitive information in cleartext, which may allow access to an attacker or a low-privileged user.

  • CVE-2020-26228HigNov 23, 2020
    risk 0.53cvss 8.1epss 0.01

    TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 9.5.23 and 10.4.10 user session identifiers were stored in cleartext - without processing with additional cryptographic hashing algorithms. This vulnerability cannot be exploited directly…

  • CVE-2019-3767HigOct 14, 2019
    risk 0.53cvss 8.2epss 0.00

    Dell ImageAssist versions prior to 8.7.15 contain an information disclosure vulnerability. Dell ImageAssist stores some sensitive encrypted information in the images it creates. A privileged user of a system running an operating system that was deployed with Dell ImageAssist…