VYPR

CWE-312

Cleartext Storage of Sensitive Information

BaseDraft

Description

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-37

CVEs mapped to this weakness (885)

page 4 of 45
  • CVE-2019-11966HigJun 5, 2019
    risk 0.57cvss 8.8epss 0.02

    A remote privilege escalation vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

  • CVE-2017-9654HigApr 24, 2018
    risk 0.57cvss 8.8epss 0.01

    The Philips DoseWise Portal web-based application versions 1.1.7.333 and 2.1.1.3069 stores login credentials in clear text within backend system files. CVSS v3 base score: 6.5, CVSS vector string: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N.

  • CVE-2025-51055HigAug 6, 2025
    risk 0.56cvss 8.6epss 0.00

    Insecure Data Storage of credentials has been found in /api_vedo/configuration/config.yml file in Vedo Suite version 2024.17. This file contains clear-text credentials, secret keys, and database information.

  • CVE-2023-3489HigAug 31, 2023
    risk 0.56cvss 8.6epss 0.00

    The firmwaredownload command on Brocade Fabric OS v9.2.0 could log the FTP/SFTP/SCP server password in clear text in the SupportSave file when performing a downgrade from Fabric OS v9.2.0 to any earlier version of Fabric OS.

  • CVE-2022-25164HigNov 25, 2022
    risk 0.56cvss 8.6epss 0.01

    Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.095Z and Mitsubishi Electric MX OPC UA Module Configurator-R versions 1.08J and prior allows a remote unauthenticated attacker to disclose sensitive information.…

  • CVE-2021-40527HigOct 25, 2021
    risk 0.56cvss 8.6epss 0.01

    Exposure of senstive information to an unauthorised actor in the "com.onepeloton.erlich" mobile application up to and including version 1.7.22 allows a remote attacker to access developer files stored in an AWS S3 bucket, by reading credentials stored in plain text within the…

  • CVE-2020-3921HigMar 27, 2020
    risk 0.56cvss 8.6epss 0.01

    UltraLog Express device management software stores user’s information in cleartext. Any user can obtain accounts information through a specific page.

  • CVE-2024-8070HigOct 13, 2024
    risk 0.55cvss 8.5epss 0.00

    CWE-312: Cleartext Storage of Sensitive Information vulnerability exists that exposes test credentials in the firmware binary

  • CVE-2024-28327HigApr 26, 2024
    risk 0.55cvss 8.4epss 0.00

    Asus RT-N12+ B1 router stores user passwords in plaintext, which could allow local attackers to obtain unauthorized access and modify router settings.

  • CVE-2022-29090HigAug 10, 2022
    risk 0.55cvss 8.5epss 0.00

    Dell Wyse Management Suite 3.6.1 and below contains a Sensitive Data Exposure vulnerability. A low privileged malicious user could potentially exploit this vulnerability in order to obtain credentials. The attacker may be able to use the exposed credentials to access the target…

  • CVE-2020-27613HigOct 21, 2020
    risk 0.55cvss 8.4epss 0.00

    The installation procedure in BigBlueButton before 2.2.28 (or earlier) uses ClueCon as the FreeSWITCH password, which allows local users to achieve unintended FreeSWITCH access.

  • CVE-2019-14890HigNov 26, 2019
    risk 0.55cvss 8.4epss 0.00

    A vulnerability was found in Ansible Tower before 3.6.1 where an attacker with low privilege could retrieve usernames and passwords credentials from the new RHSM saved in plain text into the database at '/api/v2/config' when applying the Ansible Tower license.

  • CVE-2025-32353HigJul 16, 2025
    risk 0.53cvss 8.2epss 0.00

    Kaseya Rapid Fire Tools Network Detective 2.0.16.0 has Unencrypted Credentials (for privileged access) stored in the collector.txt configuration file.

  • CVE-2025-46634HigMay 1, 2025
    risk 0.53cvss 8.2epss 0.00

    Cleartext transmission of sensitive information in the web management portal of the Tenda RX2 Pro 16.03.30.14 may allow an unauthenticated attacker to authenticate to the web management portal by collecting credentials from observed/collected traffic. It implements encryption,…

  • CVE-2025-46633HigMay 1, 2025
    risk 0.53cvss 8.2epss 0.00

    Cleartext transmission of sensitive information in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an attacker to decrypt traffic between the client and server by collecting the symmetric AES key from collected and/or observed traffic. The AES key in sent in…

  • CVE-2025-23215CriJan 31, 2025
    risk 0.53cvss —epss 0.00

    PMD is an extensible multilanguage static code analyzer. The passphrase for the PMD and PMD Designer release signing keys are included in jar published to Maven Central. The private key itself is not known to have been compromised itself, but given its passphrase is, it must…

  • CVE-2024-41716HigSep 4, 2024
    risk 0.53cvss 8.1epss 0.00

    Cleartext storage of sensitive information vulnerability exists in WindLDR and WindO/I-NV4. If this vulnerability is exploited, an attacker who obtained the product's project file may obtain user credentials of the PLC or Operator Interfaces. As a result, an attacker may be able…

  • CVE-2021-22509HigAug 28, 2024
    risk 0.53cvss 8.1epss 0.00

    A vulnerability identified in storing and reusing information in Advance Authentication. This issue can lead to leakage of sensitive data to unauthorized user. The issue affects NetIQ Advance Authentication before 6.3.5.1

  • CVE-2024-38877HigAug 2, 2024
    risk 0.53cvss 8.2epss 0.00

    A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 Domain Controller R9.2 (All versions), Omnivise T3000 Network Intrusion Detection System (NIDS) R9.2 (All versions), Omnivise T3000 Product Data Management (PDM) R9.2…

  • CVE-2023-28713HigJun 1, 2023
    risk 0.53cvss 8.1epss 0.00

    Plaintext storage of a password exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. Because account information of the database is saved in a local file in plaintext, a user who can access the PC where the affected product is installed can obtain the information. As a…