VYPR

CWE-312

Cleartext Storage of Sensitive Information

BaseDraft

Description

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-37

CVEs mapped to this weakness (885)

page 40 of 45
  • CVE-2019-10447MedOct 16, 2019
    risk 0.28cvss 4.3epss 0.01

    Jenkins Sofy.AI Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.

  • CVE-2018-19279MedNov 14, 2018
    risk 0.28cvss 4.3epss 0.00

    PRIMX ZoneCentral before 6.1.2236 on Windows sometimes leaks the plaintext of NTFS files. On non-SSD devices, this is limited to a 5-second window and file sizes less than 600 bytes. The effect on SSD devices may be greater.

  • CVE-2025-59701MedDec 2, 2025
    risk 0.27cvss 4.1epss 0.00

    Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker (with elevated privileges) to read and modify the Appliance SSD contents (because they are unencrypted).

  • CVE-2025-59792MedNov 28, 2025
    risk 0.27cvss 5.3epss 0.00

    Reveals plaintext credentials in the MONITOR command vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 1.0.0 through 2.13.0. Users are recommended to upgrade to version 2.14.0, which fixes the issue.

  • CVE-2025-54855MedSep 23, 2025
    risk 0.27cvss 4.2epss 0.00

    Cleartext storage of sensitive information was discovered in Click Programming Software version v3.60. The vulnerability can be exploited by a local user with access to the file system, while an administrator session is active, to steal credentials stored in clear text.

  • CVE-2024-35282MedSep 10, 2024
    risk 0.27cvss 4.2epss 0.00

    A cleartext storage of sensitive information in memory vulnerability [CWE-316] affecting FortiClient VPN iOS 7.2 all versions, 7.0 all versions, 6.4 all versions, 6.2 all versions, 6.0 all versions may allow an unauthenticated attacker that has physical access to a jailbroken…

  • CVE-2024-39732MedJul 14, 2024
    risk 0.27cvss 4.1epss 0.00

    IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 temporarily stores data from different environments that could be obtained by a malicious user. IBM X-Force ID: 295791.

  • CVE-2024-28024MedJun 11, 2024
    risk 0.27cvss 4.1epss 0.00

    A vulnerability exists in the FOXMAN-UN/UNEM in which sensitive information is stored in cleartext within a resource that might be accessible to another control sphere.

  • CVE-2022-46141MedDec 12, 2023
    risk 0.27cvss 4.2epss 0.00

    A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) (All versions < V19). An information disclosure vulnerability could allow a local attacker to gain access to the access level password of the SIMATIC S7-1200 and S7-1500 CPUs, when entered by a legitimate user in…

  • CVE-2023-32983MedMay 16, 2023
    risk 0.27cvss 5.3epss 0.00

    Jenkins Ansible Plugin 204.v8191fd551eb_f and earlier does not mask extra variables displayed on the configuration form, increasing the potential for attackers to observe and capture them.

  • CVE-2023-0005MedApr 12, 2023
    risk 0.27cvss 4.1epss 0.00

    A vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to expose the plaintext values of secrets stored in the device configuration and encrypted API keys.

  • CVE-2022-34910MedFeb 27, 2023
    risk 0.27cvss 4.1epss 0.00

    An issue was discovered in the A4N (Aremis 4 Nomad) application 1.5.0 for Android. It uses a local database to store data and accounts. However, the password is stored in cleartext. Therefore, an attacker can retrieve the passwords of other users that used the same device.

  • CVE-2022-22470MedJan 9, 2023
    risk 0.27cvss 4.1epss 0.00

    IBM Security Verify Governance 10.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 225232.

  • CVE-2022-26390MedSep 9, 2022
    risk 0.27cvss 4.2epss 0.00

    The Baxter Spectrum Wireless Battery Module (WBM) stores network credentials and PHI (only applicable to Spectrum IQ pumps using auto programming) in unencrypted form. An attacker with physical access to a device that hasn't had all data and settings erased may be able to…

  • CVE-2021-22300MedFeb 6, 2021
    risk 0.27cvss 4.1epss 0.00

    There is an information leak vulnerability in eCNS280_TD versions V100R005C00 and V100R005C10. A command does not have timeout exit mechanism. Temporary file contains sensitive information. This allows attackers to obtain information by inter-process access that requires other…

  • CVE-2018-10812MedMay 8, 2018
    risk 0.27cvss 4.1epss 0.00

    The Bitpie application through 3.2.4 for Android and iOS uses cleartext storage for digital currency initial keys, which allows local users to steal currency by leveraging root access to read /com.biepie/shared_prefs/com.bitpie_preferences.xml (on Android) or a plist file in the…

  • CVE-2025-55717MedMar 10, 2026
    risk 0.26cvss 4.0epss 0.00

    A cleartext storage of sensitive information vulnerability [CWE-312] vulnerability in Fortinet FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiRecorder 7.2.0 through 7.2.3, FortiRecorder 7.0 all…

  • CVE-2025-49728MedSep 16, 2025
    risk 0.26cvss 4.0epss 0.00

    Cleartext storage of sensitive information in Microsoft PC Manager allows an unauthorized attacker to bypass a security feature locally.

  • CVE-2023-48707MedNov 24, 2023
    risk 0.26cvss 5.0epss 0.00

    CodeIgniter Shield is an authentication and authorization provider for CodeIgniter 4. The `secretKey` value is an important key for HMAC SHA256 authentication and in affected versions was stored in the database in cleartext form. If a malicious person somehow had access to the…

  • CVE-2022-27549MedJul 6, 2022
    risk 0.26cvss 4.0epss 0.00

    HCL Launch may store certain data for recurring activities in a plain text format.