VYPR

CWE-312

Cleartext Storage of Sensitive Information

BaseDraft

Description

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-37

CVEs mapped to this weakness (848)

page 5 of 43
  • CVE-2019-9872HigJul 3, 2019
    risk 0.53cvss 8.1epss 0.01

    In several versions of JetBrains IntelliJ IDEA Ultimate, creating run configurations for cloud application servers leads to saving a cleartext unencrypted record of the server credentials in the IDE configuration files. If the Settings Repository plugin was then used and…

  • CVE-2026-47702CriAug 11, 2026
    risk 0.52cvss epss 0.00

    TypeBot is a chatbot builder tool. In version 3.16.1, API tokens (bearer credentials used to authenticate against the builder API) are stored in the database as cleartext strings. An attacker who gains read access to the database (e.g., via SQL injection, backup exposure, or…

  • CVE-2026-33026CriMar 30, 2026
    risk 0.52cvss 9.1epss 0.00

    Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui backup restore mechanism allows attackers to tamper with encrypted backup archives and inject malicious configuration during restoration. This issue has been patched in version 2.3.4.

  • CVE-2023-50957HigFeb 10, 2024
    risk 0.52cvss 8.0epss 0.00

    IBM Storage Defender - Resiliency Service 2.0 could allow a privileged user to perform unauthorized actions after obtaining encrypted data from clear text key storage. IBM X-Force ID: 275783.

  • CVE-2013-2680HigFeb 5, 2020
    risk 0.52cvss 7.5epss 0.09

    Cisco Linksys E4200 1.0.05 Build 7 devices store passwords in cleartext allowing remote attackers to obtain sensitive information.

  • CVE-2009-0964HigMar 19, 2009
    risk 0.52cvss 7.5epss 0.02

    UserView_list.php in PHPRunner 4.2, and possibly earlier, stores passwords in cleartext in the database, which allows attackers to gain privileges. NOTE: this can be leveraged with a separate SQL injection vulnerability to obtain passwords remotely without authentication.

  • CVE-2008-6157HigFeb 17, 2009
    risk 0.52cvss 7.5epss 0.03

    SepCity Classified Ads stores the admin password in cleartext in data/classifieds.mdb, which allows context-dependent attackers to obtain sensitive information.

  • CVE-2025-34428HigDec 10, 2025
    risk 0.51cvss 7.8epss 0.00

    MailEnable versions prior to 10.54 contain a cleartext storage of credentials vulnerability that can lead to local credential compromise and account takeover. The product stores user and administrative passwords in plaintext within AUTH.SAV with overly permissive filesystem…

  • CVE-2025-34427HigDec 10, 2025
    risk 0.51cvss 7.8epss 0.00

    MailEnable versions prior to 10.54 contain a cleartext storage of credentials vulnerability that can lead to local credential compromise and account takeover. The product stores user and administrative passwords in plaintext within AUTH.TAB with overly permissive filesystem…

  • CVE-2025-34200HigSep 19, 2025
    risk 0.51cvss 7.8epss 0.00

    Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA and SaaS deployments) provision the appliance with the network account credentials in clear-text inside /etc/issue, and the file is world-readable by default. An attacker with local shell access can…

  • CVE-2025-50777HigJul 30, 2025
    risk 0.51cvss 7.8epss 0.00

    The firmware of the AZIOT 2MP Full HD Smart Wi-Fi CCTV Home Security Camera (version V1.00.02) contains an Incorrect Access Control vulnerability that allows local attackers to gain root shell access. Once accessed, the device exposes critical data including Wi-Fi credentials…

  • CVE-2023-49113HigJun 20, 2024
    risk 0.51cvss 7.8epss 0.00

    The Kiuwan Local Analyzer (KLA) Java scanning application contains several hard-coded secrets in plain text format. In some cases, this can potentially compromise the confidentiality of the scan results. Several credentials were found in the JAR files of the Kiuwan Local…

  • CVE-2023-2809HigOct 4, 2023
    risk 0.51cvss 7.8epss 0.00

    Plaintext credential usage vulnerability in Sage 200 Spain 2023.38.001 version, the exploitation of which could allow a remote attacker to extract SQL database credentials from the DLL application. This vulnerability could be linked to known techniques to obtain remote execution…

  • CVE-2023-26593HigApr 11, 2023
    risk 0.51cvss 7.8epss 0.00

    CENTUM series provided by Yokogawa Electric Corporation are vulnerable to cleartext storage of sensitive information. If an attacker who can login or access the computer where the affected product is installed tampers the password file stored in the computer, the user privilege…

  • CVE-2022-22031HigJul 12, 2022
    risk 0.51cvss 7.8epss 0.01

    Windows Credential Guard Domain-joined Public Key Elevation of Privilege Vulnerability

  • CVE-2022-28214HigMay 11, 2022
    risk 0.51cvss 7.8epss 0.00

    During an update of SAP BusinessObjects Enterprise, Central Management Server (CMS) - versions 420, 430, authentication credentials are being exposed in Sysmon event logs. This Information Disclosure could cause a high impact on systems’ Confidentiality, Integrity, and…

  • CVE-2021-3551HigFeb 16, 2022
    risk 0.51cvss 7.8epss 0.00

    A flaw was found in the PKI-server, where the spkispawn command, when run in debug mode, stores admin credentials in the installation log file. This flaw allows a local attacker to retrieve the file to obtain the admin password and gain admin privileges to the Dogtag CA manager.…

  • CVE-2021-40363HigFeb 9, 2022
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP1), SIMATIC WinCC V15 and earlier (All versions < V15 SP1 Update 7), SIMATIC WinCC V16 (All versions < V16 Update 5), SIMATIC…

  • CVE-2021-25502HigNov 5, 2021
    risk 0.51cvss 7.9epss 0.00

    A vulnerability of storing sensitive information insecurely in Property Settings prior to SMR Nov-2021 Release 1 allows attackers to read ESN value without priviledge.

  • CVE-2021-38422HigNov 3, 2021
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics DIALink versions 1.2.4.0 and prior stores sensitive information in cleartext, which may allow an attacker to have extensive access to the application directory and escalate privileges.