VYPR

CWE-312

Cleartext Storage of Sensitive Information

BaseDraft

Description

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-37

CVEs mapped to this weakness (848)

page 6 of 43
  • CVE-2021-31581HigJul 22, 2021
    risk 0.51cvss 7.9epss 0.01

    The restricted shell provided by Akkadian Provisioning Manager Engine (PME) can be escaped by abusing the 'Edit MySQL Configuration' command. This command launches a standard vi editor interface which can then be escaped. This issue was resolved in Akkadian OVA appliance version…

  • CVE-2020-35455HigMar 17, 2021
    risk 0.51cvss 7.8epss 0.00

    The Taidii Diibear Android application 2.4.0 and all its derivatives allow attackers to obtain user credentials from Shared Preferences and the SQLite database because of insecure data storage.

  • CVE-2021-0337HigFeb 10, 2021
    risk 0.51cvss 7.8epss 0.00

    In moveInMediaStore of FileSystemProvider.java, there is a possible file exposure due to stale metadata. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1…

  • CVE-2020-7516HigJul 23, 2020
    risk 0.51cvss 7.8epss 0.00

    A CWE-316: Cleartext Storage of Sensitive Information in Memory vulnerability exists in Easergy Builder V1.4.7.2 and prior which could allow an attacker access to login credentials.

  • CVE-2020-5899HigJul 1, 2020
    risk 0.51cvss 7.8epss 0.00

    In NGINX Controller 3.0.0-3.4.0, recovery code required to change a user's password is transmitted and stored in the database in plain text, which allows an attacker who can intercept the database connection or have read access to the database, to request a password reset using…

  • CVE-2019-4676HigJul 1, 2020
    risk 0.51cvss 7.8epss 0.01

    IBM Security Identity Manager Virtual Appliance 7.0.2 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 171512.

  • CVE-2019-10453HigOct 16, 2019
    risk 0.51cvss 7.8epss 0.00

    Jenkins Delphix Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.

  • CVE-2019-12171HigJul 8, 2019
    risk 0.51cvss 7.8epss 0.01

    Dropbox.exe (and QtWebEngineProcess.exe in the Web Helper) in the Dropbox desktop application 71.4.108.0 store cleartext credentials in memory upon successful login or new account creation. These are not securely freed in the running process.

  • CVE-2019-3937HigApr 30, 2019
    risk 0.51cvss 7.8epss 0.00

    Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 stores usernames, passwords, slideshow passcode, and other configuration options in cleartext in the file /tmp/scfgdndf. A local attacker can use this vulnerability to recover sensitive data.

  • CVE-2018-12572HigMar 21, 2019
    risk 0.51cvss 7.8epss 0.00

    Avast Free Antivirus prior to 19.1.2360 stores user credentials in memory upon login, which allows local users to obtain sensitive information by dumping AvastUI.exe application memory and parsing the data.

  • CVE-2018-19009HigJan 25, 2019
    risk 0.51cvss 7.8epss 0.00

    Pilz PNOZmulti Configurator prior to version 10.9 allows an authenticated attacker with local access to the system containing the PNOZmulti Configurator software to view sensitive credential data in clear-text. This sensitive data is applicable to only the PMI m107 diag HMI…

  • CVE-2016-8366HigApr 5, 2018
    risk 0.51cvss 7.3epss 0.06

    Webvisit in Phoenix Contact ILC PLCs offers a password macro to protect HMI pages on the PLC against casual or coincidental opening of HMI pages by the user. The password macro can be configured in a way that the password is stored and transferred in clear text.

  • CVE-2017-1309HigJul 19, 2017
    risk 0.51cvss 7.8epss 0.00

    IBM InfoSphere Master Data Management Server 11.0 - 11.6 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 125463.

  • CVE-2008-6828HigJun 8, 2009
    risk 0.51cvss 7.8epss 0.00

    Symantec Altiris Deployment Solution 6.x before 6.9.355 SP1 stores the Application Identity Account password in memory in cleartext, which allows local users to gain privileges and modify clients of the Deployment Solution Server.

  • CVE-2024-25661HigOct 1, 2024
    risk 0.50cvss 7.7epss 0.00

    In Infinera TNMS (Transcend Network Management System) 19.10.3, cleartext storage of sensitive information in memory of the desktop application TNMS Client allows guest OS administrators to obtain various users' passwords by reading memory dumps of the desktop application.

  • CVE-2022-22069HigSep 2, 2022
    risk 0.50cvss 7.7epss 0.00

    Devices with keyprotect off may store unencrypted keybox in RPMB and cause cryptographic issue in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

  • CVE-2021-27178HigFeb 10, 2021
    risk 0.50cvss 7.5epss 0.18

    An issue was discovered on FiberHome HG6245D devices through RP2613. Some passwords are stored in cleartext in nvram.

  • CVE-2021-27176HigFeb 10, 2021
    risk 0.50cvss 7.5epss 0.19

    An issue was discovered on FiberHome HG6245D devices through RP2613. wifictl_5g.cfg has cleartext passwords and 0644 permissions.

  • CVE-2021-27175HigFeb 10, 2021
    risk 0.50cvss 7.5epss 0.18

    An issue was discovered on FiberHome HG6245D devices through RP2613. wifictl_2g.cfg has cleartext passwords and 0644 permissions.

  • CVE-2021-27174HigFeb 10, 2021
    risk 0.50cvss 7.5epss 0.19

    An issue was discovered on FiberHome HG6245D devices through RP2613. wifi_custom.cfg has cleartext passwords and 0644 permissions.