VYPR

CWE-312

Cleartext Storage of Sensitive Information

BaseDraft

Description

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-37

CVEs mapped to this weakness (885)

page 7 of 45
  • CVE-2021-27176HigFeb 10, 2021
    risk 0.50cvss 7.5epss 0.19

    An issue was discovered on FiberHome HG6245D devices through RP2613. wifictl_5g.cfg has cleartext passwords and 0644 permissions.

  • CVE-2021-27175HigFeb 10, 2021
    risk 0.50cvss 7.5epss 0.18

    An issue was discovered on FiberHome HG6245D devices through RP2613. wifictl_2g.cfg has cleartext passwords and 0644 permissions.

  • CVE-2021-27174HigFeb 10, 2021
    risk 0.50cvss 7.5epss 0.19

    An issue was discovered on FiberHome HG6245D devices through RP2613. wifi_custom.cfg has cleartext passwords and 0644 permissions.

  • CVE-2021-27140HigFeb 10, 2021
    risk 0.50cvss 7.5epss 0.19

    An issue was discovered on FiberHome HG6245D devices through RP2613. It is possible to find passwords and authentication cookies stored in cleartext in the web.log HTTP logs.

  • CVE-2020-24577HigJan 8, 2021
    risk 0.50cvss 7.5epss 0.19

    An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. The One Touch application discloses sensitive information, such as the hashed admin login password and the Internet provider connection username and cleartext password, in the…

  • CVE-2020-27986HigOct 28, 2020
    risk 0.50cvss 7.5epss 0.16

    SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI. NOTE: reportedly, the vendor's position for SMTP and SVN is "it is the administrator's responsibility to configure it.

  • CVE-2009-5068HigJan 15, 2020
    risk 0.50cvss 7.2epss 0.02

    There is a file disclosure vulnerability in SMF (Simple Machines Forum) affecting versions through v2.0.3. On some configurations a SMF deployment is shared by several "co-admins" that are not trusted beyond the SMF deployment. This vulnerability allows them to read arbitrary…

  • CVE-2019-10449HigOct 16, 2019
    risk 0.50cvss 8.8epss 0.01

    Jenkins Fortify on Demand Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.

  • CVE-2019-10440HigOct 16, 2019
    risk 0.50cvss 8.8epss 0.01

    Jenkins NeoLoad Plugin 2.2.5 and earlier stored credentials unencrypted in its global configuration file and in job config.xml files on the Jenkins master where they could be viewed by users with Extended Read permission, or access to the master file system.

  • CVE-2019-10348HigJul 11, 2019
    risk 0.50cvss 8.8epss 0.02

    Jenkins Gogs Plugin stored credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.

  • CVE-2019-3606HigMar 26, 2019
    risk 0.50cvss 7.7epss 0.00

    Data Leakage Attacks vulnerability in the web portal component when in an MDR pair in McAfee Network Security Management (NSM) 9.1 < 9.1.7.75 (Update 4) and 9.2 < 9.2.7.31 Update2 allows administrators to view configuration information in plain text format via the GUI or GUI…

  • CVE-2026-59657HigAug 21, 2026
    risk 0.49cvss 7.5epss 0.00

    Cleartext Storage of Sensitive Information vulnerability in Apache CloudStack with AsyncJob storage in the database. This issue affects Apache CloudStack: from 4.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.20.3.1 or…

  • CVE-2026-13380HigJul 20, 2026
    risk 0.49cvss 7.5epss 0.00

    VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP credentials in the HTTP responses of three unauthenticated endpoints. The credentials are present in these responses only when SFTP connections have been configured within the application. No authentication is…

  • CVE-2026-56270HigJun 24, 2026
    risk 0.49cvss 7.5epss 0.02

    Flowise before 3.1.0 (versions 3.0.13 and earlier) contains a missing authentication vulnerability in the /api/v1/loginmethod endpoint that allows unauthenticated users to retrieve an organization's complete SSO configuration, including OAuth client secrets in cleartext, by…

  • CVE-2026-6332HigMay 14, 2026
    risk 0.49cvss 7.5epss 0.00

    CWE-312: Cleartext Storage of Sensitive Information vulnerability exists that could cause the disclosure of a sensitive information which could result in revealing protected source code and loss of confidentiality, When an authorized attacker accesses the source code for…

  • CVE-2024-55027HigMar 3, 2026
    risk 0.49cvss 7.5epss 0.00

    Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to stroe credentials in plaintext in the component uac_temp.db.

  • CVE-2026-27520HigFeb 24, 2026
    risk 0.49cvss 7.5epss 0.00

    Binardat 10G08-0800GSM network switch firmware versions prior to V300SP10260209 store a user password in a client-side cookie as a Base64-encoded value accessible via the web interface. Because Base64 is reversible and provides no confidentiality, an attacker who can access…

  • CVE-2025-12774HigFeb 3, 2026
    risk 0.49cvss 7.5epss 0.00

    A vulnerability in the migration script for Brocade SANnav before 3.0 could allow the collection of database sql queries in the SANnav support save file. An attacker with access to Brocade SANnav supportsave file, could open the file and then obtain sensitive information such…

  • CVE-2026-22240HigJan 14, 2026
    risk 0.49cvss 7.5epss 0.03

    The vulnerability exists in BLUVOYIX due to an improper password storage implementation and subsequent exposure via unauthenticated APIs. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable users API to…

  • CVE-2019-25279HigJan 8, 2026
    risk 0.49cvss 7.5epss 0.00

    FaceSentry Access Control System 6.4.8 contains a cleartext password storage vulnerability that allows attackers to access unencrypted credentials in the device's SQLite database. Attackers can directly read sensitive login information stored in…