VYPR

CWE-312

Cleartext Storage of Sensitive Information

BaseDraft

Description

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-37

CVEs mapped to this weakness (885)

page 8 of 45
  • CVE-2020-36887HigDec 10, 2025
    risk 0.49cvss 7.5epss 0.00

    SpinetiX Fusion Digital Signage 3.4.8 contains an unauthenticated information disclosure vulnerability in the database backup directory. Attackers can access the /content/files/backups/ endpoint to download sensitive backup files containing user credentials and system…

  • CVE-2025-65320HigDec 3, 2025
    risk 0.49cvss 7.5epss 0.00

    Abacre Restaurant Point of Sale (POS) up to 15.0.0.1656 are vulnerable to Cleartext Storage of Sensitive Information in Memory. The application leaves valid device-bound license keys in process memory during an activation attempt.

  • CVE-2025-65278HigNov 26, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in file users.json in GroceryMart commit 21934e6 (2020-10-23) allowing unauthenticated attackers to gain sensitive information including plaintext usernames and passwords.

  • CVE-2025-25613HigNov 20, 2025
    risk 0.49cvss 7.5epss 0.00

    FS Inc S3150-8T2F 8-Port Gigabit Ethernet L2+ Switch, 8 x Gigabit RJ45, with 2 x 1Gb SFP, Fanless. All versions before 2.2.0D Build 135103 were discovered to transmit cookies for their web based administrative application containing usernames and passwords. These were…

  • CVE-2025-63208HigNov 19, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in bridgetech VB288 Objective QoE Content Extractor, firmware version 5.6.0-8, allowing attackers to gain sensitive information such as administrator passwords via the /probe/core/setup/passwd endpoint.

  • CVE-2025-59409HigOct 2, 2025
    risk 0.49cvss 7.5epss 0.00

    Flock Safety Falcon and Sparrow License Plate Readers OPM1.171019.026 ship with development Wi-Fi credentials (test_flck) stored in cleartext in production firmware.

  • CVE-2025-44649HigJul 21, 2025
    risk 0.49cvss 7.5epss 0.00

    In the configuration file of racoon in the TRENDnet TEW-WLC100P 2.03b03, the first item of exchage_mode is set to aggressive. Aggressive mode in IKE Phase 1 exposes identity information in plaintext, is vulnerable to offline dictionary attacks, and lacks flexibility in…

  • CVE-2025-27460HigJul 3, 2025
    risk 0.49cvss 7.6epss 0.00

    The hard drives of the device are not encrypted using a full volume encryption feature such as BitLocker. This allows an attacker with physical access to the device to use an alternative operating system to interact with the hard drives, completely circumventing the Windows…

  • CVE-2025-45001HigJun 9, 2025
    risk 0.49cvss 7.5epss 0.00

    react-native-keys 0.7.11 is vulnerable to sensitive information disclosure (remote) as encryption cipher and Base64 chunks are stored as plaintext in the compiled native binary. Attackers can extract these secrets using basic static analysis tools.

  • CVE-2025-44614HigMay 30, 2025
    risk 0.49cvss 7.5epss 0.00

    Tinxy WiFi Lock Controller v1 RF was discovered to store users' sensitive information, including credentials and mobile phone numbers, in plaintext.

  • CVE-2025-25758HigMar 20, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue in KukuFM Android v1.12.7 (11207) allows attackers to access sensitive cleartext data via the android:allowBackup="true" in the ANdroidManifest.xml

  • CVE-2025-27685HigMar 5, 2025
    risk 0.49cvss 7.5epss 0.00

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 allows Configuration File Contains CA & Private Key V-2022-001.

  • CVE-2025-26495HigFeb 11, 2025
    risk 0.49cvss 7.5epss 0.00

    Cleartext Storage of Sensitive Information vulnerability in Salesforce Tableau Server can record the Personal Access Token (PAT) into logging repositories.This issue affects Tableau Server: before 2022.1.3, before 2021.4.8, before 2021.3.13, before 2021.2.14, before 2021.1.16,…

  • CVE-2024-55196HigDec 19, 2024
    risk 0.49cvss 7.5epss 0.00

    Insufficiently Protected Credentials in the Mail Server Configuration in GoPhish v0.12.1 allows an attacker to access cleartext passwords for the configured IMAP and SMTP servers.

  • CVE-2024-51175HigDec 17, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue in H3C switch h3c-S1526 allows a remote attacker to obtain sensitive information via the S1526.cfg component.

  • CVE-2024-40582HigDec 9, 2024
    risk 0.49cvss 7.5epss 0.00

    Pentaminds CuroVMS v2.0.1 was discovered to contain exposed sensitive information.

  • CVE-2024-6400HigOct 4, 2024
    risk 0.49cvss 7.5epss 0.01

    Cleartext Storage of Sensitive Information, Exposure of Sensitive Information Through Data Queries vulnerability in Finrota Netahsilat allows Retrieve Embedded Sensitive Data, Authentication Bypass, IMAP/SMTP Command Injection, Collect Data from Common Resource Locations. This…

  • CVE-2024-8644HigSep 27, 2024
    risk 0.49cvss 7.5epss 0.00

    Cleartext Storage of Sensitive Information in a Cookie vulnerability in Oceanic Software ValeApp allows Protocol Manipulation, : JSON Hijacking (aka JavaScript Hijacking). This issue affects ValeApp: before v2.0.0.

  • CVE-2024-45862HigSep 19, 2024
    risk 0.49cvss 7.5epss 0.00

    Kastle Systems firmware prior to May 1, 2024, stored machine credentials in cleartext, which may allow an attacker to access sensitive information.

  • CVE-2024-6921HigSep 2, 2024
    risk 0.49cvss 7.5epss 0.00

    Cleartext Storage of Sensitive Information vulnerability in NAC Telecommunication Systems Inc. NACPremium allows Retrieve Embedded Sensitive Data. This issue affects NACPremium: through 01082024.