CWE-312
Cleartext Storage of Sensitive Information
Description
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-37
CVEs mapped to this weakness (848)
page 8 of 43| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-63208 | Hig | 0.49 | 7.5 | 0.00 | Nov 19, 2025 | An issue was discovered in bridgetech VB288 Objective QoE Content Extractor, firmware version 5.6.0-8, allowing attackers to gain sensitive information such as administrator passwords via the /probe/core/setup/passwd endpoint. | ||
| CVE-2025-59409 | Hig | 0.49 | 7.5 | 0.00 | Oct 2, 2025 | Flock Safety Falcon and Sparrow License Plate Readers OPM1.171019.026 ship with development Wi-Fi credentials (test_flck) stored in cleartext in production firmware. | ||
| CVE-2025-44649 | Hig | 0.49 | 7.5 | 0.00 | Jul 21, 2025 | In the configuration file of racoon in the TRENDnet TEW-WLC100P 2.03b03, the first item of exchage_mode is set to aggressive. Aggressive mode in IKE Phase 1 exposes identity information in plaintext, is vulnerable to offline dictionary attacks, and lacks flexibility in… | ||
| CVE-2025-27460 | Hig | 0.49 | 7.6 | 0.00 | Jul 3, 2025 | The hard drives of the device are not encrypted using a full volume encryption feature such as BitLocker. This allows an attacker with physical access to the device to use an alternative operating system to interact with the hard drives, completely circumventing the Windows… | ||
| CVE-2025-45001 | Hig | 0.49 | 7.5 | 0.00 | Jun 9, 2025 | react-native-keys 0.7.11 is vulnerable to sensitive information disclosure (remote) as encryption cipher and Base64 chunks are stored as plaintext in the compiled native binary. Attackers can extract these secrets using basic static analysis tools. | ||
| CVE-2025-44614 | Hig | 0.49 | 7.5 | 0.00 | May 30, 2025 | Tinxy WiFi Lock Controller v1 RF was discovered to store users' sensitive information, including credentials and mobile phone numbers, in plaintext. | ||
| CVE-2025-25758 | Hig | 0.49 | 7.5 | 0.00 | Mar 20, 2025 | An issue in KukuFM Android v1.12.7 (11207) allows attackers to access sensitive cleartext data via the android:allowBackup="true" in the ANdroidManifest.xml | ||
| CVE-2025-27685 | Hig | 0.49 | 7.5 | 0.00 | Mar 5, 2025 | Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 allows Configuration File Contains CA & Private Key V-2022-001. | ||
| CVE-2025-26495 | Hig | 0.49 | 7.5 | 0.00 | Feb 11, 2025 | Cleartext Storage of Sensitive Information vulnerability in Salesforce Tableau Server can record the Personal Access Token (PAT) into logging repositories.This issue affects Tableau Server: before 2022.1.3, before 2021.4.8, before 2021.3.13, before 2021.2.14, before 2021.1.16,… | ||
| CVE-2024-55196 | Hig | 0.49 | 7.5 | 0.00 | Dec 19, 2024 | Insufficiently Protected Credentials in the Mail Server Configuration in GoPhish v0.12.1 allows an attacker to access cleartext passwords for the configured IMAP and SMTP servers. | ||
| CVE-2024-51175 | — | Hig | 0.49 | 7.5 | 0.00 | Dec 17, 2024 | An issue in H3C switch h3c-S1526 allows a remote attacker to obtain sensitive information via the S1526.cfg component. | |
| CVE-2024-40582 | Hig | 0.49 | 7.5 | 0.00 | Dec 9, 2024 | Pentaminds CuroVMS v2.0.1 was discovered to contain exposed sensitive information. | ||
| CVE-2024-6400 | Hig | 0.49 | 7.5 | 0.01 | Oct 4, 2024 | Cleartext Storage of Sensitive Information, Exposure of Sensitive Information Through Data Queries vulnerability in Finrota Netahsilat allows Retrieve Embedded Sensitive Data, Authentication Bypass, IMAP/SMTP Command Injection, Collect Data from Common Resource Locations. This… | ||
| CVE-2024-8644 | Hig | 0.49 | 7.5 | 0.00 | Sep 27, 2024 | Cleartext Storage of Sensitive Information in a Cookie vulnerability in Oceanic Software ValeApp allows Protocol Manipulation, : JSON Hijacking (aka JavaScript Hijacking). This issue affects ValeApp: before v2.0.0. | ||
| CVE-2024-45862 | Hig | 0.49 | 7.5 | 0.00 | Sep 19, 2024 | Kastle Systems firmware prior to May 1, 2024, stored machine credentials in cleartext, which may allow an attacker to access sensitive information. | ||
| CVE-2024-6921 | Hig | 0.49 | 7.5 | 0.00 | Sep 2, 2024 | Cleartext Storage of Sensitive Information vulnerability in NAC Telecommunication Systems Inc. NACPremium allows Retrieve Embedded Sensitive Data. This issue affects NACPremium: through 01082024. | ||
| CVE-2024-33892 | Hig | 0.49 | 7.5 | 0.00 | Aug 2, 2024 | Insecure Permissions vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are susceptible to leaking information through cookies. This is fixed in version 21.2s10 and 22.1s3 | ||
| CVE-2019-16638 | Hig | 0.49 | 7.5 | 0.00 | Jul 16, 2024 | An issue was found on the Ruijie EG-2000 series gateway. An attacker can easily dump cleartext stored passwords in /data/config.text with simple XORs. This affects EG-2000SE EG_RGOS 11.1(1)B1. | ||
| CVE-2024-3742 | Hig | 0.49 | 7.5 | 0.01 | Apr 18, 2024 | Electrolink transmitters store credentials in clear-text. Use of these credentials could allow an attacker to access the system. | ||
| CVE-2024-28387 | Hig | 0.49 | 7.5 | 0.00 | Mar 25, 2024 | An issue in axonaut v.3.1.23 and before allows a remote attacker to obtain sensitive information via the log.txt component. |
- risk 0.49cvss 7.5epss 0.00
An issue was discovered in bridgetech VB288 Objective QoE Content Extractor, firmware version 5.6.0-8, allowing attackers to gain sensitive information such as administrator passwords via the /probe/core/setup/passwd endpoint.
- risk 0.49cvss 7.5epss 0.00
Flock Safety Falcon and Sparrow License Plate Readers OPM1.171019.026 ship with development Wi-Fi credentials (test_flck) stored in cleartext in production firmware.
- risk 0.49cvss 7.5epss 0.00
In the configuration file of racoon in the TRENDnet TEW-WLC100P 2.03b03, the first item of exchage_mode is set to aggressive. Aggressive mode in IKE Phase 1 exposes identity information in plaintext, is vulnerable to offline dictionary attacks, and lacks flexibility in…
- risk 0.49cvss 7.6epss 0.00
The hard drives of the device are not encrypted using a full volume encryption feature such as BitLocker. This allows an attacker with physical access to the device to use an alternative operating system to interact with the hard drives, completely circumventing the Windows…
- risk 0.49cvss 7.5epss 0.00
react-native-keys 0.7.11 is vulnerable to sensitive information disclosure (remote) as encryption cipher and Base64 chunks are stored as plaintext in the compiled native binary. Attackers can extract these secrets using basic static analysis tools.
- risk 0.49cvss 7.5epss 0.00
Tinxy WiFi Lock Controller v1 RF was discovered to store users' sensitive information, including credentials and mobile phone numbers, in plaintext.
- risk 0.49cvss 7.5epss 0.00
An issue in KukuFM Android v1.12.7 (11207) allows attackers to access sensitive cleartext data via the android:allowBackup="true" in the ANdroidManifest.xml
- risk 0.49cvss 7.5epss 0.00
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 allows Configuration File Contains CA & Private Key V-2022-001.
- risk 0.49cvss 7.5epss 0.00
Cleartext Storage of Sensitive Information vulnerability in Salesforce Tableau Server can record the Personal Access Token (PAT) into logging repositories.This issue affects Tableau Server: before 2022.1.3, before 2021.4.8, before 2021.3.13, before 2021.2.14, before 2021.1.16,…
- risk 0.49cvss 7.5epss 0.00
Insufficiently Protected Credentials in the Mail Server Configuration in GoPhish v0.12.1 allows an attacker to access cleartext passwords for the configured IMAP and SMTP servers.
- risk 0.49cvss 7.5epss 0.00
An issue in H3C switch h3c-S1526 allows a remote attacker to obtain sensitive information via the S1526.cfg component.
- risk 0.49cvss 7.5epss 0.00
Pentaminds CuroVMS v2.0.1 was discovered to contain exposed sensitive information.
- risk 0.49cvss 7.5epss 0.01
Cleartext Storage of Sensitive Information, Exposure of Sensitive Information Through Data Queries vulnerability in Finrota Netahsilat allows Retrieve Embedded Sensitive Data, Authentication Bypass, IMAP/SMTP Command Injection, Collect Data from Common Resource Locations. This…
- risk 0.49cvss 7.5epss 0.00
Cleartext Storage of Sensitive Information in a Cookie vulnerability in Oceanic Software ValeApp allows Protocol Manipulation, : JSON Hijacking (aka JavaScript Hijacking). This issue affects ValeApp: before v2.0.0.
- risk 0.49cvss 7.5epss 0.00
Kastle Systems firmware prior to May 1, 2024, stored machine credentials in cleartext, which may allow an attacker to access sensitive information.
- risk 0.49cvss 7.5epss 0.00
Cleartext Storage of Sensitive Information vulnerability in NAC Telecommunication Systems Inc. NACPremium allows Retrieve Embedded Sensitive Data. This issue affects NACPremium: through 01082024.
- risk 0.49cvss 7.5epss 0.00
Insecure Permissions vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are susceptible to leaking information through cookies. This is fixed in version 21.2s10 and 22.1s3
- risk 0.49cvss 7.5epss 0.00
An issue was found on the Ruijie EG-2000 series gateway. An attacker can easily dump cleartext stored passwords in /data/config.text with simple XORs. This affects EG-2000SE EG_RGOS 11.1(1)B1.
- risk 0.49cvss 7.5epss 0.01
Electrolink transmitters store credentials in clear-text. Use of these credentials could allow an attacker to access the system.
- risk 0.49cvss 7.5epss 0.00
An issue in axonaut v.3.1.23 and before allows a remote attacker to obtain sensitive information via the log.txt component.