CWE-312
Cleartext Storage of Sensitive Information
Description
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-37
CVEs mapped to this weakness (848)
page 9 of 43| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-49341 | Hig | 0.49 | 7.5 | 0.00 | Mar 9, 2024 | An issue was discovered in Newland Nquire 1000 Interactive Kiosk version NQ1000-II_G_V1.00.011, allows remote attackers to obtain sensitive information via cleartext credential storage in backup.htm component. | ||
| CVE-2024-24375 | Hig | 0.49 | 7.5 | 0.00 | Mar 7, 2024 | SQL injection vulnerability in Jfinalcms v.5.0.0 allows a remote attacker to obtain sensitive information via /admin/admin name parameter. | ||
| CVE-2023-6874 | Hig | 0.49 | 7.5 | 0.00 | Feb 5, 2024 | Prior to v7.4.0, Ember ZNet is vulnerable to a denial of service attack through manipulation of the NWK sequence number | ||
| CVE-2023-27098 | Hig | 0.49 | 7.5 | 0.00 | Jan 9, 2024 | TP-Link Tapo APK up to v2.12.703 uses hardcoded credentials for access to the login panel. | ||
| CVE-2023-6250 | Hig | 0.49 | 7.5 | 0.00 | Dec 26, 2023 | The BestWebSoft's Like & Share WordPress plugin before 2.74 discloses the content of password protected posts to unauthenticated users via a meta tag | ||
| CVE-2023-46388 | Hig | 0.49 | 7.5 | 0.02 | Nov 30, 2023 | LOYTEC electronics GmbH LINX-212 and LINX-151 devices (all versions) are vulnerable to Insecure Permissions via dpal_config.zml file. This vulnerability allows remote attackers to disclose smtp client account credentials and bypass email authentication. | ||
| CVE-2023-46386 | Hig | 0.49 | 7.5 | 0.02 | Nov 30, 2023 | LOYTEC electronics GmbH LINX-212 and LINX-151 devices (all versions) are vulnerable to Insecure Permissions via registry.xml file. This vulnerability allows remote attackers to disclose smtp client account credentials and bypass email authentication. | ||
| CVE-2023-46384 | Hig | 0.49 | 7.5 | 0.02 | Nov 30, 2023 | LOYTEC electronics GmbH LINX Configurator (all versions) is vulnerable to Insecure Permissions. Cleartext storage of credentials allows remote attackers to disclose admin password and bypass an authentication to login Loytec device. | ||
| CVE-2023-46376 | Hig | 0.49 | 7.5 | 0.00 | Oct 27, 2023 | Zentao Biz version 8.7 and before is vulnerable to Information Disclosure. | ||
| CVE-2023-44037 | Hig | 0.49 | 7.5 | 0.00 | Oct 14, 2023 | An issue in ZPE Systems, Inc Nodegrid OS v.5.8.10 thru v.5.8.13 and v.5.10.3 thru v.5.10.5 allows a remote attacker to obtain sensitive information via the TACACS+ server component. | ||
| CVE-2023-44159 | Hig | 0.49 | 7.5 | 0.00 | Sep 27, 2023 | Sensitive information disclosure due to cleartext storage of sensitive information. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979. | ||
| CVE-2023-44153 | Hig | 0.49 | 7.5 | 0.00 | Sep 27, 2023 | Sensitive information disclosure due to cleartext storage of sensitive information in memory. The following products are affected: Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 35979. | ||
| CVE-2023-31041 | Hig | 0.49 | 7.5 | 0.00 | Aug 14, 2023 | An issue was discovered in SysPasswordDxe in Insyde InsydeH2O with kernel 5.0 through 5.5. System password information could optionally be stored in cleartext, which might lead to possible information disclosure. | ||
| CVE-2023-39379 | Hig | 0.49 | 7.5 | 0.00 | Aug 4, 2023 | Fujitsu Software Infrastructure Manager (ISM) stores sensitive information at the product's maintenance data (ismsnap) in cleartext form. As a result, the password for the proxy server that is configured in ISM may be retrieved. Affected products and versions are as follows:… | ||
| CVE-2023-30146 | Hig | 0.49 | 7.5 | 0.01 | Aug 4, 2023 | Assmann Digitus Plug&View IP Camera HT-IP211HDP, version 2.000.022 allows unauthenticated attackers to download a copy of the camera's settings and the administrator credentials. | ||
| CVE-2023-39144 | Hig | 0.49 | 7.5 | 0.01 | Aug 3, 2023 | Element55 KnowMore appliances version 21 and older was discovered to store passwords in plaintext. | ||
| CVE-2023-33742 | Hig | 0.49 | 7.5 | 0.01 | Jul 27, 2023 | TeleAdapt RoomCast TA-2400 1.0 through 3.1 suffers from Cleartext Storage of Sensitive Information: RSA private key in Update.exe. | ||
| CVE-2023-30367 | Hig | 0.49 | 7.5 | 0.00 | Jul 26, 2023 | Multi-Remote Next Generation Connection Manager (mRemoteNG) is free software that enables users to store and manage multi-protocol connection configurations to remotely connect to systems. mRemoteNG configuration files can be stored in an encrypted state on disk. mRemoteNG… | ||
| CVE-2023-31821 | Hig | 0.49 | 7.5 | 0.01 | Jul 13, 2023 | An issue found in ALBIS Co. ALBIS v.13.6.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp ALBIS function. | ||
| CVE-2023-27243 | Hig | 0.49 | 7.5 | 0.00 | Jun 21, 2023 | An access control issue in Makves DCAP v3.0.0.122 allows unauthenticated attackers to obtain cleartext credentials via a crafted web request to the product API. |
- risk 0.49cvss 7.5epss 0.00
An issue was discovered in Newland Nquire 1000 Interactive Kiosk version NQ1000-II_G_V1.00.011, allows remote attackers to obtain sensitive information via cleartext credential storage in backup.htm component.
- risk 0.49cvss 7.5epss 0.00
SQL injection vulnerability in Jfinalcms v.5.0.0 allows a remote attacker to obtain sensitive information via /admin/admin name parameter.
- risk 0.49cvss 7.5epss 0.00
Prior to v7.4.0, Ember ZNet is vulnerable to a denial of service attack through manipulation of the NWK sequence number
- risk 0.49cvss 7.5epss 0.00
TP-Link Tapo APK up to v2.12.703 uses hardcoded credentials for access to the login panel.
- risk 0.49cvss 7.5epss 0.00
The BestWebSoft's Like & Share WordPress plugin before 2.74 discloses the content of password protected posts to unauthenticated users via a meta tag
- risk 0.49cvss 7.5epss 0.02
LOYTEC electronics GmbH LINX-212 and LINX-151 devices (all versions) are vulnerable to Insecure Permissions via dpal_config.zml file. This vulnerability allows remote attackers to disclose smtp client account credentials and bypass email authentication.
- risk 0.49cvss 7.5epss 0.02
LOYTEC electronics GmbH LINX-212 and LINX-151 devices (all versions) are vulnerable to Insecure Permissions via registry.xml file. This vulnerability allows remote attackers to disclose smtp client account credentials and bypass email authentication.
- risk 0.49cvss 7.5epss 0.02
LOYTEC electronics GmbH LINX Configurator (all versions) is vulnerable to Insecure Permissions. Cleartext storage of credentials allows remote attackers to disclose admin password and bypass an authentication to login Loytec device.
- risk 0.49cvss 7.5epss 0.00
Zentao Biz version 8.7 and before is vulnerable to Information Disclosure.
- risk 0.49cvss 7.5epss 0.00
An issue in ZPE Systems, Inc Nodegrid OS v.5.8.10 thru v.5.8.13 and v.5.10.3 thru v.5.10.5 allows a remote attacker to obtain sensitive information via the TACACS+ server component.
- risk 0.49cvss 7.5epss 0.00
Sensitive information disclosure due to cleartext storage of sensitive information. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979.
- risk 0.49cvss 7.5epss 0.00
Sensitive information disclosure due to cleartext storage of sensitive information in memory. The following products are affected: Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 35979.
- risk 0.49cvss 7.5epss 0.00
An issue was discovered in SysPasswordDxe in Insyde InsydeH2O with kernel 5.0 through 5.5. System password information could optionally be stored in cleartext, which might lead to possible information disclosure.
- risk 0.49cvss 7.5epss 0.00
Fujitsu Software Infrastructure Manager (ISM) stores sensitive information at the product's maintenance data (ismsnap) in cleartext form. As a result, the password for the proxy server that is configured in ISM may be retrieved. Affected products and versions are as follows:…
- risk 0.49cvss 7.5epss 0.01
Assmann Digitus Plug&View IP Camera HT-IP211HDP, version 2.000.022 allows unauthenticated attackers to download a copy of the camera's settings and the administrator credentials.
- risk 0.49cvss 7.5epss 0.01
Element55 KnowMore appliances version 21 and older was discovered to store passwords in plaintext.
- risk 0.49cvss 7.5epss 0.01
TeleAdapt RoomCast TA-2400 1.0 through 3.1 suffers from Cleartext Storage of Sensitive Information: RSA private key in Update.exe.
- risk 0.49cvss 7.5epss 0.00
Multi-Remote Next Generation Connection Manager (mRemoteNG) is free software that enables users to store and manage multi-protocol connection configurations to remotely connect to systems. mRemoteNG configuration files can be stored in an encrypted state on disk. mRemoteNG…
- risk 0.49cvss 7.5epss 0.01
An issue found in ALBIS Co. ALBIS v.13.6.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp ALBIS function.
- risk 0.49cvss 7.5epss 0.00
An access control issue in Makves DCAP v3.0.0.122 allows unauthenticated attackers to obtain cleartext credentials via a crafted web request to the product API.