VYPR

CWE-312

Cleartext Storage of Sensitive Information

BaseDraft

Description

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-37

CVEs mapped to this weakness (848)

page 9 of 43
  • CVE-2023-49341HigMar 9, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in Newland Nquire 1000 Interactive Kiosk version NQ1000-II_G_V1.00.011, allows remote attackers to obtain sensitive information via cleartext credential storage in backup.htm component.

  • CVE-2024-24375HigMar 7, 2024
    risk 0.49cvss 7.5epss 0.00

    SQL injection vulnerability in Jfinalcms v.5.0.0 allows a remote attacker to obtain sensitive information via /admin/admin name parameter.

  • CVE-2023-6874HigFeb 5, 2024
    risk 0.49cvss 7.5epss 0.00

    Prior to v7.4.0, Ember ZNet is vulnerable to a denial of service attack through manipulation of the NWK sequence number

  • CVE-2023-27098HigJan 9, 2024
    risk 0.49cvss 7.5epss 0.00

    TP-Link Tapo APK up to v2.12.703 uses hardcoded credentials for access to the login panel.

  • CVE-2023-6250HigDec 26, 2023
    risk 0.49cvss 7.5epss 0.00

    The BestWebSoft's Like & Share WordPress plugin before 2.74 discloses the content of password protected posts to unauthenticated users via a meta tag

  • CVE-2023-46388HigNov 30, 2023
    risk 0.49cvss 7.5epss 0.02

    LOYTEC electronics GmbH LINX-212 and LINX-151 devices (all versions) are vulnerable to Insecure Permissions via dpal_config.zml file. This vulnerability allows remote attackers to disclose smtp client account credentials and bypass email authentication.

  • CVE-2023-46386HigNov 30, 2023
    risk 0.49cvss 7.5epss 0.02

    LOYTEC electronics GmbH LINX-212 and LINX-151 devices (all versions) are vulnerable to Insecure Permissions via registry.xml file. This vulnerability allows remote attackers to disclose smtp client account credentials and bypass email authentication.

  • CVE-2023-46384HigNov 30, 2023
    risk 0.49cvss 7.5epss 0.02

    LOYTEC electronics GmbH LINX Configurator (all versions) is vulnerable to Insecure Permissions. Cleartext storage of credentials allows remote attackers to disclose admin password and bypass an authentication to login Loytec device.

  • CVE-2023-46376HigOct 27, 2023
    risk 0.49cvss 7.5epss 0.00

    Zentao Biz version 8.7 and before is vulnerable to Information Disclosure.

  • CVE-2023-44037HigOct 14, 2023
    risk 0.49cvss 7.5epss 0.00

    An issue in ZPE Systems, Inc Nodegrid OS v.5.8.10 thru v.5.8.13 and v.5.10.3 thru v.5.10.5 allows a remote attacker to obtain sensitive information via the TACACS+ server component.

  • CVE-2023-44159HigSep 27, 2023
    risk 0.49cvss 7.5epss 0.00

    Sensitive information disclosure due to cleartext storage of sensitive information. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979.

  • CVE-2023-44153HigSep 27, 2023
    risk 0.49cvss 7.5epss 0.00

    Sensitive information disclosure due to cleartext storage of sensitive information in memory. The following products are affected: Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 35979.

  • CVE-2023-31041HigAug 14, 2023
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in SysPasswordDxe in Insyde InsydeH2O with kernel 5.0 through 5.5. System password information could optionally be stored in cleartext, which might lead to possible information disclosure.

  • CVE-2023-39379HigAug 4, 2023
    risk 0.49cvss 7.5epss 0.00

    Fujitsu Software Infrastructure Manager (ISM) stores sensitive information at the product's maintenance data (ismsnap) in cleartext form. As a result, the password for the proxy server that is configured in ISM may be retrieved. Affected products and versions are as follows:…

  • CVE-2023-30146HigAug 4, 2023
    risk 0.49cvss 7.5epss 0.01

    Assmann Digitus Plug&View IP Camera HT-IP211HDP, version 2.000.022 allows unauthenticated attackers to download a copy of the camera's settings and the administrator credentials.

  • CVE-2023-39144HigAug 3, 2023
    risk 0.49cvss 7.5epss 0.01

    Element55 KnowMore appliances version 21 and older was discovered to store passwords in plaintext.

  • CVE-2023-33742HigJul 27, 2023
    risk 0.49cvss 7.5epss 0.01

    TeleAdapt RoomCast TA-2400 1.0 through 3.1 suffers from Cleartext Storage of Sensitive Information: RSA private key in Update.exe.

  • CVE-2023-30367HigJul 26, 2023
    risk 0.49cvss 7.5epss 0.00

    Multi-Remote Next Generation Connection Manager (mRemoteNG) is free software that enables users to store and manage multi-protocol connection configurations to remotely connect to systems. mRemoteNG configuration files can be stored in an encrypted state on disk. mRemoteNG…

  • CVE-2023-31821HigJul 13, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue found in ALBIS Co. ALBIS v.13.6.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp ALBIS function.

  • CVE-2023-27243HigJun 21, 2023
    risk 0.49cvss 7.5epss 0.00

    An access control issue in Makves DCAP v3.0.0.122 allows unauthenticated attackers to obtain cleartext credentials via a crafted web request to the product API.