VYPR

CWE-313

Cleartext Storage in a File or on Disk

VariantDraft

Description

The product stores sensitive information in cleartext in a file, or on disk.

The sensitive information could be read by attackers with access to the file, or with physical or administrator access to the raw disk. Even if the information is encoded in a way that is not human-readable, certain techniques could determine which encoding is being used, then decode the information.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (30)

page 1 of 2
  • CVE-2025-5098CriMay 23, 2025
    risk 0.59cvss 9.1epss 0.00

    PrinterShare Android application allows the capture of Gmail authentication tokens that can be reused to access a user's Gmail account without proper authorization.

  • CVE-2016-6538HigJul 6, 2018
    risk 0.57cvss 8.8epss 0.01

    The TrackR Bravo mobile app stores the account password used to authenticate to the cloud API in cleartext in the cache.db file. Updated apps, version 5.1.6 for iOS and 2.2.5 for Android, have been released by the vendor to address the vulnerabilities in CVE-2016-6538,…

  • CVE-2016-6547HigJul 13, 2018
    risk 0.51cvss 7.8epss 0.00

    The Zizai Tech Nut mobile app stores the account password used to authenticate to the cloud API in cleartext in the cache.db file.

  • CVE-2016-6546HigJul 13, 2018
    risk 0.51cvss 7.8epss 0.00

    The iTrack Easy mobile application stores the account password used to authenticate to the cloud API in base64-encoding in the cache.db file. The base64 encoding format is considered equivalent to cleartext.

  • CVE-2026-24349HigJun 9, 2026
    risk 0.46cvss 7.1epss 0.00

    A vulnerability has been identified in SIMATIC WinCC Unified PC Runtime V16 (All versions), SIMATIC WinCC Unified PC Runtime V17 (All versions), SIMATIC WinCC Unified PC Runtime V18 (All versions), SIMATIC WinCC Unified PC Runtime V19 (All versions), SIMATIC WinCC Unified PC…

  • CVE-2026-8804MedJul 3, 2026
    risk 0.44cvss epss 0.00

    Puppet resource_api (shipped in Puppet Core 8.x and Puppet Enterprise 2023.8.x and 2025.x) does not preserve the sensitive flag on parameters defined via the resource-api, causing values such as passwords to be stored in cleartext in the agent's local transaction state cache.…

  • CVE-2025-4397MedMay 7, 2026
    risk 0.44cvss 6.8epss 0.00

    Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker can use these credentials to modify encrypted drive data.

  • CVE-2025-64305MedJan 7, 2026
    risk 0.42cvss 6.5epss 0.00

    MicroServer copies parts of the system firmware to an unencrypted external SD card on boot, which contains user and vendor secrets. An attacker can utilize these plaintext secrets to modify the vendor firmware, or gain admin access to the web portal.

  • CVE-2024-20448MedOct 2, 2024
    risk 0.41cvss 6.3epss 0.00

    A vulnerability in the Cisco Nexus Dashboard Fabric Controller (NDFC) software, formerly Cisco Data Center Network Manager (DCNM), could allow an attacker with access to a backup file to view sensitive information. This vulnerability is due to the improper storage of…

  • CVE-2025-36154MedDec 24, 2025
    risk 0.40cvss 6.2epss 0.00

    IBM Concert 1.0.0 through 2.1.0 stores sensitive information in cleartext during recursive docker builds which could be obtained by a local user.

  • CVE-2024-6785MedSep 21, 2024
    risk 0.36cvss 5.5epss 0.00

    The configuration file stores credentials in cleartext. An attacker with local access rights can read or modify the configuration file, potentially resulting in the service being abused due to sensitive information exposure.

  • CVE-2024-30406MedApr 12, 2024
    risk 0.36cvss 5.5epss 0.00

    A Cleartext Storage in a File on Disk vulnerability in Juniper Networks Junos OS Evolved ACX Series devices using the Paragon Active Assurance Test Agent software installed on network devices allows a local, authenticated attacker with high privileges to read all other users…

  • CVE-2023-4066MedSep 27, 2023
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in Red Hat's AMQ Broker, which stores certain passwords in a secret security-properties-prop-module, defined in ActivemqArtemisSecurity CR; however, they are shown in plaintext in the StatefulSet details yaml of AMQ Broker.

  • CVE-2019-19291MedMar 10, 2020
    risk 0.35cvss 5.3epss 0.01

    A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0), SiNVR/SiVMS Video Server (All versions < V5.0.0). The FTP services of the SiVMS/SiNVR Video Server and the Control Center Server (CCS) maintain log files that store login credentials in…

  • CVE-2026-5531MedApr 5, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability has been found in SourceCodester Student Result Management System 1.0. Impacted is an unknown function of the file /login_credentials.txt of the component HTTP GET Request Handler. The manipulation leads to cleartext storage in a file or on disk. The attack may…

  • CVE-2023-35699MedJul 10, 2023
    risk 0.34cvss 5.3epss 0.00

    Cleartext Storage on Disk in the SICK ICR890-4 could allow an unauthenticated attacker with local access to the device to disclose sensitive information by accessing a SD card.

  • CVE-2018-10622MedAug 10, 2018
    risk 0.34cvss 5.2epss 0.00

    Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker can use these credentials for network authentication.

  • CVE-2024-38280MedJun 13, 2024
    risk 0.30cvss 4.6epss 0.00

    An unauthorized user is able to gain access to sensitive data, including credentials, by physically retrieving the hard disk of the product as the data is stored in clear text.

  • CVE-2024-5916MedAug 14, 2024
    risk 0.29cvss 4.4epss 0.00

    An information exposure vulnerability in Palo Alto Networks PAN-OS software enables a local system administrator to unintentionally disclose secrets, passwords, and tokens of external systems. A read-only administrator who has access to the config log, can read secrets,…

  • CVE-2026-6796MedApr 21, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was determined in Sanluan PublicCMS up to 6.202506.d. Affected is the function log_login of the file core/src/main/java/com/publiccms/controller/admin/LoginAdminController.java of the component Failed Login Handler. This manipulation of the argument errorPassword…