VYPR

CWE-316

Cleartext Storage of Sensitive Information in Memory

VariantDraft

Description

The product stores sensitive information in cleartext in memory.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (37)

page 1 of 2
  • CVE-2025-52579CriJul 11, 2025
    risk 0.61cvss 9.4epss 0.00

    Emerson ValveLink Products store sensitive information in cleartext in memory. The sensitive memory might be saved to disk, stored in a core dump, or remain uncleared if the product crashes, or if the programmer does not properly clear the memory before freeing it.

  • CVE-2024-36792HigJun 7, 2024
    risk 0.53cvss 8.2epss 0.00

    An issue in the implementation of the WPS in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to gain access to the router's pin.

  • CVE-2022-0835HigApr 11, 2022
    risk 0.53cvss 8.1epss 0.00

    AVEVA System Platform 2020 stores sensitive information in cleartext, which may allow access to an attacker or a low-privileged user.

  • CVE-2025-50109HigJul 11, 2025
    risk 0.50cvss 7.7epss 0.00

    Emerson ValveLink Products store sensitive information in cleartext within a resource that might be accessible to another control sphere.

  • CVE-2023-44153HigSep 27, 2023
    risk 0.49cvss 7.5epss 0.00

    Sensitive information disclosure due to cleartext storage of sensitive information in memory. The following products are affected: Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 35979.

  • CVE-2025-9970HigOct 8, 2025
    risk 0.48cvss 7.4epss 0.00

    Cleartext Storage of Sensitive Information in Memory vulnerability in ABB MConfig.This issue affects MConfig: through 1.4.9.21.

  • CVE-2023-40724HigSep 12, 2023
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been identified in QMS Automotive (All versions < V12.39). User credentials are found in memory as plaintext. An attacker could perform a memory dump, and get access to credentials, and use it for impersonation.

  • CVE-2024-25649MedMar 14, 2024
    risk 0.44cvss 6.7epss 0.00

    In Delinea PAM Secret Server 11.4, it is possible for an attacker (with Administrator access to the Secret Server machine) to read the following data from a memory dump: the decrypted master key, database credentials (when SQL Server Authentication is enabled), the encryption…

  • CVE-2021-32942MedJun 9, 2021
    risk 0.43cvss 6.6epss 0.00

    The vulnerability could expose cleartext credentials from AVEVA InTouch Runtime 2020 R2 and all prior versions (WindowViewer) if an authorized, privileged user creates a diagnostic memory dump of the process and saves it to a non-protected location.

  • CVE-2025-60794MedNov 20, 2025
    risk 0.42cvss 6.5epss 0.00

    Session tokens and passwords in couch-auth 0.21.2 are stored in JavaScript objects and remain in memory without explicit clearing in src/user.ts lines 700-707. This creates a window of opportunity for sensitive data extraction through memory dumps, debugging tools, or other…

  • CVE-2024-33901MedMay 20, 2024
    risk 0.42cvss 6.5epss 0.01

    Issue in KeePassXC 2.7.7 allows an attacker (who has the privileges of the victim) to recover some passwords stored in the .kdbx database via a memory dump. NOTE: the vendor disputes this because memory-management constraints make this unavoidable in the current design and other…

  • CVE-2024-33900MedMay 20, 2024
    risk 0.42cvss 6.5epss 0.00

    KeePassXC 2.7.7 allows an attacker (who has the privileges of the victim) to recover cleartext credentials via a memory dump. NOTE: the vendor disputes this because memory-management constraints make this unavoidable in the current design and other realistic designs.

  • CVE-2025-60791MedOct 27, 2025
    risk 0.40cvss 6.2epss 0.00

    Easywork Enterprise 2.1.3.354 is vulnerable to Cleartext Storage of Sensitive Information in Memory. The application leaves valid device-bound license keys in process memory after a failed activation attempt. The keys can be obtained by attaching a debugger or analyzing the…

  • CVE-2024-24915MedJun 29, 2025
    risk 0.40cvss 6.1epss 0.00

    Credentials are not cleared from memory after being used. A user with Administrator permissions can execute memory dump for SmartConsole process and fetch them.

  • CVE-2026-0857MedMay 20, 2026
    risk 0.39cvss 6.0epss 0.00

    Cleartext Storage of Sensitive Information in Memory vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component. This issue affects Meona Client Launcher Component: through 19.06.2020 15:11:49; Meona Server Component: through 2025.04 5+323020.

  • CVE-2021-23211MedJun 11, 2021
    risk 0.39cvss 6.0epss 0.00

    Cleartext Storage of Sensitive Information in Memory vulnerability in Gallagher Command Centre Server allows Cloud end-to-end encryption key to be discoverable in server memory dumps. This issue affects: Gallagher Command Centre 8.40 versions prior to 8.40.1888 (MR3).

  • CVE-2021-23182MedJun 11, 2021
    risk 0.39cvss 6.0epss 0.00

    Cleartext Storage of Sensitive Information in Memory vulnerability in Gallagher Command Centre Server allows OSDP reader master keys to be discoverable in server memory dumps. This issue affects: Gallagher Command Centre 8.40 versions prior to 8.40.1888 (MR3); All versions of…

  • CVE-2026-53604higJul 14, 2026
    risk 0.38cvss epss

    ## Impact The web handler `renderMobileBundle` (`internal/web/handlers.go:1325`) passes the real `*pki.CAResolver` directly into `mobilebundle.Build`. Inside `Build` (`internal/mobilebundle/builder.go:54`), `resolver.LoadByID` decrypts the CA's ed25519 private key into a…

  • CVE-2026-24319MedFeb 10, 2026
    risk 0.38cvss 5.8epss 0.00

    In SAP Business One, sensitive information is written to the application�s memory dump files without obfuscation. Gaining access to this information could potentially lead to unauthorized operations within the B1 environment, including modification of company data. This issue…

  • CVE-2026-8636MedJun 22, 2026
    risk 0.36cvss 5.5epss 0.00

    IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 allows an attacker to retrieve user passwords and cryptographic keys from memory. Attacker can use the same keys to decrypt password, gain access to the application and access sensitive data…