VYPR

CWE-922

Insecure Storage of Sensitive Information

ClassIncomplete

Description

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

If read access is not properly restricted, then attackers can steal the sensitive information. If write access is not properly restricted, then attackers can modify and possibly delete the data, causing incorrect results and possibly a denial of service.

Hierarchy (View 1000)

Parents

CVEs mapped to this weakness (381)

page 2 of 20
  • CVE-2023-43634HigSep 21, 2023
    risk 0.57cvss 8.8epss 0.00

    When sealing/unsealing the “vault” key, a list of PCRs is used, which defines which PCRs are used. In a previous project, CYMOTIVE found that the configuration is not protected by the secure boot, and in response Zededa implemented measurements on the config partition that…

  • CVE-2017-7253HigMar 30, 2017
    risk 0.57cvss 8.8epss 0.03

    Dahua IP Camera devices 3.200.0001.6 can be exploited via these steps: 1. Use the default low-privilege credentials to list all users via a request to a certain URI. 2. Login to the IP camera with admin credentials so as to obtain full control of the target IP camera. During…

  • CVE-2025-14376HigJan 20, 2026
    risk 0.56cvss epss 0.00

    A security issue was discovered within the legacy ADI server component of Verve Asset Manager, caused by plaintext secrets stored in environment variables on the ADI server. This component has been retired and has been optional since the 1.36 release in 2024.

  • CVE-2024-30896CriNov 21, 2024
    risk 0.56cvss 9.1epss 0.05

    InfluxDB OSS 2.x through 2.7.11 stores the administrative operator token under the default organization which allows authorized users with read access to the authorization resource of the default organization to retrieve the operator token. InfluxDB OSS 1.x, Enterprise, Cloud,…

  • CVE-2025-46627HigMay 1, 2025
    risk 0.53cvss 8.2epss 0.00

    Use of weak credentials in the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated attacker to authenticate to the telnet service by calculating the root password based on easily-obtained device information. The password is based on the last two digits/octets of the MAC address.

  • CVE-2024-37144HigDec 10, 2024
    risk 0.53cvss 8.2epss 0.00

    Dell PowerFlex appliance versions prior to IC 46.381.00 and IC 46.376.00, Dell PowerFlex rack versions prior to RCM 3.8.1.0 (for RCM 3.8.x train) and prior to RCM 3.7.6.0 (for RCM 3.7.x train), Dell PowerFlex custom node using PowerFlex Manager versions prior to 4.6.1.0, Dell…

  • CVE-2024-48770HigOct 11, 2024
    risk 0.53cvss 8.2epss 0.00

    An issue in Plug n Play Camera com.wisdomcity.zwave 1.1.0 allows a remote attacker to obtain sensitive information via the firmware update process.

  • CVE-2024-22773HigFeb 6, 2024
    risk 0.53cvss 8.1epss 0.01

    Intelbras Action RF 1200 routers 1.2.2 and earlier and Action RG 1200 routers 2.1.7 and earlier expose the Password in Cookie resulting in Login Bypass.

  • CVE-2022-44619HigMay 10, 2023
    risk 0.53cvss 8.2epss 0.00

    Insecure storage of sensitive information in the Intel(R) DCM software before version 5.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2026-33407CriMar 24, 2026
    risk 0.52cvss 9.1epss 0.00

    Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, Wallos endpoints/logos/search.php accepts HTTP_PROXY and HTTPS_PROXY environment variables without validation, enabling SSRF via proxy hijacking. The server performs DNS resolution on…

  • CVE-2023-31150HigMay 10, 2023
    risk 0.52cvss 8.0epss 0.00

    A Storing Passwords in a Recoverable Format vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) database system could allow an authenticated attacker to retrieve passwords. See SEL Service Bulletin dated 2022-11-15 for more…

  • CVE-2025-34189HigSep 19, 2025
    risk 0.51cvss 7.8epss 0.00

    Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 1.0.735 and Application versions prior to 20.0.1330 (macOS/Linux client deployments) contain a vulnerability in the local inter-process communication (IPC) mechanism. The software stores IPC request…

  • CVE-2023-32184HigSep 19, 2023
    risk 0.51cvss 7.8epss 0.00

    A Insecure Storage of Sensitive Information vulnerability in openSUSE opensuse-welcome allows local attackers to execute code as the user that runs opensuse-welcome if a custom layout is chosen This issue affects opensuse-welcome: from 0.1 before 0.1.9+git.35.4b9444a.

  • CVE-2023-29757HigJun 9, 2023
    risk 0.51cvss 7.8epss 0.00

    An issue found in Blue Light Filter v.1.5.5 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating the SharedPreference files.

  • CVE-2023-29755HigJun 9, 2023
    risk 0.51cvss 7.8epss 0.00

    An issue found in Twilight v.13.3 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating the SharedPreference files.

  • CVE-2020-8482HigMay 29, 2020
    risk 0.51cvss 7.8epss 0.00

    Insecure storage of sensitive information in ABB Device Library Wizard versions 6.0.X, 6.0.3.1 and 6.0.3.2 allows unauthenticated low privilege user to read file that contains confidential data

  • CVE-2019-5627HigMay 22, 2019
    risk 0.51cvss 7.8epss 0.00

    The iOS mobile application BlueCats Reveal before 5.14 stores the username and password in the app cache as base64 encoded strings, i.e. clear text. These persist in the cache even if the user logs out. This can allow an attacker to compromise the affected BlueCats network…

  • CVE-2019-5626HigMay 22, 2019
    risk 0.51cvss 7.8epss 0.00

    The Android mobile application BlueCats Reveal before 3.0.19 stores the username and password in a clear text file. This file persists until the user logs out or the session times out from non-usage (30 days of no user activity). This can allow an attacker to compromise the…

  • CVE-2025-37100HigJun 10, 2025
    risk 0.50cvss 7.7epss 0.00

    A vulnerability in the APIs of HPE Aruba Networking Private 5G Core could potentially expose sensitive information to unauthorized users. A successful exploitation could allow an attacker to iteratively navigate through the filesystem and ultimately download protected system…

  • CVE-2025-45242HigMay 5, 2025
    risk 0.50cvss 7.7epss 0.00

    Rhymix v2.1.22 was discovered to contain an arbitrary file deletion vulnerability via the procFileAdminEditImage method in /file/file.admin.controller.php.