CWE-312— Cleartext Storage of Sensitive Information
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.— MITRE CWE catalog
903 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-312page 15 of 19
- CVE-2020-35658MEDIUMCVSS 5.3EG 5.32020-12-23
SpamTitan before 7.09 allows attackers to tamper with backups, because backups are not encrypted.
- CVE-2020-15784MEDIUMCVSS 5.3EG 5.32020-09-09
A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP8). Insecure storage of sensitive information in the configuration files could allow the retrieval of user names.
- CVE-2019-17655MEDIUMCVSS 5.3EG 5.32020-06-16
A cleartext storage in a file or on disk (CWE-313) vulnerability in FortiOS SSL VPN 6.2.0 through 6.2.2, 6.0.9 and earlier and FortiProxy 2.0.0, 1.2.9 and earlier may allow an attacker to retrieve a logged-in SSL VPN user's credentials sho…
- CVE-2020-12801MEDIUMCVSS 5.3EG 5.32020-05-18
If LibreOffice has an encrypted document open and crashes, that document is auto-saved encrypted. On restart, LibreOffice offers to restore the document and prompts for the password to decrypt it. If the recovery is successful, and if the …
- CVE-2020-12859MEDIUMCVSS 5.3EG 5.32020-05-18
Unnecessary fields in the OpenTrace/BlueTrace protocol in COVIDSafe through v1.0.17 allow a remote attacker to identify a device model by observing cleartext payload data. This allows re-identification of devices, especially less common ph…
- CVE-2020-11821MEDIUMCVSS 5.3EG 5.32020-04-27
In Rukovoditel 2.5.2, users' passwords and usernames are stored in a cookie with URL encoding, base64 encoding, and hashing. Thus, an attacker can easily apply brute force on them.
- CVE-2019-19291MEDIUMCVSS 5.3EG 5.32020-03-10
A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0), SiNVR/SiVMS Video Server (All versions < V5.0.0). The FTP services of the SiVMS/SiNVR Video Server and the Control Center Server (CCS) maintain log…
- CVE-2020-9407MEDIUMCVSS 5.3EG 5.32020-02-26
IBL Online Weather before 4.3.5a allows attackers to obtain sensitive information by reading the IWEBSERVICE_JSONRPC_COOKIE cookie.
- CVE-2019-8118MEDIUMCVSS 5.3EG 5.32019-11-05
Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 uses weak cryptographic function to store the failed login attempts for customer accounts.
- CVE-2026-9274MEDIUMCVSS 5.2EG 5.22026-05-25
This vulnerability exists in CP Plus Wi-Fi Camera due to improper protection of sensitive information in runtime memory. An attacker with physical access could exploit this vulnerability by accessing the UART interface and performing memor…
- CVE-2025-55280MEDIUMCVSS 5.2EG 5.22025-08-13
This vulnerability exists in ZKTeco WL20 due to storage of Wi-Fi credentials, configuration data and system data in plaintext within the device firmware. An attacker with physical access could exploit this vulnerability by extracting the f…
- CVE-2025-0418MEDIUMCVSS 5.2EG 5.22025-04-01
Valmet DNA user passwords in plain text. This practice poses a security risk as attackers who gain access to local project data can read the passwords.
- CVE-2021-36096MEDIUMCVSS 5.2EG 5.22021-09-06
Generated Support Bundles contains private S/MIME and PGP keys if containing folder is not hidden. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.28 and prior v…
- CVE-2025-11009MEDIUMCVSS 5.1EG 5.12025-12-17
Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GT Designer3 Version1 (GOT2000) all versions and Mitsubishi Electric GT Designer3 Version1 (GOT1000) all versions allows a local unauthenticated attacker to ob…
- CVE-2025-53758MEDIUMCVSS 5.1EG 5.12025-07-16
This vulnerability exists in Digisol DG-GR6821AC Router due to use of default admin credentials at its web management interface. An attacker with physical access could exploit this vulnerability by extracting the firmware and reverse engin…
- CVE-2025-53755MEDIUMCVSS 5.1EG 5.12025-07-16
This vulnerability exists in Digisol DG-GR6821AC Router due to storage of credentials and PINS without encryption in the device firmware. An attacker with physical access could exploit this vulnerability by extracting the firmware and reve…
- CVE-2024-47056MEDIUMCVSS 5.1EG 5.12025-05-28
SummaryThis advisory addresses a security vulnerability in Mautic where sensitive .env configuration files may be directly accessible via a web browser. This exposure could lead to the disclosure of sensitive information, including databa…
- CVE-2025-2189MEDIUMCVSS 5.1EG 5.12025-03-11
This vulnerability exists in the Tinxy smart devices due to storage of credentials in plaintext within the device firmware. An attacker with physical access could exploit this by extracting the firmware and analyzing the binary data to obt…
- CVE-2023-31002MEDIUMCVSS 5.1EG 5.12024-02-07
IBM Security Access Manager Container 10.0.0.0 through 10.0.6.1 temporarily stores sensitive information in files that could be accessed by a local user. IBM X-Force ID: 254657.
- CVE-2024-50570MEDIUMCVSS 5.0EG 5.02024-12-18
A Cleartext Storage of Sensitive Information vulnerability [CWE-312] in FortiClientWindows 7.4.0 through 7.4.1, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13 and FortiClientLinux 7.4.0 through 7.4.2, 7.2.0 through 7.2.7, 7.0.0 through 7.0.13 m…
- CVE-2023-0690MEDIUMCVSS 5.0EG 5.02023-02-08
HashiCorp Boundary from 0.10.0 through 0.11.2 contain an issue where when using a PKI-based worker with a Key Management Service (KMS) defined in the configuration file, new credentials created after an automatic rotation may not have bee…
- CVE-2021-1865MEDIUMCVSS 5.0EG 5.02021-09-08
An issue obscuring passwords in screenshots was addressed with improved logic. This issue is fixed in iOS 14.5 and iPadOS 14.5. A user's password may be visible on screen.
- CVE-2026-100862MEDIUMCVSS 4.9EG 4.92026-09-27
heym, a workflow automation platform, stores and returns multiple capability secrets in plaintext in versions prior to 0.0.91. Affected secrets include webhook header-auth values (returned in cleartext by GET /api/workflows/{id} and persis…
- CVE-2026-3221MEDIUMCVSS 4.9EG 4.92026-02-25
Sensitive user account information is not encrypted in the database in Devolutions Server 2025.3.14 and earlier, which allows an attacker with access to the database to obtain sensitive user information via direct database access.
- CVE-2025-12772MEDIUMCVSS 4.9EG 4.92026-02-02
Brocade SANnav before 2.4.0b logs the Brocade Fabric OS Switch admin password on the SANnav support save logs. When OOM occurs on a Brocade SANnav server, the call stack trace for the Brocade switch is also collected in the heap dump file…
- CVE-2025-12680MEDIUMCVSS 4.9EG 4.92026-02-02
Brocade SANnav before Brocade SANnav 2.4.0b logs database passwords in clear text in the standby SANnav server, after disaster recovery failover. The vulnerability could allow a remote authenticated attacker with admin privilege able to a…
- CVE-2025-34270MEDIUMCVSS 4.9EG 4.92025-10-30
Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the AD/LDAP user import functionality as it fails to obfuscate the password field during import. As a result, the plaintext password supplied for imported accounts m…
- CVE-2024-7259MEDIUMCVSS 4.9EG 4.92024-09-26
A flaw was found in oVirt. A user with administrator privileges, including users with the ReadOnlyAdmin permission, may be able to use browser developer tools to view Provider passwords in cleartext.
- CVE-2024-33470MEDIUMCVSS 4.9EG 4.92024-05-24
An issue in the SMTP Email Settings of AVTECH Room Alert 4E v4.4.0 allows attackers to gain access to credentials in plaintext via a passback attack. NOTE: This vulnerability only affects products that are no longer supported by the mainta…
- CVE-2023-20207MEDIUMCVSS 4.9EG 4.92023-07-12
A vulnerability in the logging component of Cisco Duo Authentication Proxy could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability exists because certain unencr…
- CVE-2023-22949MEDIUMCVSS 4.9EG 4.92023-04-14
An issue was discovered in TigerGraph Enterprise Free Edition 3.x. There is logging of user credentials. All authenticated GSQL access requests are logged by TigerGraph in multiple places. Each request includes both the username and passwo…
- CVE-2021-20162MEDIUMCVSS 4.9EG 4.92021-12-30
Trendnet AC2600 TEW-827DRU version 2.08B01 stores credentials in plaintext. Usernames and passwords are stored in plaintext in the config files on the device. For example, /etc/config/cameo contains the admin password in plaintext.
- CVE-2021-35035MEDIUMCVSS 4.9EG 4.92021-12-29
A cleartext storage of sensitive information vulnerability in the Zyxel NBG6604 firmware could allow a remote, authenticated attacker to obtain sensitive information from the configuration file.
- CVE-2021-38911MEDIUMCVSS 4.9EG 4.92021-10-19
IBM Security Risk Manager on CP4S 1.7.0.0 stores user credentials in plain clear text which can be read by a an authenticatedl privileged user. IBM X-Force ID: 209940.
- CVE-2021-33325MEDIUMCVSS 4.9EG 4.92021-08-03
The Portal Workflow module in Liferay Portal 7.3.2 and earlier, and Liferay DXP 7.0 before fix pack 93, 7.1 before fix pack 19, and 7.2 before fix pack 7, user's clear text passwords are stored in the database if workflow is enabled for us…
- CVE-2021-27233MEDIUMCVSS 4.9EG 4.92021-02-16
An issue was discovered in Mutare Voice (EVM) 3.x before 3.3.8. On the admin portal of the web application, password information for external systems is visible in cleartext. The Settings.asp page is affected by this issue.
- CVE-2020-11415MEDIUMCVSS 4.9EG 4.92020-04-27
An issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.17 and 3.x before 3.22.1. Admin users can retrieve the LDAP server system username/password (as configured in nxrm) in cleartext.
- CVE-2019-18615MEDIUMCVSS 4.9EG 4.92019-12-19
In CloudVision Portal (CVP) for all releases in the 2018.2 Train, under certain conditions, the application logs user passwords in plain text for certain API calls, potentially leading to user password exposure. This only affects CVP envir…
- CVE-2019-13947MEDIUMCVSS 4.9EG 4.92019-12-12
A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The user configuration menu in the web interface of the Control Center Server (CCS) transfers user passwords in clear to the client (browser). An …
- CVE-2023-25596MEDIUMCVSS 4.5EG 4.92023-03-22
A vulnerability exists in ClearPass Policy Manager that allows for an attacker with administrative privileges to access sensitive information in a cleartext format. A successful exploit allows an attacker to retrieve information which cou…
- CVE-2023-0005MEDIUMCVSS 4.1EG 4.92023-04-12
A vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to expose the plaintext values of secrets stored in the device configuration and encrypted API keys.
- CVE-2018-5559MEDIUMCVSS 3.4EG 4.92018-11-28
In Rapid7 Komand version 0.41.0 and prior, certain endpoints that are able to list the always encrypted-at-rest connection data could return some configurations of connection data without obscuring sensitive data from the API response sent…
- CVE-2026-50267MEDIUMCVSS 4.7EG 4.72026-06-17
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Configuration.Abstractions 4.0.0 through 4.1.0, when MySQL or PostgreSQL service bindings from `VCAP_S…
- CVE-2020-23249MEDIUMCVSS 4.7EG 4.72021-01-05
GigaVUE-OS (GVOS) 5.4 - 5.9 stores a Redis database password in plaintext.
- CVE-2018-1882MEDIUMCVSS 4.7EG 4.72019-04-08
In a certain atypical IBM Spectrum Protect 7.1 and 8.1 configurations, the node password could be displayed in plain text in the IBM Spectrum Protect client trace file. IBM X-Force ID: 151968.
- CVE-2025-56566MEDIUMCVSS 4.6EG 4.62026-09-16
MikroTik firmware 7.19.4 stores sensitive authentication credentials and network state in cleartext within non-volatile storage. An attacker with physical access to the device can extract this material from an SPI flash dump, without authe…
- CVE-2026-38571MEDIUMCVSS 4.6EG 4.62026-06-26
Cleartext storage and exposure of WPA2 credentials, and missing authentication on the rr/wr memory read/write commands, in the unauthenticated UART debug console of the Tenda N300 F3 (V603) allow a physically proximate attacker to obtain s…
- CVE-2024-53651MEDIUMCVSS 4.6EG 4.62025-02-11
A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 6MD85 (CP300) (All versions), SIPROTEC 5 6MD86 (CP200) (All versions), SIPROTEC 5 6MD86 (CP300) (All versio…
- CVE-2024-45718MEDIUMCVSS 4.6EG 4.62025-02-11
Sensitive data could be exposed to non- privileged users in a configuration file. Local access to the computer with a low- privileged account is required to access the configuration file containing the sensitive data.
- CVE-2024-10523MEDIUMCVSS 4.6EG 4.62024-11-04
This vulnerability exists in TP-Link IoT Smart Hub due to storage of Wi-Fi credentials in plain text within the device firmware. An attacker with physical access could exploit this by extracting the firmware and analyzing the binary data t…
Map vulnerabilities like CWE-312 to your infrastructure
EchelonGraph correlates every CVE — across CWE-312 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →