CWE-312— Cleartext Storage of Sensitive Information
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.— MITRE CWE catalog
902 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-312page 5 of 19
- CVE-2015-8314HIGHCVSS 7.5EG 7.52023-12-12
The Devise gem before 3.5.4 for Ruby mishandles Remember Me cookies for sessions, which may allow an adversary to obtain unauthorized persistent application access.
- CVE-2023-46388HIGHCVSS 7.5EG 7.52023-11-30
LOYTEC electronics GmbH LINX-212 and LINX-151 devices (all versions) are vulnerable to Insecure Permissions via dpal_config.zml file. This vulnerability allows remote attackers to disclose smtp client account credentials and bypass email a…
- CVE-2023-46386HIGHCVSS 7.5EG 7.52023-11-30
LOYTEC electronics GmbH LINX-212 and LINX-151 devices (all versions) are vulnerable to Insecure Permissions via registry.xml file. This vulnerability allows remote attackers to disclose smtp client account credentials and bypass email auth…
- CVE-2023-46384HIGHCVSS 7.5EG 7.52023-11-30
LOYTEC electronics GmbH LINX Configurator (all versions) is vulnerable to Insecure Permissions. Cleartext storage of credentials allows remote attackers to disclose admin password and bypass an authentication to login Loytec device.
- CVE-2023-46376HIGHCVSS 7.5EG 7.52023-10-27
Zentao Biz version 8.7 and before is vulnerable to Information Disclosure.
- CVE-2023-44037HIGHCVSS 7.5EG 7.52023-10-14
An issue in ZPE Systems, Inc Nodegrid OS v.5.8.10 thru v.5.8.13 and v.5.10.3 thru v.5.10.5 allows a remote attacker to obtain sensitive information via the TACACS+ server component.
- CVE-2023-44159HIGHCVSS 7.5EG 7.52023-09-27
Sensitive information disclosure due to cleartext storage of sensitive information. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979.
- CVE-2023-44153HIGHCVSS 7.5EG 7.52023-09-27
Sensitive information disclosure due to cleartext storage of sensitive information in memory. The following products are affected: Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 35979.
- CVE-2023-31041HIGHCVSS 7.5EG 7.52023-08-14
An issue was discovered in SysPasswordDxe in Insyde InsydeH2O with kernel 5.0 through 5.5. System password information could optionally be stored in cleartext, which might lead to possible information disclosure.
- CVE-2023-39379HIGHCVSS 7.5EG 7.52023-08-04
Fujitsu Software Infrastructure Manager (ISM) stores sensitive information at the product's maintenance data (ismsnap) in cleartext form. As a result, the password for the proxy server that is configured in ISM may be retrieved. Affected p…
- CVE-2023-30146HIGHCVSS 7.5EG 7.52023-08-04
Assmann Digitus Plug&View IP Camera HT-IP211HDP, version 2.000.022 allows unauthenticated attackers to download a copy of the camera's settings and the administrator credentials.
- CVE-2023-39144HIGHCVSS 7.5EG 7.52023-08-03
Element55 KnowMore appliances version 21 and older was discovered to store passwords in plaintext.
- CVE-2023-33742HIGHCVSS 7.5EG 7.52023-07-27
TeleAdapt RoomCast TA-2400 1.0 through 3.1 suffers from Cleartext Storage of Sensitive Information: RSA private key in Update.exe.
- CVE-2023-30367HIGHCVSS 7.5EG 7.52023-07-26
Multi-Remote Next Generation Connection Manager (mRemoteNG) is free software that enables users to store and manage multi-protocol connection configurations to remotely connect to systems. mRemoteNG configuration files can be stored in an …
- CVE-2023-31821HIGHCVSS 7.5EG 7.52023-07-13
An issue found in ALBIS Co. ALBIS v.13.6.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp ALBIS function.
- CVE-2023-27243HIGHCVSS 7.5EG 7.52023-06-21
An access control issue in Makves DCAP v3.0.0.122 allows unauthenticated attackers to obtain cleartext credentials via a crafted web request to the product API.
- CVE-2023-22584HIGHCVSS 7.5EG 7.52023-06-11
The Danfoss AK-EM100 stores login credentials in cleartext.
- CVE-2023-29480HIGHCVSS 7.5EG 7.52023-04-24
Ribose RNP before 0.16.3 sometimes lets secret keys remain unlocked after use.
- CVE-2023-31043HIGHCVSS 7.5EG 7.52023-04-23
EnterpriseDB EDB Postgres Advanced Server (EPAS) before 14.6.0 logs unredacted passwords in situations where optional parameters are used with CREATE/ALTER USER/GROUP/ROLE, and redacting was configured with edb_filter_log.redact_password_c…
- CVE-2023-26760HIGHCVSS 7.5EG 7.52023-02-27
Sme.UP ERP TOKYO V6R1M220406 was discovered to contain an information disclosure vulnerability via the /debug endpoint. This vulnerability allows attackers to access cleartext credentials needed to authenticate to the AS400 system.
- CVE-2022-48073HIGHCVSS 7.5EG 7.52023-01-27
Phicomm K2G v22.6.3.20 was discovered to store the root and admin passwords in plaintext.
- CVE-2022-48071HIGHCVSS 7.5EG 7.52023-01-27
Phicomm K2 v22.6.534.263 was discovered to store the root and admin passwords in plaintext.
- CVE-2022-38112HIGHCVSS 7.5EG 7.52023-01-20
In DPA 2022.4 and older releases, generated heap memory dumps contain sensitive information in cleartext.
- CVE-2022-37785HIGHCVSS 7.5EG 7.52023-01-01
An issue was discovered in WeCube Platform 3.2.2. Cleartext passwords are displayed in the configuration for terminal plugins.
- CVE-2022-24188HIGHCVSS 7.5EG 7.52022-11-28
The /device/signin end-point for the Ourphoto App version 1.4.1 discloses clear-text password information for functionality within the picture frame devices. The deviceVideoCallPassword and mqttPassword are returned in clear-text. The lack…
- CVE-2022-42956HIGHCVSS 7.5EG 7.52022-11-07
The PassWork extension 5.0.9 for Chrome and other browsers allows an attacker to obtain the cleartext master password.
- CVE-2022-42955HIGHCVSS 7.5EG 7.52022-11-07
The PassWork extension 5.0.9 for Chrome and other browsers allows an attacker to obtain cleartext cached credentials.
- CVE-2022-37857HIGHCVSS 7.5EG 7.52022-09-08
bilde2910 Hauk v1.6.1 requires a hardcoded password which by default is blank. This hardcoded password is hashed but stored within the config.php file server-side as well as in clear-text on the android client device by default.
- CVE-2022-34924HIGHCVSS 7.5EG 7.52022-08-02
Lanling OA Landray Office Automation (OA) internal patch number #133383/#137780 contains an arbitrary file read vulnerability via the component /sys/ui/extend/varkind/custom.jsp.
- CVE-2022-31205HIGHCVSS 7.5EG 7.52022-07-26
In Omron CS series, CJ series, and CP series PLCs through 2022-05-18, the password for access to the Web UI is stored in memory area D1449...D1452 and can be read out using the Omron FINS protocol without any further authentication.
- CVE-2022-30275HIGHCVSS 7.5EG 7.52022-07-26
The Motorola MOSCAD Toolbox software through 2022-05-02 relies on a cleartext password. It utilizes an MDLC driver to communicate with MOSCAD/ACE RTUs for engineering purposes. Access to these communications is protected by a password stor…
- CVE-2022-24660HIGHCVSS 7.5EG 7.52022-07-20
The debug interface of Goldshell ASIC Miners v2.2.1 and below was discovered to be exposed publicly on the web interface, allowing attackers to access passwords and other sensitive information in plaintext.
- CVE-2021-45025HIGHCVSS 7.5EG 7.52022-06-17
ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to Cleartext Storage of Sensitive Information in a Cookie.
- CVE-2022-31004HIGHCVSS 7.5EG 7.52022-06-02
CVEProject/cve-services is an open source project used to operate the CVE services API. A conditional in 'data.js' has potential for production secrets to be written to disk. The affected method writes the generated randomKey to disk if th…
- CVE-2021-27757HIGHCVSS 7.5EG 7.52022-03-04
" Insecure password storage issue.The application stores sensitive information in cleartext within a resource that might be accessible to another control sphere.Since the information is stored in cleartext, attackers could potentially read…
- CVE-2021-42642HIGHCVSS 7.5EG 7.52022-02-02
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an unauthenticated attacker to disclose the plaintext console username and password for a printe…
- CVE-2021-45077HIGHCVSS 7.5EG 7.52021-12-30
Netgear Nighthawk R6700 version 1.0.4.120 stores sensitive information in plaintext. All usernames and passwords for the device's associated services are stored in plaintext on the device. For example, the admin password is stored in plain…
- CVE-2021-20827HIGHCVSS 7.5EG 7.52021-12-24
Plaintext storage of a password vulnerability in IDEC PLCs (FC6A Series MICROSmart All-in-One CPU module v2.32 and earlier, FC6A Series MICROSmart Plus CPU module v1.91 and earlier, WindLDR v8.19.1 and earlier, WindEDIT Lite v1.3.1 and ear…
- CVE-2021-43388HIGHCVSS 7.5EG 7.52021-12-14
Unisys Cargo Mobile Application before 1.2.29 uses cleartext to store sensitive information, which might be revealed in a backup. The issue is addressed by ensuring that the allowBackup flag (in the manifest) is False.
- CVE-2021-42370HIGHCVSS 7.5EG 7.52021-11-08
A password mismanagement situation exists in XoruX LPAR2RRD and STOR2RRD before 7.30 because cleartext information is present in HTML password input fields in the device properties. (Viewing the passwords requires configuring a web browser…
- CVE-2021-42763HIGHCVSS 7.5EG 7.52021-11-02
Couchbase Server before 6.6.3 and 7.x before 7.0.2 stores Sensitive Information in Cleartext. The issue occurs when the cluster manager forwards a HTTP request from the pluggable UI (query workbench etc) to the specific service. In the bac…
- CVE-2021-37842HIGHCVSS 7.5EG 7.52021-11-02
metakv in Couchbase Server 7.0.0 uses Cleartext for Storage of Sensitive Information. Remote Cluster XDCR credentials can get leaked in debug logs. Config key tombstone purging was added in Couchbase Server 7.0.0. This issue happens when a…
- CVE-2020-19137HIGHCVSS 7.5EG 7.52021-09-08
Incorrect Access Control in Autumn v1.0.4 and earlier allows remote attackers to obtain clear-text login credentials via the component "autumn-cms/user/getAllUser/?page=1&limit=10".
- CVE-2021-30997HIGHCVSS 7.5EG 7.52021-08-24
A S/MIME issue existed in the handling of encrypted email. This issue was addressed by not automatically loading some MIME parts. This issue is fixed in iOS 15.2 and iPadOS 15.2. An attacker may be able to recover plaintext contents of an …
- CVE-2021-31820HIGHCVSS 7.5EG 7.52021-08-18
In Octopus Server after version 2018.8.2 if the Octopus Server Web Request Proxy is configured with authentication, the password is shown in plaintext in the UI.
- CVE-2020-18759HIGHCVSS 7.5EG 7.52021-08-13
An information disclosure vulnerability exists in the EPA protocol of Dut Computer Control Engineering Co.'s PLC MAC1100.
- CVE-2021-37548HIGHCVSS 7.5EG 7.52021-08-06
In JetBrains TeamCity before 2021.1, passwords in cleartext sometimes could be stored in VCS.
- CVE-2021-33323HIGHCVSS 7.5EG 7.52021-08-03
The Dynamic Data Mapping module in Liferay Portal 7.1.0 through 7.3.2, and Liferay DXP 7.1 before fix pack 19, and 7.2 before fix pack 7, autosaves form values for unauthenticated users, which allows remote attackers to view the autosaved …
- CVE-2020-22741HIGHCVSS 7.5EG 7.52021-07-19
An issue was discovered in Xuperchain 3.6.0 that allows for attackers to recover any arbitrary users' private key after obtaining the partial signature in multisignature.
- CVE-2020-12731HIGHCVSS 7.5EG 7.52021-07-15
The MagicMotion Flamingo 2 application for Android stores data on an sdcard under com.vt.magicmotion/files/Pictures, whence it can be read by other applications.
Map vulnerabilities like CWE-312 to your infrastructure
EchelonGraph correlates every CVE — across CWE-312 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →