CWE-312— Cleartext Storage of Sensitive Information
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.— MITRE CWE catalog
902 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-312page 6 of 19
- CVE-2021-31817HIGHCVSS 7.5EG 7.52021-07-08
When configuring Octopus Server if it is configured with an external SQL database, on initial configuration the database password is written to the OctopusServer.txt log file in plaintext.
- CVE-2021-31816HIGHCVSS 7.5EG 7.52021-07-08
When configuring Octopus Server if it is configured with an external SQL database, on initial configuration the database password is written to the OctopusServer.txt log file in plaintext.
- CVE-2021-29950HIGHCVSS 7.5EG 7.52021-06-24
Thunderbird unprotects a secret OpenPGP key prior to using it for a decryption, signing or key import task. If the task runs into a failure, the secret key may remain in memory in its unprotected state. This vulnerability affects Thunderbi…
- CVE-2020-29324HIGHCVSS 7.5EG 7.52021-06-04
The DLink Router DIR-895L MFC v1.21b05 is vulnerable to credentials disclosure in telnet service through decompilation of firmware, that allows an unauthenticated attacker to gain access to the firmware and to extract sensitive data.
- CVE-2021-25644HIGHCVSS 7.5EG 7.52021-05-19
An issue was discovered in Couchbase Server 5.x and 6.x through 6.6.1 and 7.0.0 Beta. Incorrect commands to the REST API can result in leaked authentication information being stored in cleartext in the debug.log and info.log files, and is …
- CVE-2021-30183HIGHCVSS 7.5EG 7.52021-05-14
Cleartext storage of sensitive information in multiple versions of Octopus Server where in certain situations when running import or export processes, the password used to encrypt and decrypt sensitive values would be written to the logs i…
- CVE-2021-31791HIGHCVSS 7.5EG 7.52021-04-23
In Hardware Sentry KM before 10.0.01 for BMC PATROL, a cleartext password may be discovered after a failure or timeout of a command.
- CVE-2021-25898HIGHCVSS 7.5EG 7.52021-04-23
An issue was discovered in svc-login.php in Void Aural Rec Monitor 9.0.0.1. Passwords are stored in unencrypted source-code text files. This was noted when accessing the svc-login.php file. The value is used to authenticate a high-privileg…
- CVE-2021-28937HIGHCVSS 7.5EG 7.52021-03-29
The /password.html page of the Web management interface of the Acexy Wireless-N WiFi Repeater REV 1.0 (28.08.06.1) contains the administrator account password in plaintext. The page can be intercepted on HTTP.
- CVE-2021-28374HIGHCVSS 7.5EG 7.52021-03-15
The Debian courier-authlib package before 0.71.1-2 for Courier Authentication Library creates a /run/courier/authdaemon directory with weak permissions, allowing an attacker to read user information. This may include a cleartext password i…
- CVE-2019-18630HIGHCVSS 7.5EG 7.52021-03-04
On Xerox AltaLink B8045/B8055/B8065/B8075/B8090 and C8030/C8035/C8045/C8055/C8070 multifunction printers with software releases before 101.00x.099.28200, portions of the drive containing executable code were not encrypted thus leaving it o…
- CVE-2021-27178HIGHCVSS 7.5EG 7.52021-02-10
An issue was discovered on FiberHome HG6245D devices through RP2613. Some passwords are stored in cleartext in nvram.
- CVE-2021-27176HIGHCVSS 7.5EG 7.52021-02-10
An issue was discovered on FiberHome HG6245D devices through RP2613. wifictl_5g.cfg has cleartext passwords and 0644 permissions.
- CVE-2021-27175HIGHCVSS 7.5EG 7.52021-02-10
An issue was discovered on FiberHome HG6245D devices through RP2613. wifictl_2g.cfg has cleartext passwords and 0644 permissions.
- CVE-2021-27174HIGHCVSS 7.5EG 7.52021-02-10
An issue was discovered on FiberHome HG6245D devices through RP2613. wifi_custom.cfg has cleartext passwords and 0644 permissions.
- CVE-2021-27140HIGHCVSS 7.5EG 7.52021-02-10
An issue was discovered on FiberHome HG6245D devices through RP2613. It is possible to find passwords and authentication cookies stored in cleartext in the web.log HTTP logs.
- CVE-2020-5018HIGHCVSS 7.5EG 7.52021-01-08
IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may include sensitive information in its URLs increasing the risk of such information being caputured by an attacker. IBM X-Force ID: 193654.
- CVE-2020-24577HIGHCVSS 7.5EG 7.52021-01-08
An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. The One Touch application discloses sensitive information, such as the hashed admin login password and the Internet provider connection usernam…
- CVE-2020-29502HIGHCVSS 7.5EG 7.52021-01-05
Dell EMC PowerStore versions prior to 1.0.3.0.5.007 contain a Plain-Text Password Storage Vulnerability in PowerStore X & T environments. A locally authenticated attacker could potentially exploit this vulnerability, leading to the disclos…
- CVE-2020-29500HIGHCVSS 7.5EG 7.52021-01-05
Dell EMC PowerStore versions prior to 1.0.3.0.5.007 contain a Plain-Text Password Storage Vulnerability in PowerStore T environments. A locally authenticated attacker could potentially exploit this vulnerability, leading to the disclosure …
- CVE-2018-19941HIGHCVSS 7.5EG 7.52020-12-31
A vulnerability has been reported to affect QNAP NAS. If exploited, this vulnerability allows an attacker to access sensitive information stored in cleartext inside cookies via certain widely-available tools. QNAP have already fixed this v…
- CVE-2020-29550HIGHCVSS 7.5EG 7.52020-12-23
An issue was discovered in URVE Build 24.03.2020. The password of an integration user account (used for the connection of the MS Office 365 Integration Service) is stored in cleartext in configuration files as well as in the database. The …
- CVE-2020-26551HIGHCVSS 7.5EG 7.52020-11-17
An issue was discovered in Aviatrix Controller before R5.3.1151. Encrypted key values are stored in a readable file.
- CVE-2020-27986HIGHCVSS 7.5EG 7.52020-10-28
SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI. NOTE: reportedly, the vendor's position for SMTP and SVN is "it is the administrator's responsibility to…
- CVE-2020-8225HIGHCVSS 7.5EG 7.52020-09-18
A cleartext storage of sensitive information in Nextcloud Desktop Client 2.6.4 gave away information about used proxies and their authentication credentials.
- CVE-2020-15484HIGHCVSS 7.5EG 7.52020-08-26
An issue was discovered on Nescomed Multipara Monitor M1000 devices. The internal storage of the underlying Linux system stores data in cleartext, without integrity protection against tampering.
- CVE-2020-17495HIGHCVSS 7.5EG 7.52020-08-11
django-celery-results through 1.2.1 stores task results in the database. Among the data it stores are the variables passed into the tasks. The variables may contain sensitive cleartext information that does not belong unencrypted in the da…
- CVE-2020-14017HIGHCVSS 7.5EG 7.52020-06-24
An issue was discovered in Navigate CMS 2.9 r1433. Sessions, as well as associated information such as CSRF tokens, are stored in cleartext files in the directory /private/sessions. An unauthenticated user could use a brute-force approach …
- CVE-2020-10273HIGHCVSS 7.5EG 7.52020-06-24
MiR controllers across firmware versions 2.8.1.1 and before do not encrypt or protect in any way the intellectual property artifacts installed in the robots. This flaw allows attackers with access to the robot or the robot network (while i…
- CVE-2020-13637HIGHCVSS 7.5EG 7.52020-06-17
An issue was discovered in the stashcat app through 3.9.2 for macOS, Windows, Android, iOS, and possibly other platforms. It stores the client_key, the device_id, and the public key for end-to-end encryption in cleartext, enabling an attac…
- CVE-2020-7513HIGHCVSS 7.5EG 7.52020-06-16
A CWE-312: Cleartext Storage of Sensitive Information vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to intercept traffic and read configuration data.
- CVE-2020-13783HIGHCVSS 7.5EG 7.52020-06-03
D-Link DIR-865L Ax 1.20B01 Beta devices have Cleartext Storage of Sensitive Information.
- CVE-2020-11826HIGHCVSS 7.5EG 7.52020-04-16
Users can lock their notes with a password in Memono version 3.8. Thus, users needs to know a password to read notes. However, these notes are stored in a database without encryption and an attacker can read the password-protected notes wi…
- CVE-2020-11694HIGHCVSS 7.5EG 7.52020-04-10
In JetBrains PyCharm 2019.2.5 and 2019.3 on Windows, Apple Notarization Service credentials were included. This is fixed in 2019.2.6 and 2019.3.3.
- CVE-2020-10267HIGHCVSS 7.5EG 7.52020-04-06
Universal Robots control box CB 3.1 across firmware versions (tested on 1.12.1, 1.12, 1.11 and 1.10) does not encrypt or protect in any way the intellectual property artifacts installed from the UR+ platform of hardware and software compon…
- CVE-2019-15656HIGHCVSS 7.5EG 7.52020-03-19
D-Link DSL-2875AL and DSL-2877AL devices through 1.00.05 are prone to information disclosure via a simple crafted request to index.asp on the web management server because of username_v and password_v variables.
- CVE-2019-10682HIGHCVSS 7.5EG 7.52020-03-18
django-nopassword before 5.0.0 stores cleartext secrets in the database.
- CVE-2020-10532HIGHCVSS 7.5EG 7.52020-03-12
The AD Helper component in WatchGuard Fireware before 5.8.5.10317 allows remote attackers to discover cleartext passwords via the /domains/list URI.
- CVE-2019-9104HIGHCVSS 7.5EG 7.52020-03-11
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. The application's configuration file contains parameters that repre…
- CVE-2019-18238HIGHCVSS 7.5EG 7.52020-02-26
In Moxa ioLogik 2500 series firmware, Version 3.0 or lower, and IOxpress configuration utility, Version 2.3.0 or lower, sensitive information is stored in configuration files without encryption, which may allow an attacker to access an adm…
- CVE-2020-3935HIGHCVSS 7.5EG 7.52020-02-11
TAIWAN SECOM CO., LTD., a Door Access Control and Personnel Attendance Management system, stores users’ information by cleartext in the cookie, which divulges password to attackers.
- CVE-2013-2680HIGHCVSS 7.5EG 7.52020-02-05
Cisco Linksys E4200 1.0.05 Build 7 devices store passwords in cleartext allowing remote attackers to obtain sensitive information.
- CVE-2020-7213HIGHCVSS 7.5EG 7.52020-01-21
Parallels 13 uses cleartext HTTP as part of the update process, allowing man-in-the-middle attacks. Users of out-of-date versions are presented with a pop-up window for a parallels_updates.xml file on the http://update.parallels.com web si…
- CVE-2011-5247HIGHCVSS 7.5EG 7.52020-01-08
Snare for Linux before 1.7.0 has password disclosure because the rendered page contains the field RemotePassword.
- CVE-2019-19314HIGHCVSS 7.5EG 7.52020-01-05
GitLab EE 8.4 through 12.5, 12.4.3, and 12.3.6 stored several tokens in plaintext.
- CVE-2008-7272HIGHCVSS 7.5EG 7.52019-11-08
FireGPG before 0.6 handle user’s passphrase and decrypted cleartext insecurely by writing pre-encrypted cleartext and the user's passphrase to disk which may result in the compromise of secure communication or a users’s private key.
- CVE-2019-4314HIGHCVSS 7.5EG 7.52019-10-29
IBM Security Guardium Big Data Intelligence (SonarG) 4.0 stores sensitive information in cleartext within a resource that might be accessible to another control sphere. IBM X-Force ID: 1610141.
- CVE-2019-3636HIGHCVSS 7.5EG 7.52019-10-28
A File Masquerade vulnerability in McAfee Total Protection (MTP) version 16.0.R21 and earlier in Windows client allowed an attacker to read the plaintext list of AV-Scan exclusion files from the Windows registry, and to possibly replace ex…
- CVE-2019-15023HIGHCVSS 7.5EG 7.52019-10-09
A security vulnerability exists in Zingbox Inspector versions 1.294 and earlier, that results in passwords for 3rd party integrations being stored in cleartext in device configuration.
- CVE-2019-15947HIGHCVSS 7.5EG 7.52019-09-05
In Bitcoin Core 0.18.0, bitcoin-qt stores wallet.dat data unencrypted in memory. Upon a crash, it may dump a core file. If a user were to mishandle a core file, an attacker can reconstruct the user's wallet.dat file, including their privat…
Map vulnerabilities like CWE-312 to your infrastructure
EchelonGraph correlates every CVE — across CWE-312 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →