← Back
CWE-312

812 CVEs • Abstraction: Base

Cleartext Storage of Sensitive Information

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

JSON object

Loading...

CVEs (812)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dell
1Wyse Management Suite
Jun 17, 2026
Aug 10, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Dell Wyse Management Suite 3.6.1 and below contains an Plain-text Password Storage Vulnerability in UI. An attacker with low privileges could potentially exploit this vulnerability, leading to the disclosure of certain u...Show more
Dell Wyse Management Suite 3.6.1 and below contains an Plain-text Password Storage Vulnerability in UI. An attacker with low privileges could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account.Show less
1Dell
1Wyse Management Suite
Jun 17, 2026
Aug 10, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Dell Wyse Management Suite 3.6.1 and below contains a Sensitive Data Exposure vulnerability. A low privileged malicious user could potentially exploit this vulnerability in order to obtain credentials. The attacker may b...Show more
Dell Wyse Management Suite 3.6.1 and below contains a Sensitive Data Exposure vulnerability. A low privileged malicious user could potentially exploit this vulnerability in order to obtain credentials. The attacker may be able to use the exposed credentials to access the target device and perform unauthorized actions.Show less
1Landray
1Landray Office Automation
Jun 17, 2026
Aug 2, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Lanling OA Landray Office Automation (OA) internal patch number #133383/#137780 contains an arbitrary file read vulnerability via the component /sys/ui/extend/varkind/custom.jsp.
1Omron
7Cp1w Cif41 Firmware
Sysmac Cj2h FirmwareSysmac Cj2m Firmware+4 more
Jun 17, 2026
Jul 26, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
In Omron CS series, CJ series, and CP series PLCs through 2022-05-18, the password for access to the Web UI is stored in memory area D1449...D1452 and can be read out using the Omron FINS protocol without any further aut...Show more
In Omron CS series, CJ series, and CP series PLCs through 2022-05-18, the password for access to the Web UI is stored in memory area D1449...D1452 and can be read out using the Omron FINS protocol without any further authentication.Show less
1Motorolasolutions
1Mdlc
Jun 17, 2026
Jul 26, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
The Motorola MOSCAD Toolbox software through 2022-05-02 relies on a cleartext password. It utilizes an MDLC driver to communicate with MOSCAD/ACE RTUs for engineering purposes. Access to these communications is protected...Show more
The Motorola MOSCAD Toolbox software through 2022-05-02 relies on a cleartext password. It utilizes an MDLC driver to communicate with MOSCAD/ACE RTUs for engineering purposes. Access to these communications is protected by a password stored in cleartext in the wmdlcdrv.ini driver configuration file. In addition, this password is used for access control to MOSCAD/STS projects protected with the Legacy Password feature. In this case, an insecure CRC of the password is present in the project file: this CRC is validated against the password in the driver configuration file.Show less
1Goldshell
1Goldshell Miner Firmware
Jun 17, 2026
Jul 20, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
The debug interface of Goldshell ASIC Miners v2.2.1 and below was discovered to be exposed publicly on the web interface, allowing attackers to access passwords and other sensitive information in plaintext.
1Chcnav
1P5e Gnss Firmware
Jun 17, 2026
Jul 18, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Browsing the path: http://ip/wifi_ap_pata_get.cmd, will show in the name of the existing access point on the component, and a password in clear text.
1Google
1Android
Jun 17, 2026
Jul 13, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
In multiple functions of StorageManagerService.java and UserManagerService.java, there is a possible way to leave user's directories unencrypted due to a logic error in the code. This could lead to local information disc...Show more
In multiple functions of StorageManagerService.java and UserManagerService.java, there is a possible way to leave user's directories unencrypted due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-224585613Show less
1Microsoft
5Windows 10
Windows 11Windows Server 2016+2 more
Jun 17, 2026
Jul 12, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Windows Credential Guard Domain-joined Public Key Elevation of Privilege Vulnerability
1Hcltechsw
1Hcl Launch
Jun 17, 2026
Jul 6, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
HCL Launch may store certain data for recurring activities in a plain text format.
1Ibm
1Urbancode Deploy
Jun 17, 2026
Jul 1, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
IBM UrbanCode Deploy (UCD) 6.2.7.15, 7.0.5.10, 7.1.2.6, and 7.2.2.1 could disclose sensitive database information to a local user in plain text. IBM X-Force ID: 221008.
1Ibm
1Urbancode Deploy
Jun 17, 2026
Jul 1, 2022
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
IBM UrbanCode Deploy (UCD) 6.2.7.15, 7.0.5.10, 7.1.2.6, and 7.2.2.1 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 22106.
1Ibm
1Spectrum Protect Client
Jun 17, 2026
Jun 30, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
IBM Spectrum Protect Client 8.1.0.0 through 8.1.14.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 225886.
1Melag
1Ftp Server
Jun 17, 2026
Jun 24, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
MELAG FTP Server 2.2.0.4 stores unencrpyted passwords of FTP users in a local configuration file.
1Rocketsoftware
1Ags Zena
Jul 9, 2026
Jun 17, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to Cleartext Storage of Sensitive Information in a Cookie.
1Sicunet
1Access Control
Nov 21, 2024
Jun 11, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A vulnerability was found in SICUNET Access Controller 0.32-05z. It has been declared as problematic. This vulnerability affects unknown code of the component Password Storage. The manipulation leads to weak encryption....Show more
A vulnerability was found in SICUNET Access Controller 0.32-05z. It has been declared as problematic. This vulnerability affects unknown code of the component Password Storage. The manipulation leads to weak encryption. Attacking locally is a requirement.Show less
1Filezilla Project
1Filezilla Client
Jun 17, 2026
Jun 7, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
FileZilla v3.59.0 allows attackers to obtain cleartext passwords of connected SSH or FTP servers via a memory dump.- NOTE: the vendor does not consider this a vulnerability
1Mitre
1Cve Services
Jun 17, 2026
Jun 2, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
CVEProject/cve-services is an open source project used to operate the CVE services API. A conditional in 'data.js' has potential for production secrets to be written to disk. The affected method writes the generated rand...Show more
CVEProject/cve-services is an open source project used to operate the CVE services API. A conditional in 'data.js' has potential for production secrets to be written to disk. The affected method writes the generated randomKey to disk if the environment is not development. If this method were called in production, it is possible that it would write the plaintext key to disk. A patch is not available as of time of publication but is anticipated as a "hot fix" for version 1.1.1 and for the 2.x branch.Show less
1Netapp
1E Series Santricity Os Controller
Jun 17, 2026
Jun 2, 2022
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
E-Series SANtricity OS Controller Software versions 11.40 through 11.70.2 store the LDAP BIND password in plaintext within a file accessible only to privileged users.
1Ibm
1Spectrum Protect
Jun 17, 2026
May 17, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
IBM Spectrum Protect Operations Center 8.1.12 and 8.1.13 could allow a local attacker to obtain sensitive information, caused by plain text user account passwords potentially being stored in the browser's application com...Show more
IBM Spectrum Protect Operations Center 8.1.12 and 8.1.13 could allow a local attacker to obtain sensitive information, caused by plain text user account passwords potentially being stored in the browser's application command history. By accessing browser history, an attacker could exploit this vulnerability to obtain other user accounts' passwords. IBM X-Force ID: 226322.Show less