CWE-312
812 CVEs • Abstraction: Base
Cleartext Storage of Sensitive Information
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
CVEs (812)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Unisoon 1Ultralog Express Firmware Jun 17, 2026 Mar 27, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 UltraLog Express device management software stores user’s information in cleartext. Any user can obtain accounts information through a specific page. |
1Netsas 1Enigma Network Management Solution Jun 17, 2026 Mar 19, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 NETSAS Enigma NMS 65.0.0 and prior does not encrypt sensitive data stored within the SQL database. It is possible for an attacker to expose unencrypted sensitive data. |
1Django Nopassword Project 1Django Nopassword Jun 17, 2026 Mar 18, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 django-nopassword before 5.0.0 stores cleartext secrets in the database. |
1Rockwellautomation 4Micrologix 1100 Firmware Micrologix 1400 A FirmwareMicrologix 1400 B Firmware+1 moreJun 17, 2026 Mar 16, 2020 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix 500 Software v12.001 and prior, If Simple Mail Transfer Protocol (SMTP...Show more |
1Watchguard 1Ad Helper Firmware Jun 17, 2026 Mar 12, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The AD Helper component in WatchGuard Fireware before 5.8.5.10317 allows remote attackers to discover cleartext passwords via the /domains/list URI. |
1Moxa 6Mb3170 Firmware Mb3180 FirmwareMb3270 Firmware+3 moreJun 17, 2026 Mar 11, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. The application's configuration file contains pa...Show more |
1Siemens 2Sinvr 3 Central Control Server Sinvr 3 Video ServerJun 17, 2026 Mar 10, 2020 N/A· v4 6.5 MEDIUM· v3 3.5 LOW· v2 A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0), SiNVR/SiVMS Video Server (All versions < V5.0.0). The FTP services of the SiVMS/SiNVR Video Server and the Control Center Server...Show more |
1Jenkins 1Zephyr For Jira Test Management Jun 17, 2026 Mar 9, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Jenkins Zephyr for JIRA Test Management Plugin 1.5 and earlier stores its credentials in plain text in a global configuration file on the Jenkins master file system. |
1Redhat 2Decision Manager Process Automation ManagerJun 17, 2026 Mar 5, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability was found in business-central, as shipped in rhdm-7.5.1 and rhpam-7.5.1, where encoded passwords are stored in errai_security_context. The encoding used for storing the passwords is Base64, not an encrypt...Show more |
2Canonical Mozilla2Thunderbird Ubuntu LinuxJun 17, 2026 Mar 2, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 If a user saved passwords before Thunderbird 60 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is because the older stored password file was not deleted when the da...Show more |
1Moxa 20Iologik 2512 Hspa T Firmware Iologik 2512 Hspa FirmwareIologik 2512 T Firmware+17 moreJun 17, 2026 Feb 26, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Moxa ioLogik 2500 series firmware, Version 3.0 or lower, and IOxpress configuration utility, Version 2.3.0 or lower, sensitive information is stored in configuration files without encryption, which may allow an attack...Show more |
IBL Online Weather before 4.3.5a allows attackers to obtain sensitive information by reading the IWEBSERVICE_JSONRPC_COOKIE cookie. |
1Secom 2Dr.id Access Control Dr.id Attendance SystemJun 17, 2026 Feb 11, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 TAIWAN SECOM CO., LTD., a Door Access Control and Personnel Attendance Management system, stores users’ information by cleartext in the cookie, which divulges password to attackers. |
Cisco Linksys E4200 1.0.05 Build 7 devices store passwords in cleartext allowing remote attackers to obtain sensitive information. |
IBM StoredIQ 7.6.0.17 through 7.6.0.20 could disclose sensitive information to a local user due to data in certain directories not being encrypted when it contained symbolic links. IBM X-Force ID: 175133. |
Parallels 13 uses cleartext HTTP as part of the update process, allowing man-in-the-middle attacks. Users of out-of-date versions are presented with a pop-up window for a parallels_updates.xml file on the http://update.p...Show more |
1Simplemachines 1Simple Machines Forum Nov 21, 2024 Jan 15, 2020 N/A· v4 7.2 HIGH· v3 3.5 LOW· v2 There is a file disclosure vulnerability in SMF (Simple Machines Forum) affecting versions through v2.0.3. On some configurations a SMF deployment is shared by several "co-admins" that are not trusted beyond the SMF depl...Show more |
3Fedoraproject HpRedhat4389 Directory Server Directory ServerHp Ux Directory Server+1 moreNov 21, 2024 Jan 9, 2020 N/A· v4 3.3 LOW· v3 1.9 LOW· v2 389 Directory Server before 1.2.7.1 (aka Red Hat Directory Server 8.2) and HP-UX Directory Server before B.08.10.03, when audit logging is enabled, logs the Directory Manager password (nsslapd-rootpw) in cleartext when c...Show more |
Snare for Linux before 1.7.0 has password disclosure because the rendered page contains the field RemotePassword. |
GitLab EE 8.4 through 12.5, 12.4.3, and 12.3.6 stored several tokens in plaintext. |