CWE-312
856 CVEs • Abstraction: Base
Cleartext Storage of Sensitive Information
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
CVEs (856)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ibm 1Security Identity Manager Virtual Appliance Jun 17, 2026 Jul 1, 2020 N/A· v4 7.8 HIGH· v3 2.1 LOW· v2 IBM Security Identity Manager Virtual Appliance 7.0.2 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 171512. |
In Saleor Storefront before version 2.10.3, request data used to authenticate customers was inadvertently cached in the browser's local storage mechanism, including credentials. A malicious user with direct access to the...Show more |
1Baxter 2Em1200 Firmware Em2400 FirmwareJun 17, 2026 Jun 29, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Baxter ExactaMix EM 2400 Versions 1.10, 1.11 and ExactaMix EM1200 Versions 1.1, 1.2 systems store device data with sensitive information in an unencrypted database. This could allow an attacker with network access to vie...Show more |
1Biotronik 2Cardiomessenger Ii S Gsm Firmware Cardiomessenger Ii S T Line FirmwareJun 17, 2026 Jun 29, 2020 N/A· v4 4.6 MEDIUM· v3 2.1 LOW· v2 BIOTRONIK CardioMessenger II, The affected products do not encrypt sensitive information while at rest. An attacker with physical access to the CardioMessenger can disclose medical measurement data and the serial number...Show more |
2Apache Netapp3Activemq Artemis ArtemisOncommand Workflow AutomationJun 17, 2026 Jun 26, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A flaw was found in ActiveMQ Artemis management API from version 2.7.0 up until 2.12.0, where a user inadvertently stores passwords in plaintext in the Artemis shadow file (etc/artemis-users.properties file) when executi...Show more |
An issue was discovered in Navigate CMS 2.9 r1433. Sessions, as well as associated information such as CSRF tokens, are stored in cleartext files in the directory /private/sessions. An unauthenticated user could use a br...Show more |
4Aliasrobotics Enabled RoboticsMobile Industrial Robotics+1 more10Er Flex Firmware Er Lite FirmwareEr One Firmware+7 moreJun 17, 2026 Jun 24, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 MiR controllers across firmware versions 2.8.1.1 and before do not encrypt or protect in any way the intellectual property artifacts installed in the robots. This flaw allows attackers with access to the robot or the rob...Show more |
An issue was discovered in the stashcat app through 3.9.2 for macOS, Windows, Android, iOS, and possibly other platforms. It stores the client_key, the device_id, and the public key for end-to-end encryption in cleartext...Show more |
A cleartext storage in a file or on disk (CWE-313) vulnerability in FortiOS SSL VPN 6.2.0 through 6.2.2, 6.0.9 and earlier and FortiProxy 2.0.0, 1.2.9 and earlier may allow an attacker to retrieve a logged-in SSL VPN use...Show more |
1Schneider Electric 1Easergy T300 Firmware Jun 17, 2026 Jun 16, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A CWE-312: Cleartext Storage of Sensitive Information vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to intercept traffic and read configuration data. |
1Homey 2Homey Firmware Homey Pro FirmwareJun 17, 2026 Jun 4, 2020 N/A· v4 4.3 MEDIUM· v3 3.3 LOW· v2 An issue was discovered in all Athom Homey and Homey Pro devices up to the current version 4.2.0. An attacker within RF range can obtain a cleartext copy of the network configuration of the device, including the Wi-Fi PS...Show more |
D-Link DIR-865L Ax 1.20B01 Beta devices have Cleartext Storage of Sensitive Information. |
2Johnsoncontrols Tyco2C Cure 9000 Firmware Victor Video Management SystemJun 17, 2026 May 21, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 During installation or upgrade to Software House C•CURE 9000 v2.70 and American Dynamics victor Video Management System v5.2, the credentials of the user used to perform the installation or upgrade are logged in a file....Show more |
2Libreoffice Opensuse2Leap LibreofficeJun 17, 2026 May 18, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 If LibreOffice has an encrypted document open and crashes, that document is auto-saved encrypted. On restart, LibreOffice offers to restore the document and prompts for the password to decrypt it. If the recovery is succ...Show more |
Unnecessary fields in the OpenTrace/BlueTrace protocol in COVIDSafe through v1.0.17 allow a remote attacker to identify a device model by observing cleartext payload data. This allows re-identification of devices, especi...Show more |
The administrative passwords for all versions of Bond JetSelect are stored within an unprotected file on the filesystem, rather than encrypted within the MySQL database. This backup copy of the passwords is made as part...Show more |
1Redhat 1Openshift Container Platform Jun 17, 2026 May 12, 2020 N/A· v4 6.6 MEDIUM· v3 4.6 MEDIUM· v2 A flaw was found in OpenShift Container Platform where OAuth tokens are not encrypted when the encryption of data at rest is enabled. This flaw allows an attacker with access to a backup to obtain OAuth tokens and then u...Show more |
1Blaauwproducts 1Remote Kiln Control Jun 17, 2026 May 7, 2020 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Blaauw Remote Kiln Control through v3.00r4 allows an unauthenticated attacker to access MySQL credentials in cleartext in /engine/db.inc, /lang/nl.bak, or /lang/en.bak. |
1Sonatype 1Nexus Repository Manager Jun 17, 2026 Apr 27, 2020 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.17 and 3.x before 3.22.1. Admin users can retrieve the LDAP server system username/password (as configured in nxrm) in cleartext. |
Jenkins Copr Plugin 0.3 and earlier stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system. |