CWE-312
812 CVEs • Abstraction: Base
Cleartext Storage of Sensitive Information
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
CVEs (812)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In version 6.1.0.19 and prior of Wink Labs's Wink - Smart Home Android app, the OAuth token used by the app to authorize user access is not stored in an encrypted and secure manner. |
1Photo,video Locker Calculator Project 1Photo,video Locker Calculator Nov 21, 2024 Feb 20, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The "Photo,Video Locker-Calculator" application 12.0 for Android has android:allowBackup="true" in AndroidManifest.xml, which allows attackers to obtain sensitive cleartext information via an "adb backup '-f smart.calcul...Show more |
A vulnerability in the Policy and Charging Rules Function (PCRF) of the Cisco Policy Suite (CPS) could allow an unauthenticated, remote attacker to access sensitive data. The attacker could use this information to conduc...Show more |
An Cleartext Storage of Sensitive Information issue was discovered in General Motors (GM) and Shanghai OnStar (SOS) SOS iOS Client 7.1. Successful exploitation of this vulnerability may allow a remote attacker to access...Show more |
Encryption key exposure in firmware in iSmartAlarm CubeOne version 2.2.4.8 and earlier allows attackers to decrypt log files via an exposed key. |
The Files APP 7.1.1.308 and earlier versions in some Huawei mobile phones has a vulnerability of plaintext storage of users' Safe passwords. An attacker with the root privilege of an Android system could forge the Safe t...Show more |
2Debian Wordpress2Debian Linux WordpressMay 13, 2026 Oct 3, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which might make it easier for remote attackers to hijack unactivated user accou...Show more |
1Ibm 1Infosphere Master Data Management Server May 13, 2026 Jul 19, 2017 N/A· v4 7.8 HIGH· v3 2.1 LOW· v2 IBM InfoSphere Master Data Management Server 11.0 - 11.6 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 125463. |
The Milwaukee ONE-KEY Android mobile application stores the master token in plaintext in the apk binary. |
Moxa Secure Router EDR-G903 devices before 3.4.12 allow remote attackers to discover cleartext passwords by reading a configuration file. |
1Siemens 2Ruggedcom Rox Ii Firmware Ruggedcom Rugged Operating SystemMay 6, 2026 Aug 3, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The SSL layer of the HTTPS service in Siemens RuggedCom ROS before 4.2.0 and ROX II does not properly implement CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-or...Show more |
1Dlink 2Dir 300 Dir 300 FirmwareApr 22, 2026 Dec 20, 2011 N/A· v4 5.7 MEDIUM· v3 6.8 MEDIUM· v2 The D-Link DIR-300 router stores cleartext passwords, which allows context-dependent attackers to obtain sensitive information via unspecified vectors. |
SanDisk Cruzer Enterprise USB flash drives use a fixed 256-bit key for obtaining access to the cleartext drive contents, which makes it easier for physically proximate attackers to read or modify data by determining and...Show more |
The Huawei D100 stores the administrator's account name and password in cleartext in a cookie, which allows context-dependent attackers to obtain sensitive information by (1) reading a cookie file, by (2) sniffing the ne...Show more |
1Symantec 1Altiris Deployment Solution Apr 23, 2026 Jun 8, 2009 N/A· v4 7.8 HIGH· v3 4.3 MEDIUM· v2 Symantec Altiris Deployment Solution 6.x before 6.9.355 SP1 stores the Application Identity Account password in memory in cleartext, which allows local users to gain privileges and modify clients of the Deployment Soluti...Show more |
1Klinzmann 1Application Access Server Apr 23, 2026 May 14, 2009 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Application Access Server (A-A-S) 2.0.48 stores (1) passwords and (2) the port keyword in cleartext in aas.ini, which allows local users to obtain sensitive information by reading this file. |
1Apple 2Mac Os X Mac Os X ServerApr 23, 2026 May 13, 2009 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 iChat in Apple Mac OS X 10.5 before 10.5.7 disables SSL for AOL Instant Messenger (AIM) communication in certain circumstances that are inconsistent with the Require SSL setting, which allows remote attackers to obtain s...Show more |
2Fedoraproject Opensc Project2Fedora OpenscApr 23, 2026 May 11, 2009 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 src/tools/pkcs11-tool.c in pkcs11-tool in OpenSC 0.11.7, when used with unspecified third-party PKCS#11 modules, generates RSA keys with incorrect public exponents, which allows attackers to read the cleartext form of me...Show more |
UserView_list.php in PHPRunner 4.2, and possibly earlier, stores passwords in cleartext in the database, which allows attackers to gain privileges. NOTE: this can be leveraged with a separate SQL injection vulnerability...Show more |
SepCity Classified Ads stores the admin password in cleartext in data/classifieds.mdb, which allows context-dependent attackers to obtain sensitive information. |