← Back
CWE-312

856 CVEs • Abstraction: Base

Cleartext Storage of Sensitive Information

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

JSON object

Loading...

CVEs (856)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Pifzer
3Plum A+3 Infusion System Firmware
Plum A+ Infusion System FirmwareSymbiq Infusion System Firmware
Nov 21, 2024
Mar 25, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Wireless keys are stored in plain text on Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and prior. Hospira recommends th...Show more
Wireless keys are stored in plain text on Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and prior. Hospira recommends that customers close Port 20/FTP and Port 23/TELNET on the affected devices. Hospira has also released the Plum 360 Infusion System which is not vulnerable to this issue.Show less
1Envoy
1Passport
Nov 21, 2024
Mar 21, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Envoy Passport for Android and Envoy Passport for iPhone could allow a local attacker to obtain sensitive information, caused by the storing of unencrypted data in logs. An attacker could exploit this vulnerability to ob...Show more
Envoy Passport for Android and Envoy Passport for iPhone could allow a local attacker to obtain sensitive information, caused by the storing of unencrypted data in logs. An attacker could exploit this vulnerability to obtain two API keys, a token and other sensitive information.Show less
1Hidglobal
1Easylobby Solo
Nov 21, 2024
Mar 21, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
EasyLobby Solo could allow a local attacker to obtain sensitive information, caused by the storing of the social security number in plaintext. By visiting the kiosk and viewing the Visitor table of the database, an attac...Show more
EasyLobby Solo could allow a local attacker to obtain sensitive information, caused by the storing of the social security number in plaintext. By visiting the kiosk and viewing the Visitor table of the database, an attacker could exploit this vulnerability to view stored social security numbers.Show less
1Avas!t
1Free Antivirus
Nov 21, 2024
Mar 21, 2019
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
Avast Free Antivirus prior to 19.1.2360 stores user credentials in memory upon login, which allows local users to obtain sensitive information by dumping AvastUI.exe application memory and parsing the data.
4Debian
FedoraprojectGoogle+1 more
6Chrome
Debian LinuxEnterprise Linux Desktop+3 more
Jun 17, 2026
Feb 19, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An exposed debugging endpoint in the browser in Google Chrome on Android prior to 72.0.3626.81 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted Intent.
1Kunbus
1Pr100088 Modbus Gateway Firmware
Jun 17, 2026
Feb 12, 2019
N/A· v4
7.2 HIGH· v3
4.0 MEDIUM· v2
An attacker could retrieve plain-text credentials stored in a XML file on PR100088 Modbus gateway versions prior to Release R02 (or Software Version 1.1.13166) through FTP.
1Redhat
1Ceph
Nov 21, 2024
Jan 28, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in log files via plaintext. Versions up to v13.2.4 are vulnerable.
1Pilz
1Pnozmulti Configurator
Nov 21, 2024
Jan 25, 2019
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
Pilz PNOZmulti Configurator prior to version 10.9 allows an authenticated attacker with local access to the system containing the PNOZmulti Configurator software to view sensitive credential data in clear-text. This sens...Show more
Pilz PNOZmulti Configurator prior to version 10.9 allows an authenticated attacker with local access to the system containing the PNOZmulti Configurator software to view sensitive credential data in clear-text. This sensitive data is applicable to only the PMI m107 diag HMI device. An attacker with access to this sensitive data and physical access to the PMI m107 diag can modify data on the HMI device.Show less
1Medtronic
329901 Encore Programmer Firmware
Carelink 2090 Programmer FirmwareCarelink 9790 Programmer Firmware
May 22, 2025
Dec 14, 2018
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
Medtronic CareLink and Encore Programmers do not encrypt or do not sufficiently encrypt sensitive PII and PHI information while at rest .
1Gitlab
1Gitlab
Nov 21, 2024
Dec 4, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It has Cleartext Storage of Sensitive Information.
1Rapid7
1Komand
Jun 17, 2026
Nov 28, 2018
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
In Rapid7 Komand version 0.41.0 and prior, certain endpoints that are able to list the always encrypted-at-rest connection data could return some configurations of connection data without obscuring sensitive data from th...Show more
In Rapid7 Komand version 0.41.0 and prior, certain endpoints that are able to list the always encrypted-at-rest connection data could return some configurations of connection data without obscuring sensitive data from the API response sent over an encrypted channel. This issue does not affect Rapid7 Komand version 0.42.0 and later versions.Show less
1Primx
1Zonecentral
Nov 21, 2024
Nov 14, 2018
N/A· v4
4.3 MEDIUM· v3
2.1 LOW· v2
PRIMX ZoneCentral before 6.1.2236 on Windows sometimes leaks the plaintext of NTFS files. On non-SSD devices, this is limited to a 5-second window and file sizes less than 600 bytes. The effect on SSD devices may be grea...Show more
PRIMX ZoneCentral before 6.1.2236 on Windows sometimes leaks the plaintext of NTFS files. On non-SSD devices, this is limited to a 5-second window and file sizes less than 600 bytes. The effect on SSD devices may be greater.Show less
1Ibm
1Robotic Process Automation With Automation Anywhere
Nov 21, 2024
Nov 2, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
IBM Robotic Process Automation with Automation Anywhere 11 could store highly sensitive information in the form of unencrypted passwords that would be available to a local user. IBM X-Force ID: 151713.
1Moxa
1Thingspro
Nov 21, 2024
Oct 19, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Sensitive Information Stored in Clear Text in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.
1Lenovo
1Xclarity Administrator
Jun 17, 2026
Jul 30, 2018
N/A· v4
7.5 HIGH· v3
3.5 LOW· v2
In Lenovo xClarity Administrator versions earlier than 2.1.0, an attacker that gains access to the underlying LXCA file system user may be able to retrieve a credential store containing the service processor user names a...Show more
In Lenovo xClarity Administrator versions earlier than 2.1.0, an attacker that gains access to the underlying LXCA file system user may be able to retrieve a credential store containing the service processor user names and passwords for servers previously managed by that LXCA instance, and potentially decrypt those credentials more easily than intended.Show less
2Debian
Fedoraproject
2389 Directory Server
Debian Linux
Nov 21, 2024
Jul 18, 2018
N/A· v4
7.2 HIGH· v3
4.0 MEDIUM· v2
389-ds-base before versions 1.3.8.5, 1.4.0.12 is vulnerable to a Cleartext Storage of Sensitive Information. By default, when the Replica and/or retroChangeLog plugins are enabled, 389-ds-base stores passwords in plainte...Show more
389-ds-base before versions 1.3.8.5, 1.4.0.12 is vulnerable to a Cleartext Storage of Sensitive Information. By default, when the Replica and/or retroChangeLog plugins are enabled, 389-ds-base stores passwords in plaintext format in their respective changelog files. An attacker with sufficiently high privileges, such as root or Directory Manager, can query these files in order to retrieve plaintext passwords.Show less
1Ibm
1Websphere Application Server
Nov 21, 2024
Jul 6, 2018
N/A· v4
6.7 MEDIUM· v3
2.1 LOW· v2
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local attacker to obtain clear text password in a trace file caused by improper handling of some datasource custom properties. IBM X-Force ID: 144346.
2Redhat
Theforeman
2Foreman
Satellite
Nov 21, 2024
Jun 21, 2018
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
A flaw was found in foreman before version 1.15 in the logging of adding and registering images. An attacker with access to the foreman log file would be able to view passwords for provisioned systems in the log file, al...Show more
A flaw was found in foreman before version 1.15 in the logging of adding and registering images. An attacker with access to the foreman log file would be able to view passwords for provisioned systems in the log file, allowing them to access those systems.Show less
1Makemytrip
1Makemytrip
Nov 21, 2024
May 20, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in the MakeMyTrip application 7.2.4 for Android. The databases (locally stored) are not encrypted and have cleartext that might lead to sensitive information disclosure, as demonstrated by data/co...Show more
An issue was discovered in the MakeMyTrip application 7.2.4 for Android. The databases (locally stored) are not encrypted and have cleartext that might lead to sensitive information disclosure, as demonstrated by data/com.makemytrip/databases and data/com.makemytrip/Cache SQLite database files.Show less
1Bitpie
1Bitcoin Wallet
Nov 21, 2024
May 8, 2018
N/A· v4
4.1 MEDIUM· v3
1.9 LOW· v2
The Bitpie application through 3.2.4 for Android and iOS uses cleartext storage for digital currency initial keys, which allows local users to steal currency by leveraging root access to read /com.biepie/shared_prefs/com...Show more
The Bitpie application through 3.2.4 for Android and iOS uses cleartext storage for digital currency initial keys, which allows local users to steal currency by leveraging root access to read /com.biepie/shared_prefs/com.bitpie_preferences.xml (on Android) or a plist file in the app data folder (on iOS).Show less