← Back
CWE-312

856 CVEs • Abstraction: Base

Cleartext Storage of Sensitive Information

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

JSON object

Loading...

CVEs (856)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Philips
1Dosewise
Nov 21, 2024
Apr 24, 2018
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
The Philips DoseWise Portal web-based application versions 1.1.7.333 and 2.1.1.3069 stores login credentials in clear text within backend system files. CVSS v3 base score: 6.5, CVSS vector string: AV:N/AC:L/PR:L/UI:N/S:U...Show more
The Philips DoseWise Portal web-based application versions 1.1.7.333 and 2.1.1.3069 stores login credentials in clear text within backend system files. CVSS v3 base score: 6.5, CVSS vector string: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N.Show less
1Phoenixcontact
1Ilc Plcs Firmware
Nov 21, 2024
Apr 5, 2018
N/A· v4
7.3 HIGH· v3
5.0 MEDIUM· v2
Webvisit in Phoenix Contact ILC PLCs offers a password macro to protect HMI pages on the PLC against casual or coincidental opening of HMI pages by the user. The password macro can be configured in a way that the passwor...Show more
Webvisit in Phoenix Contact ILC PLCs offers a password macro to protect HMI pages on the PLC against casual or coincidental opening of HMI pages by the user. The password macro can be configured in a way that the password is stored and transferred in clear text.Show less
1Laravel Log Viewer Project
1Laravel Log Viewer
Jun 17, 2026
Mar 25, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
rap2hpoutre Laravel Log Viewer before v0.13.0 relies on Base64 encoding for l, dl, and del requests, which makes it easier for remote attackers to bypass intended access restrictions, as demonstrated by reading arbitrary...Show more
rap2hpoutre Laravel Log Viewer before v0.13.0 relies on Base64 encoding for l, dl, and del requests, which makes it easier for remote attackers to bypass intended access restrictions, as demonstrated by reading arbitrary files via a dl request.Show less
1Insteon
1Insteon For Hub
Nov 21, 2024
Feb 22, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
In version 1.9.7 and prior of Insteon's Insteon for Hub Android app, the OAuth token used by the app to authorize user access is not stored in an encrypted and secure manner.
1Wink
1Wink
Nov 21, 2024
Feb 22, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
In version 6.1.0.19 and prior of Wink Labs's Wink - Smart Home Android app, the OAuth token used by the app to authorize user access is not stored in an encrypted and secure manner.
1Photo,video Locker Calculator Project
1Photo,video Locker Calculator
Nov 21, 2024
Feb 20, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The "Photo,Video Locker-Calculator" application 12.0 for Android has android:allowBackup="true" in AndroidManifest.xml, which allows attackers to obtain sensitive cleartext information via an "adb backup '-f smart.calcul...Show more
The "Photo,Video Locker-Calculator" application 12.0 for Android has android:allowBackup="true" in AndroidManifest.xml, which allows attackers to obtain sensitive cleartext information via an "adb backup '-f smart.calculator.gallerylock'" command.Show less
1Cisco
1Policy Suite
Nov 21, 2024
Jan 18, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability in the Policy and Charging Rules Function (PCRF) of the Cisco Policy Suite (CPS) could allow an unauthenticated, remote attacker to access sensitive data. The attacker could use this information to conduc...Show more
A vulnerability in the Policy and Charging Rules Function (PCRF) of the Cisco Policy Suite (CPS) could allow an unauthenticated, remote attacker to access sensitive data. The attacker could use this information to conduct additional reconnaissance attacks. The attacker would also have to have access to the internal VLAN where CPS is deployed. The vulnerability is due to incorrect permissions of certain system files and not sufficiently protecting sensitive data that is at rest. An attacker could exploit the vulnerability by using certain tools available on the internal network interface to request and view system files. An exploit could allow the attacker to find out sensitive information about the application. Cisco Bug IDs: CSCvf77666.Show less
1Gm
1Shanghai Onstar
Nov 21, 2024
Jan 9, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An Cleartext Storage of Sensitive Information issue was discovered in General Motors (GM) and Shanghai OnStar (SOS) SOS iOS Client 7.1. Successful exploitation of this vulnerability may allow a remote attacker to access...Show more
An Cleartext Storage of Sensitive Information issue was discovered in General Motors (GM) and Shanghai OnStar (SOS) SOS iOS Client 7.1. Successful exploitation of this vulnerability may allow a remote attacker to access an encryption key that is stored in cleartext in memory.Show less
1Ismartalarm
1Cubeone Firmware
May 13, 2026
Dec 1, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Encryption key exposure in firmware in iSmartAlarm CubeOne version 2.2.4.8 and earlier allows attackers to decrypt log files via an exposed key.
1Huawei
1Files
May 13, 2026
Nov 22, 2017
N/A· v4
6.7 MEDIUM· v3
2.1 LOW· v2
The Files APP 7.1.1.308 and earlier versions in some Huawei mobile phones has a vulnerability of plaintext storage of users' Safe passwords. An attacker with the root privilege of an Android system could forge the Safe t...Show more
The Files APP 7.1.1.308 and earlier versions in some Huawei mobile phones has a vulnerability of plaintext storage of users' Safe passwords. An attacker with the root privilege of an Android system could forge the Safe to read users' plaintext Safe passwords, leading to information leak.Show less
2Debian
Wordpress
2Debian Linux
Wordpress
May 13, 2026
Oct 3, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which might make it easier for remote attackers to hijack unactivated user accou...Show more
WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which might make it easier for remote attackers to hijack unactivated user accounts by leveraging database read access (such as access gained through an unspecified SQL injection vulnerability).Show less
1Ibm
1Infosphere Master Data Management Server
May 13, 2026
Jul 19, 2017
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
IBM InfoSphere Master Data Management Server 11.0 - 11.6 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 125463.
1Milwaukeetool
1One Key
May 13, 2026
Jun 20, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Milwaukee ONE-KEY Android mobile application stores the master token in plaintext in the apk binary.
1Moxa
1Edr G903 Firmware
May 6, 2026
May 31, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Moxa Secure Router EDR-G903 devices before 3.4.12 allow remote attackers to discover cleartext passwords by reading a configuration file.
1Siemens
2Ruggedcom Rox Ii Firmware
Ruggedcom Rugged Operating System
May 6, 2026
Aug 3, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The SSL layer of the HTTPS service in Siemens RuggedCom ROS before 4.2.0 and ROX II does not properly implement CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-or...Show more
The SSL layer of the HTTPS service in Siemens RuggedCom ROS before 4.2.0 and ROX II does not properly implement CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, a different vulnerability than CVE-2014-3566.Show less
1Dlink
2Dir 300
Dir 300 Firmware
Apr 22, 2026
Dec 20, 2011
N/A· v4
5.7 MEDIUM· v3
6.8 MEDIUM· v2
The D-Link DIR-300 router stores cleartext passwords, which allows context-dependent attackers to obtain sensitive information via unspecified vectors.
1Sandisk
1Cruzer Enterprise Firmware
Apr 23, 2026
Jan 7, 2010
N/A· v4
N/A· v3
4.6 MEDIUM· v2
SanDisk Cruzer Enterprise USB flash drives use a fixed 256-bit key for obtaining access to the cleartext drive contents, which makes it easier for physically proximate attackers to read or modify data by determining and...Show more
SanDisk Cruzer Enterprise USB flash drives use a fixed 256-bit key for obtaining access to the cleartext drive contents, which makes it easier for physically proximate attackers to read or modify data by determining and providing this key.Show less
1Huawei
1D100 Firmware
Apr 23, 2026
Jul 1, 2009
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Huawei D100 stores the administrator's account name and password in cleartext in a cookie, which allows context-dependent attackers to obtain sensitive information by (1) reading a cookie file, by (2) sniffing the ne...Show more
The Huawei D100 stores the administrator's account name and password in cleartext in a cookie, which allows context-dependent attackers to obtain sensitive information by (1) reading a cookie file, by (2) sniffing the network for HTTP headers, and possibly by using unspecified other vectors.Show less
1Symantec
1Altiris Deployment Solution
Apr 23, 2026
Jun 8, 2009
N/A· v4
7.8 HIGH· v3
4.3 MEDIUM· v2
Symantec Altiris Deployment Solution 6.x before 6.9.355 SP1 stores the Application Identity Account password in memory in cleartext, which allows local users to gain privileges and modify clients of the Deployment Soluti...Show more
Symantec Altiris Deployment Solution 6.x before 6.9.355 SP1 stores the Application Identity Account password in memory in cleartext, which allows local users to gain privileges and modify clients of the Deployment Solution Server.Show less
1Klinzmann
1Application Access Server
Apr 23, 2026
May 14, 2009
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Application Access Server (A-A-S) 2.0.48 stores (1) passwords and (2) the port keyword in cleartext in aas.ini, which allows local users to obtain sensitive information by reading this file.