CWE-312— Cleartext Storage of Sensitive Information
796 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-312page 1 of 16
- CVE-2001-1536HIGHCVSS 7.5EG 7.52001-12-31
Autogalaxy stores usernames and passwords in cleartext in cookies, which makes it easier for remote attackers to obtain authentication information and gain unauthorized access via sniffing or a cross-site scripting attack.
- CVE-2001-1537HIGHCVSS 7.5EG 7.52001-12-31
The default "basic" security setting' in config.php for TWIG webmail 2.7.4 and earlier stores cleartext usernames and passwords in cookies, which could allow attackers to obtain authentication information and gain privileges.
- CVE-2002-1696MEDIUMCVSS 5.5EG 5.52002-12-31
Microsoft Outlook plug-in PGP version 7.0, 7.0.3, and 7.0.4 silently saves a decrypted copy of a message to hard disk when "Automatically decrypt/verify when opening messages" option is checked, "Always use Secure Viewer when decrypting" o…
- CVE-2002-1800HIGHCVSS 7.5EG 7.52002-12-31
phpRank 1.8 stores the administrative password in plaintext on the server and in the "ap" cookie, which allows remote attackers to retrieve the administrative password.
- CVE-2004-2397HIGHCVSS 7.5EG 7.52004-12-31
The web-based Management Console in Blue Coat Security Gateway OS 3.0 through 3.1.3.13 and 3.2.1, when importing a private key, stores the key and its passphrase in plaintext in a log file, which allows attackers to steal digital certifica…
- CVE-2005-1828HIGHCVSS 7.5EG 7.52005-05-26
D-Link DSL-504T stores usernames and passwords in cleartext in the router configuration file, which allows remote attackers to obtain sensitive information.
- CVE-2005-2160HIGHCVSS 7.5EG 7.52005-07-06
IMail stores usernames and passwords in cleartext in a cookie, which allows remote attackers to obtain sensitive information.
- CVE-2005-2209MEDIUMCVSS 5.5EG 5.52005-07-11
Capturix ScanShare 1.06 build 50 stores sensitive information such as the password in cleartext in capturixss_cfg.ini, which is readable by local users.
- CVE-2007-5778HIGHCVSS 7.5EG 7.52007-11-01
Mobile Spy (1) stores login credentials in cleartext under the RetinaxStudios registry key, and (2) sends login credentials and log data over a cleartext HTTP connection, which allows attackers to obtain sensitive information by reading th…
- CVE-2008-1567MEDIUMCVSS 5.5EG 5.52008-03-31
phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish secret key, in cleartext in a Session file under /tmp, which allows local users to obtain sensitive information.
- CVE-2008-6157HIGHCVSS 7.5EG 7.52009-02-17
SepCity Classified Ads stores the admin password in cleartext in data/classifieds.mdb, which allows context-dependent attackers to obtain sensitive information.
- CVE-2008-6828HIGHCVSS 7.8EG 7.82009-06-08
Symantec Altiris Deployment Solution 6.x before 6.9.355 SP1 stores the Application Identity Account password in memory in cleartext, which allows local users to gain privileges and modify clients of the Deployment Solution Server.
- CVE-2008-7272HIGHCVSS 7.5EG 7.52019-11-08
FireGPG before 0.6 handle user’s passphrase and decrypted cleartext insecurely by writing pre-encrypted cleartext and the user's passphrase to disk which may result in the compromise of secure communication or a users’s private key.
- CVE-2009-0152HIGHCVSS 7.5EG 7.52009-05-13
iChat in Apple Mac OS X 10.5 before 10.5.7 disables SSL for AOL Instant Messenger (AIM) communication in certain circumstances that are inconsistent with the Require SSL setting, which allows remote attackers to obtain sensitive informatio…
- CVE-2009-0964HIGHCVSS 7.5EG 7.52009-03-19
UserView_list.php in PHPRunner 4.2, and possibly earlier, stores passwords in cleartext in the database, which allows attackers to gain privileges. NOTE: this can be leveraged with a separate SQL injection vulnerability to obtain password…
- CVE-2009-1466MEDIUMCVSS 5.5EG 5.52009-05-14
Application Access Server (A-A-S) 2.0.48 stores (1) passwords and (2) the port keyword in cleartext in aas.ini, which allows local users to obtain sensitive information by reading this file.
- CVE-2009-1603HIGHCVSS 7.5EG 7.52009-05-11
src/tools/pkcs11-tool.c in pkcs11-tool in OpenSC 0.11.7, when used with unspecified third-party PKCS#11 modules, generates RSA keys with incorrect public exponents, which allows attackers to read the cleartext form of messages that were in…
- CVE-2009-2272HIGHCVSS 7.5EG 7.52009-07-01
The Huawei D100 stores the administrator's account name and password in cleartext in a cookie, which allows context-dependent attackers to obtain sensitive information by (1) reading a cookie file, by (2) sniffing the network for HTTP head…
- CVE-2009-5068HIGHCVSS 7.2EG 7.22020-01-15
There is a file disclosure vulnerability in SMF (Simple Machines Forum) affecting versions through v2.0.3. On some configurations a SMF deployment is shared by several "co-admins" that are not trusted beyond the SMF deployment. This vulner…
- CVE-2010-0225NONECVSS 0.0EG 0.02010-01-07
SanDisk Cruzer Enterprise USB flash drives use a fixed 256-bit key for obtaining access to the cleartext drive contents, which makes it easier for physically proximate attackers to read or modify data by determining and providing this key.
- CVE-2010-3282LOWCVSS 3.3EG 3.32020-01-09
389 Directory Server before 1.2.7.1 (aka Red Hat Directory Server 8.2) and HP-UX Directory Server before B.08.10.03, when audit logging is enabled, logs the Directory Manager password (nsslapd-rootpw) in cleartext when changing cn=config:n…
- CVE-2011-2916MEDIUMCVSS 5.5EG 5.52019-11-15
qtnx 0.9 stores non-custom SSH keys in a world-readable configuration file. If a user has a world-readable or world-executable home directory, another local system user could obtain the private key used to connect to remote NX sessions.
- CVE-2011-4723MEDIUMCVSS 5.7EG 9.0⚠ KEV2011-12-20
The D-Link DIR-300 router stores cleartext passwords, which allows context-dependent attackers to obtain sensitive information via unspecified vectors.
- CVE-2011-5247HIGHCVSS 7.5EG 7.52020-01-08
Snare for Linux before 1.7.0 has password disclosure because the rendered page contains the field RemotePassword.
- CVE-2013-2680HIGHCVSS 7.5EG 7.52020-02-05
Cisco Linksys E4200 1.0.05 Build 7 devices store passwords in cleartext allowing remote attackers to obtain sensitive information.
- CVE-2013-5676NONECVSS 0.0EG 0.02013-12-13
The Jenkins Plugin for SonarQube 3.7 and earlier allows remote authenticated users to obtain sensitive information (cleartext passwords) by reading the value in the sonar.sonarPassword parameter from jenkins/configure.
- CVE-2014-5433CRITICALCVSS 9.8EG 9.82019-03-26
An unauthenticated remote attacker may be able to execute commands to view wireless account credentials that are stored in cleartext on Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) …
- CVE-2015-1012HIGHCVSS 7.5EG 7.52019-03-25
Wireless keys are stored in plain text on version 5 of the Hospira LifeCare PCA Infusion System. According to Hospira, version 3 of the LifeCare PCA Infusion System is not indicated for wireless use, is not shipped with wireless capabiliti…
- CVE-2015-1931MEDIUMCVSS 5.5EG 5.52022-09-29
IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR1 FP10, 7 R1 before SR3 FP10, 7 before SR9 FP10, 6 R1 before SR8 FP7, 6 before SR16 FP7, and 5.0 before SR16 FP13 stores plaintext information in memory dumps, whi…
- CVE-2015-3952HIGHCVSS 7.5EG 7.52019-03-25
Wireless keys are stored in plain text on Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and prior. Hospira recommends that customers close …
- CVE-2015-8314HIGHCVSS 7.5EG 7.52023-12-12
The Devise gem before 3.5.4 for Ruby mishandles Remember Me cookies for sessions, which may allow an adversary to obtain unauthorized persistent application access.
- CVE-2016-3192MEDIUMCVSS 6.5EG 6.52019-11-26
Cloudera Manager 5.x before 5.7.1 places Sensitive Data in cleartext Readable Files.
- CVE-2016-8366HIGHCVSS 7.3EG 7.32018-04-05
Webvisit in Phoenix Contact ILC PLCs offers a password macro to protect HMI pages on the PLC against casual or coincidental opening of HMI pages by the user. The password macro can be configured in a way that the password is stored and tra…
- CVE-2017-16835HIGHCVSS 7.5EG 7.52018-02-20
The "Photo,Video Locker-Calculator" application 12.0 for Android has android:allowBackup="true" in AndroidManifest.xml, which allows attackers to obtain sensitive cleartext information via an "adb backup '-f smart.calculator.gallerylock'" …
- CVE-2017-20040MEDIUMCVSS 5.9EG 5.52022-06-11
A vulnerability was found in SICUNET Access Controller 0.32-05z. It has been declared as problematic. This vulnerability affects unknown code of the component Password Storage. The manipulation leads to weak encryption. Attacking locally i…
- CVE-2017-2672MEDIUMCVSS 6.5EG 8.82018-06-21
A flaw was found in foreman before version 1.15 in the logging of adding and registering images. An attacker with access to the foreman log file would be able to view passwords for provisioned systems in the log file, allowing them to acce…
- CVE-2017-5249CRITICALCVSS 9.8EG 9.82018-02-22
In version 6.1.0.19 and prior of Wink Labs's Wink - Smart Home Android app, the OAuth token used by the app to authorize user access is not stored in an encrypted and secure manner.
- CVE-2017-5250CRITICALCVSS 9.8EG 9.82018-02-22
In version 1.9.7 and prior of Insteon's Insteon for Hub Android app, the OAuth token used by the app to authorize user access is not stored in an encrypted and secure manner.
- CVE-2017-9654HIGHCVSS 8.8EG 8.82018-04-24
The Philips DoseWise Portal web-based application versions 1.1.7.333 and 2.1.1.3069 stores login credentials in clear text within backend system files. CVSS v3 base score: 6.5, CVSS vector string: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N.
- CVE-2017-9663HIGHCVSS 7.5EG 7.52018-01-09
An Cleartext Storage of Sensitive Information issue was discovered in General Motors (GM) and Shanghai OnStar (SOS) SOS iOS Client 7.1. Successful exploitation of this vulnerability may allow a remote attacker to access an encryption key t…
- CVE-2018-0089HIGHCVSS 7.5EG 7.52018-01-18
A vulnerability in the Policy and Charging Rules Function (PCRF) of the Cisco Policy Suite (CPS) could allow an unauthenticated, remote attacker to access sensitive data. The attacker could use this information to conduct additional reconn…
- CVE-2018-10812MEDIUMCVSS 4.1EG 4.12018-05-08
The Bitpie application through 3.2.4 for Android and iOS uses cleartext storage for digital currency initial keys, which allows local users to steal currency by leveraging root access to read /com.biepie/shared_prefs/com.bitpie_preferences…
- CVE-2018-10871LOWCVSS 3.8EG 7.22018-07-18
389-ds-base before versions 1.3.8.5, 1.4.0.12 is vulnerable to a Cleartext Storage of Sensitive Information. By default, when the Replica and/or retroChangeLog plugins are enabled, 389-ds-base stores passwords in plaintext format in their …
- CVE-2018-11242MEDIUMCVSS 6.5EG 6.52018-05-20
An issue was discovered in the MakeMyTrip application 7.2.4 for Android. The databases (locally stored) are not encrypted and have cleartext that might lead to sensitive information disclosure, as demonstrated by data/com.makemytrip/databa…
- CVE-2018-12572HIGHCVSS 7.8EG 7.82019-03-21
Avast Free Antivirus prior to 19.1.2360 stores user credentials in memory upon login, which allows local users to obtain sensitive information by dumping AvastUI.exe application memory and parsing the data.
- CVE-2018-1621MEDIUMCVSS 4.4EG 6.72018-07-06
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local attacker to obtain clear text password in a trace file caused by improper handling of some datasource custom properties. IBM X-Force ID: 144346.
- CVE-2018-16498MEDIUMCVSS 5.5EG 5.52021-05-26
In Versa Director, the unencrypted backup files stored on the Versa deployment contain credentials stored within configuration files. These credentials are for various application components such as SNMP, and SSL and Trust keystores.
- CVE-2018-16889MEDIUMCVSS 5.5EG 7.52019-01-28
Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in log files via plaintext. Versions up to v13.2.4 are vulnerable.
- CVE-2018-17489LOWCVSS 2.9EG 5.52019-03-21
EasyLobby Solo could allow a local attacker to obtain sensitive information, caused by the storing of the social security number in plaintext. By visiting the kiosk and viewing the Visitor table of the database, an attacker could exploit t…
- CVE-2018-17499LOWCVSS 2.9EG 5.52019-03-21
Envoy Passport for Android and Envoy Passport for iPhone could allow a local attacker to obtain sensitive information, caused by the storing of unencrypted data in logs. An attacker could exploit this vulnerability to obtain two API keys, …
Map vulnerabilities like CWE-312 to your infrastructure
EchelonGraph correlates every CVE — across CWE-312 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →