CWE-312— Cleartext Storage of Sensitive Information
796 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-312page 3 of 16
- CVE-2019-17106MEDIUMCVSS 6.5EG 6.52019-10-08
In Centreon Web through 2.8.29, disclosure of external components' passwords allows authenticated attackers to move laterally to external components.
- CVE-2019-17655MEDIUMCVSS 5.3EG 5.32020-06-16
A cleartext storage in a file or on disk (CWE-313) vulnerability in FortiOS SSL VPN 6.2.0 through 6.2.2, 6.0.9 and earlier and FortiProxy 2.0.0, 1.2.9 and earlier may allow an attacker to retrieve a logged-in SSL VPN user's credentials sho…
- CVE-2019-18238HIGHCVSS 7.5EG 7.52020-02-26
In Moxa ioLogik 2500 series firmware, Version 3.0 or lower, and IOxpress configuration utility, Version 2.3.0 or lower, sensitive information is stored in configuration files without encryption, which may allow an attacker to access an adm…
- CVE-2019-18254MEDIUMCVSS 4.6EG 4.62020-06-29
BIOTRONIK CardioMessenger II, The affected products do not encrypt sensitive information while at rest. An attacker with physical access to the CardioMessenger can disclose medical measurement data and the serial number from the implanted …
- CVE-2019-18615MEDIUMCVSS 4.9EG 4.92019-12-19
In CloudVision Portal (CVP) for all releases in the 2018.2 Train, under certain conditions, the application logs user passwords in plain text for certain API calls, potentially leading to user password exposure. This only affects CVP envir…
- CVE-2019-18630HIGHCVSS 7.5EG 7.52021-03-04
On Xerox AltaLink B8045/B8055/B8065/B8075/B8090 and C8030/C8035/C8045/C8055/C8070 multifunction printers with software releases before 101.00x.099.28200, portions of the drive containing executable code were not encrypted thus leaving it o…
- CVE-2019-18868CRITICALCVSS 9.8EG 9.82020-05-07
Blaauw Remote Kiln Control through v3.00r4 allows an unauthenticated attacker to access MySQL credentials in cleartext in /engine/db.inc, /lang/nl.bak, or /lang/en.bak.
- CVE-2019-19228CRITICALCVSS 9.8EG 9.82019-12-04
Fronius Solar Inverter devices before 3.14.1 (HM 1.12.1) allow attackers to bypass authentication because the password for the today account is stored in the /tmp/web_users.conf file.
- CVE-2019-19291MEDIUMCVSS 5.3EG 5.32020-03-10
A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0), SiNVR/SiVMS Video Server (All versions < V5.0.0). The FTP services of the SiVMS/SiNVR Video Server and the Control Center Server (CCS) maintain log…
- CVE-2019-19314HIGHCVSS 7.5EG 7.52020-01-05
GitLab EE 8.4 through 12.5, 12.4.3, and 12.3.6 stored several tokens in plaintext.
- CVE-2019-25279HIGHCVSS 7.5EG 8.22026-01-08
FaceSentry Access Control System 6.4.8 contains a cleartext password storage vulnerability that allows attackers to access unencrypted credentials in the device's SQLite database. Attackers can directly read sensitive login information sto…
- CVE-2019-3606HIGHCVSS 7.7EG 4.12019-03-26
Data Leakage Attacks vulnerability in the web portal component when in an MDR pair in McAfee Network Security Management (NSM) 9.1 < 9.1.7.75 (Update 4) and 9.2 < 9.2.7.31 Update2 allows administrators to view configuration information in …
- CVE-2019-3612MEDIUMCVSS 4.4EG 4.42019-04-10
Information Disclosure vulnerability in McAfee DXL Platform and TIE Server in DXL prior to 5.0.1 HF2 and TIE prior to 2.3.1 HF1 allows Authenticated users to view sensitive information in plain text via the GUI or command line.
- CVE-2019-3636HIGHCVSS 7.5EG 7.52019-10-28
A File Masquerade vulnerability in McAfee Total Protection (MTP) version 16.0.R21 and earlier in Windows client allowed an attacker to read the plaintext list of AV-Scan exclusion files from the Windows registry, and to possibly replace ex…
- CVE-2019-3753MEDIUMCVSS 6.5EG 6.52019-08-20
Dell EMC PowerConnect 8024, 7000, M6348, M6220, M8024 and M8024-K running firmware versions prior to 5.1.15.2 contain a plain-text password storage vulnerability. TACACS\Radius credentials are stored in plain text in the system settings me…
- CVE-2019-3767HIGHCVSS 8.2EG 8.22019-10-14
Dell ImageAssist versions prior to 8.7.15 contain an information disclosure vulnerability. Dell ImageAssist stores some sensitive encrypted information in the images it creates. A privileged user of a system running an operating system tha…
- CVE-2019-3937HIGHCVSS 7.8EG 7.82019-04-30
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 stores usernames, passwords, slideshow passcode, and other configuration options in cleartext in the file /tmp/scfgdndf. A local attacker can use this vulnerability to …
- CVE-2019-4314HIGHCVSS 7.5EG 7.52019-10-29
IBM Security Guardium Big Data Intelligence (SonarG) 4.0 stores sensitive information in cleartext within a resource that might be accessible to another control sphere. IBM X-Force ID: 1610141.
- CVE-2019-4566MEDIUMCVSS 5.5EG 5.52019-09-24
IBM Security Key Lifecycle Manager 3.0 and 3.0.1 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 166627.
- CVE-2019-4676HIGHCVSS 7.8EG 7.82020-07-01
IBM Security Identity Manager Virtual Appliance 7.0.2 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 171512.
- CVE-2019-4687MEDIUMCVSS 5.3EG 5.32021-01-13
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history…
- CVE-2019-4738MEDIUMCVSS 6.5EG 6.52020-12-10
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 and 6.0.0.0 through 6.0.3.1 discloses sensitive information to an authenticated user from the dashboard UI which could be used in further attacks against the system. IBM …
- CVE-2019-5765MEDIUMCVSS 5.5EG 5.52019-02-19
An exposed debugging endpoint in the browser in Google Chrome on Android prior to 72.0.3626.81 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted Intent.
- CVE-2019-5810MEDIUMCVSS 6.5EG 6.52019-06-27
Information leak in autofill in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
- CVE-2019-5848MEDIUMCVSS 6.5EG 6.52019-11-25
Incorrect font handling in autofill in Google Chrome prior to 75.0.3770.142 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
- CVE-2019-6549HIGHCVSS 7.2EG 7.22019-02-12
An attacker could retrieve plain-text credentials stored in a XML file on PR100088 Modbus gateway versions prior to Release R02 (or Software Version 1.1.13166) through FTP.
- CVE-2019-6670MEDIUMCVSS 4.4EG 4.42019-11-27
On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.1-11.6.5, vCMP hypervisors are incorrectly exposing the plaintext unit key for their vCMP guests on the filesystem.
- CVE-2019-8118MEDIUMCVSS 5.3EG 5.32019-11-05
Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 uses weak cryptographic function to store the failed login attempts for customer accounts.
- CVE-2019-9104HIGHCVSS 7.5EG 7.52020-03-11
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. The application's configuration file contains parameters that repre…
- CVE-2019-9823CRITICALCVSS 9.8EG 9.82019-07-03
In several JetBrains IntelliJ IDEA versions, creating remote run configurations of JavaEE application servers leads to saving a cleartext record of the server credentials in the IDE configuration files. The issue has been fixed in the foll…
- CVE-2019-9872HIGHCVSS 8.1EG 8.12019-07-03
In several versions of JetBrains IntelliJ IDEA Ultimate, creating run configurations for cloud application servers leads to saving a cleartext unencrypted record of the server credentials in the IDE configuration files. If the Settings Rep…
- CVE-2019-9873CRITICALCVSS 9.8EG 9.82019-07-03
In several versions of JetBrains IntelliJ IDEA Ultimate, creating Task Servers configurations leads to saving a cleartext unencrypted record of the server credentials in the IDE configuration files. The issue has been fixed in the followin…
- CVE-2020-10053MEDIUMCVSS 5.5EG 5.52021-11-09
A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.12). The affected application writes sensitive data, such as database credentials in configuration files. A local attacker with access to the configura…
- CVE-2020-10267HIGHCVSS 7.5EG 7.52020-04-06
Universal Robots control box CB 3.1 across firmware versions (tested on 1.12.1, 1.12, 1.11 and 1.10) does not encrypt or protect in any way the intellectual property artifacts installed from the UR+ platform of hardware and software compon…
- CVE-2020-10273HIGHCVSS 7.5EG 7.52020-06-24
MiR controllers across firmware versions 2.8.1.1 and before do not encrypt or protect in any way the intellectual property artifacts installed in the robots. This flaw allows attackers with access to the robot or the robot network (while i…
- CVE-2020-10532HIGHCVSS 7.5EG 7.52020-03-12
The AD Helper component in WatchGuard Fireware before 5.8.5.10317 allows remote attackers to discover cleartext passwords via the /domains/list URI.
- CVE-2020-10706MEDIUMCVSS 6.3EG 6.62020-05-12
A flaw was found in OpenShift Container Platform where OAuth tokens are not encrypted when the encryption of data at rest is enabled. This flaw allows an attacker with access to a backup to obtain OAuth tokens and then use them to log into…
- CVE-2020-10727MEDIUMCVSS 5.5EG 5.52020-06-26
A flaw was found in ActiveMQ Artemis management API from version 2.7.0 up until 2.12.0, where a user inadvertently stores passwords in plaintext in the Artemis shadow file (etc/artemis-users.properties file) when executing the `resetUsers`…
- CVE-2020-11415MEDIUMCVSS 4.9EG 4.92020-04-27
An issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.17 and 3.x before 3.22.1. Admin users can retrieve the LDAP server system username/password (as configured in nxrm) in cleartext.
- CVE-2020-11694HIGHCVSS 7.5EG 7.52020-04-10
In JetBrains PyCharm 2019.2.5 and 2019.3 on Windows, Apple Notarization Service credentials were included. This is fixed in 2019.2.6 and 2019.3.3.
- CVE-2020-11821MEDIUMCVSS 5.3EG 5.32020-04-27
In Rukovoditel 2.5.2, users' passwords and usernames are stored in a cookie with URL encoding, base64 encoding, and hashing. Thus, an attacker can easily apply brute force on them.
- CVE-2020-11826HIGHCVSS 7.5EG 7.52020-04-16
Users can lock their notes with a password in Memono version 3.8. Thus, users needs to know a password to read notes. However, these notes are stored in a database without encryption and an attacker can read the password-protected notes wi…
- CVE-2020-11918MEDIUMCVSS 5.4EG 5.42024-11-07
An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. When a backup file is created through the web interface, information on all users, including passwords, can be found in cleartext in the backup file. An attacker capable of…
- CVE-2020-11923MEDIUMCVSS 5.5EG 5.52021-04-02
An issue was discovered in WiZ Colors A60 1.14.0. API credentials are locally logged.
- CVE-2020-11924MEDIUMCVSS 5.5EG 5.52021-04-02
An issue was discovered in WiZ Colors A60 1.14.0. Wi-Fi credentials are stored in cleartext in flash memory, which presents an information-disclosure risk for a discarded or resold device.
- CVE-2020-12032CRITICALCVSS 9.1EG 9.12020-06-29
Baxter ExactaMix EM 2400 Versions 1.10, 1.11 and ExactaMix EM1200 Versions 1.1, 1.2 systems store device data with sensitive information in an unencrypted database. This could allow an attacker with network access to view or modify sensiti…
- CVE-2020-12731HIGHCVSS 7.5EG 7.52021-07-15
The MagicMotion Flamingo 2 application for Android stores data on an sdcard under com.vt.magicmotion/files/Pictures, whence it can be read by other applications.
- CVE-2020-12801MEDIUMCVSS 5.3EG 5.32020-05-18
If LibreOffice has an encrypted document open and crashes, that document is auto-saved encrypted. On restart, LibreOffice offers to restore the document and prompts for the password to decrypt it. If the recovery is successful, and if the …
- CVE-2020-12859MEDIUMCVSS 5.3EG 5.32020-05-18
Unnecessary fields in the OpenTrace/BlueTrace protocol in COVIDSafe through v1.0.17 allow a remote attacker to identify a device model by observing cleartext payload data. This allows re-identification of devices, especially less common ph…
- CVE-2020-13473MEDIUMCVSS 5.5EG 5.52020-12-28
NCH Express Accounts 8.24 and earlier allows local users to discover the cleartext password by reading the configuration file.
Map vulnerabilities like CWE-312 to your infrastructure
EchelonGraph correlates every CVE — across CWE-312 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →