CWE-256

High likelihood

Plaintext Storage of a Password

Parent: CWE-522 - Insufficiently Protected Credentials

The product stores a password in plaintext within resources such as memory or files.

215 vulnerabilities with CWE-256
CVE-2020-6961 CRITICAL
ApexPro Telemetry Server <4.2 - Info Disclosure
CVSS 10.0
CVE-2019-19105 MEDIUM
ABB Telephone Gateway TG/S <3.2 - Info Disclosure
CVSS 6.2
CVE-2019-0072 MEDIUM
Juniper Networks SBR <8.4.1R13, <8.5.0R4 - Info Disclosure
CVSS 5.6
CVE-2019-10921 HIGH
Siemens LOGO! 8 BM Firmware < 8.3 - Unauthenticated Password Exposure via Port 10005/tcp
CVSS 7.5
CVE-2019-0032 HIGH
Juniper Networks Service Insight <18.1R1 - Info Disclosure
CVSS 7.8
CVE-2019-6518 HIGH
Moxa IKS-G6824A Firmware < 4.5 and EDS-405A/408A/510A Firmware < 3.8 - Plaintext Password Storage
CVSS 7.5
CVE-2018-25396 HIGH
Heatmiser Wifi Thermostat 1.7 Credential Disclosure via networkSetup.htm
CVSS 7.5
CVE-2018-25130 MEDIUM
Beward Intercom 2.3.1 - Info Disclosure
CVSS 6.2
CVE-2018-8851 CRITICAL
Echelon SmartServer <4.11.007 - Info Disclosure
CVSS 9.8
CVE-2018-7510 CRITICAL
BeaconMedaes TotalAlert Scroll <4107600010.23 - Info Disclosure
CVSS 9.8
CVE-2018-7515 MEDIUM
Omron CX-Supervisor <3.30 - Memory Corruption
CVSS 5.3
CVE-2017-6049 HIGH
Detcon Sitewatch Gateway - Path Traversal
CVSS 7.5
CVE-2017-16714 CRITICAL
Ice Qube Thermal Mgmt Ctr <4.13 - Info Disclosure
CVSS 9.8
CVE-2017-9856 LOW
SMA Solar Technology - Info Disclosure
CVSS 3.4
CVE-2017-7913 CRITICAL
Moxa OnCell - Info Disclosure
CVSS 9.8
Details
Vulnerabilities 215
Exploit Likelihood High