CWE-312

Cleartext Storage of Sensitive Information

Parent: CWE-311 - Missing Encryption of Sensitive Data

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

804 vulnerabilities with CWE-312
CVE-2021-45025 HIGH
ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 - Cleartext Storage of Sensitive Information in Cookie
CVSS 7.5
CVE-2021-39078 MEDIUM
IBM Security Guardium 10.5 - Cleartext Storage of Sensitive Information
CVSS 4.4
CVE-2021-45491 MEDIUM
3CX < 2022-03-17 - Cleartext Storage of Sensitive Information
CVSS 6.5
CVE-2021-43590 MEDIUM
Dell EMC Enterprise Storage Analytics for vRealize Operations <6.2....
CVSS 6.0
CVE-2021-27757 HIGH
Insecure Password Storage - Info Disclosure
CVSS 7.5
CVE-2021-35036 MEDIUM
Zyxel VMG3625-T50B <V5.50(ABTL.0)b2 - Info Disclosure
CVSS 6.5
CVE-2021-3551 HIGH
dogtagpki 10.10.0-10.10.5 - Cleartext Storage of Sensitive Information in Installation Log File
CVSS 7.8
CVE-2021-40363 HIGH
SIMATIC PCS 7, WinCC - Info Disclosure
CVSS 7.8
CVE-2021-42642 HIGH
PrinterLogic Web Stack <= 19.1.1.13 SP9 - Unauthenticated Insecure Direct Object Reference
CVSS 7.5
CVE-2021-31821 MEDIUM
Octopus Tentacle < 6.1.1266 - Cleartext Storage of Sensitive Information in Docker Startup Logs
CVSS 5.5
CVE-2021-45077 HIGH
Netgear Nighthawk R6700 1.0.4.120 - Cleartext Storage of Sensitive Information
CVSS 7.5
CVE-2021-20171 MEDIUM
Netgear RAX43 1.0.3.96 - Cleartext Storage of Sensitive Information in Configuration File
CVSS 5.5
CVE-2021-20162 MEDIUM
Trendnet TEW-827DRU Firmware 2.08B01 - Cleartext Storage of Sensitive Information in Config Files
CVSS 4.9
CVE-2021-35035 MEDIUM
Zyxel NBG6604 Firmware < 1.00(abir.9)c0 - Authenticated Cleartext Storage of Sensitive Information
CVSS 4.9
CVE-2021-20827 HIGH
IDEC MICROSmart FC6A Firmware < 2.32 - Cleartext Storage of Sensitive Information
CVSS 7.5
CVE-2021-43388 HIGH
Unisys Cargo Mobile App <1.2.29 - Info Disclosure
CVSS 7.5
CVE-2021-42066 MEDIUM
SAP Business One 10.0 - Authenticated Cleartext Storage of Sensitive Database Password
CVSS 4.4
CVE-2021-41090 MEDIUM
Grafana Agent <0.20.1-0.21.2 - Info Disclosure
CVSS 6.5
CVE-2021-34544 MEDIUM
Solar-Log 500 < 2.8.2 - Cleartext Storage of Sensitive Information in Export and Notification Pages
CVSS 6.5
CVE-2021-38949 MEDIUM
IBM MQ 8.0.0.0-8.0.0.13, 9.0.0.0-9.0.0.8, 9.1.0-9.1.4 - Cleartext Storage of Sensitive Information
CVSS 5.5
CVE-2021-37157 HIGH
OpenGamePanel OGP-Agent-Linux < 2021-08-14 - Cleartext Storage of Sensitive Information in Config.pm
CVSS 8.8
CVE-2021-42370 HIGH
XoruX LPAR2RRD and STOR2RRD 7.21-7.29 - Cleartext Storage of Sensitive Information in HTML Password Fields
CVSS 7.5
CVE-2021-25502 HIGH
Property Settings <SMR Nov-2021 Release 1 - Info Disclosure
CVSS 7.9
CVE-2021-38422 HIGH
Delta Electronics DIALink <1.2.4.0 - Info Disclosure
CVSS 7.8
CVE-2021-42763 HIGH
Couchbase Server < 6.6.3 and 7.x < 7.0.2 - Cleartext Storage of Sensitive Information in HTTP Basic Auth Header
CVSS 7.5
Details
Vulnerabilities 804