CWE-312

Cleartext Storage of Sensitive Information

Parent: CWE-311 - Missing Encryption of Sensitive Data

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

818 vulnerabilities with CWE-312
CVE-2022-25158 CRITICAL
Mitsubishielectric Fx5uc Firmware - Cleartext Storage
CVSS 9.1
CVE-2022-26148 CRITICAL
Grafana & Zabbix Integration - Credentials Disclosure
CVSS 9.8
CVE-2022-23234 MEDIUM
NetApp SnapCenter < 4.5 - Authenticated Plaintext Credential Exposure
CVSS 5.5
CVE-2022-26778 MEDIUM
Veritas System Recovery <21 - Info Disclosure
CVSS 5.3
CVE-2022-21818 MEDIUM
NVIDIA License System < 1.1 - Cleartext Storage of Sensitive Information
CVSS 5.4
CVE-2022-22789 MEDIUM
Charactell FormStorm - Unauthenticated Account Takeover via Password File Manipulation
CVSS 6.1
CVE-2022-23129 MEDIUM
Iconics Genesis64 < 10.97 - Cleartext Storage
CVSS 5.5
CVE-2022-20660 MEDIUM
Cisco IP Phone Firmware < 14.1(1) - Unauthenticated Cleartext Storage of Sensitive Information
CVSS 4.6
CVE-2021-22509 HIGH
NetIQ Advance Auth <6.3.5.1 - Info Disclosure
CVSS 8.1
CVE-2021-39077 MEDIUM
IBM Security Guardium 10.5-11.4 - Cleartext Transmission of Sensitive Information
CVSS 4.4
CVE-2021-36782 CRITICAL
SUSE Rancher < 2.5.16 - Authenticated Cleartext Storage of Sensitive Information via Kubernetes API
CVSS 9.9
CVE-2021-39009 MEDIUM
IBM Cognos Analytics <11.2.1 - Info Disclosure
CVSS 5.5
CVE-2021-3585 MEDIUM
openstack-tripleo-heat-templates - Info Disclosure
CVSS 5.5
CVE-2021-41639 MEDIUM
MELAG FTP Server 2.2.0.4 - Cleartext Storage of Sensitive Information
CVSS 5.5
CVE-2021-45025 HIGH
ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 - Cleartext Storage of Sensitive Information in Cookie
CVSS 7.5
CVE-2021-39078 MEDIUM
IBM Security Guardium 10.5 - Cleartext Storage of Sensitive Information
CVSS 4.4
CVE-2021-45491 MEDIUM
3CX < 2022-03-17 - Cleartext Storage of Sensitive Information
CVSS 6.5
CVE-2021-43590 MEDIUM
Dell EMC Enterprise Storage Analytics for vRealize Operations <6.2....
CVSS 6.0
CVE-2021-27757 HIGH
Insecure Password Storage - Info Disclosure
CVSS 7.5
CVE-2021-35036 MEDIUM
Zyxel VMG3625-T50B <V5.50(ABTL.0)b2 - Info Disclosure
CVSS 6.5
CVE-2021-3551 HIGH
dogtagpki 10.10.0-10.10.5 - Cleartext Storage of Sensitive Information in Installation Log File
CVSS 7.8
CVE-2021-40363 HIGH
SIMATIC PCS 7, WinCC - Info Disclosure
CVSS 7.8
CVE-2021-42642 HIGH
PrinterLogic Web Stack <= 19.1.1.13 SP9 - Unauthenticated Insecure Direct Object Reference
CVSS 7.5
CVE-2021-31821 MEDIUM
Octopus Tentacle < 6.1.1266 - Cleartext Storage of Sensitive Information in Docker Startup Logs
CVSS 5.5
CVE-2021-45077 HIGH
Netgear Nighthawk R6700 1.0.4.120 - Cleartext Storage of Sensitive Information
CVSS 7.5
Details
Vulnerabilities 818