CWE-312

Cleartext Storage of Sensitive Information

Parent: CWE-311 - Missing Encryption of Sensitive Data

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

804 vulnerabilities with CWE-312
CVE-2020-36887 HIGH
SpinetiX Fusion Digital Signage <3.4.8 - Info Disclosure
CVSS 7.5
CVE-2020-11918 MEDIUM
Siime Eye 14.1.00000001.3.330.0.0.3.14 - Cleartext Storage of Sensitive Information in Backup Files
CVSS 5.4
CVE-2020-15332 CRITICAL
Zyxel CloudCNM SecuManager <3.1.1 - Privilege Escalation
CVSS 9.8
CVE-2020-15325 MEDIUM
Zyxel CloudCNM SecuManager <3.1.1 - Info Disclosure
CVSS 5.3
CVE-2020-14480 MEDIUM
FactoryTalk View - Cleartext Storage of Sensitive Information in RAM
CVSS 5.5
CVE-2020-10053 MEDIUM
SIMATIC RTLS Locating Manager < 2.12 - Cleartext Storage of Sensitive Information in Configuration Files
CVSS 5.5
CVE-2020-15935 MEDIUM
FortiADC <= 5.4.3 and 6.0.0 - Authenticated Cleartext Storage of Sensitive Information in GUI
CVSS 4.3
CVE-2020-19137 HIGH
autumn < 1.0.4 - Unauthenticated Cleartext Storage of Sensitive Information via User API
CVSS 7.5
CVE-2020-36473 LOW
UCWeb UC 12.12.3.1219-12.12.3.1226 - Cleartext Storage of Sensitive Information via HTTP
CVSS 3.7
CVE-2020-18759 HIGH
Dut Computer Control Engineering Co.'s PLC MAC1100 - Info Disclosure
CVSS 7.5
CVE-2020-22741 HIGH
Xuperchain 3.6.0 - Cleartext Storage of Sensitive Information
CVSS 7.5
CVE-2020-4980 MEDIUM
IBM QRadar SIEM 7.3-7.4 - Cleartext Transmission of Sensitive Information
CVSS 6.5
CVE-2020-12731 HIGH
MagicMotion Flamingo 2 - Info Disclosure
CVSS 7.5
CVE-2020-15384 MEDIUM
Brocade SANNav <2.1.1 - Info Disclosure
CVSS 5.3
CVE-2020-29324 HIGH
DLink Router DIR-895L MFC <v1.21b05 - Info Disclosure
CVSS 7.5
CVE-2020-22783 MEDIUM
Etherpad < 1.8.3 - Cleartext Storage of Sensitive Information in Database and Log Files
CVSS 6.5
CVE-2020-11924 MEDIUM
WiZ Colors A60 1.14.0 - Cleartext Storage of Sensitive Information
CVSS 5.5
CVE-2020-11923 MEDIUM
WiZ Colors A60 1.14.0 - Cleartext Storage of Sensitive API Credentials
CVSS 5.5
CVE-2020-4944 MEDIUM
IBM UrbanCode Deploy Cleartext Storage of Sensitive Information
CVSS 5.5
CVE-2020-4884 MEDIUM
IBM UrbanCode Deploy 6.2.7.9, 7.0.5.4, and 7.1.1.1 - Cleartext Storage of Sensitive Information
CVSS 5.5
CVE-2020-35455 HIGH
Taidii Diibear 2.4.0 - Cleartext Storage of Sensitive Information in Shared Preferences and SQLite Database
CVSS 7.8
CVE-2020-35454 MEDIUM
Taidii Diibear 2.4.0 - Cleartext Storage of Sensitive Information in Android Backup
CVSS 6.8
CVE-2020-36248 LOW
owncloud_client < 2.15 - Unauthenticated PIN Lock Bypass via ADB Backup Restore
CVSS 3.9
CVE-2020-4189 MEDIUM
IBM Security Guardium 11.2 - Sensitive Information Exposure via Response Headers
CVSS 4.3
CVE-2020-29001 HIGH
Geeni and Merkury Camera/Doorbell Firmware - Cleartext Storage of Sensitive Credentials in RESTful API
CVSS 7.2
Details
Vulnerabilities 804