CWE-312

Cleartext Storage of Sensitive Information

Parent: CWE-311 - Missing Encryption of Sensitive Data

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

805 vulnerabilities with CWE-312
CVE-2015-3952 HIGH
Hospira Plum A+ <13.4, Plum A+3 <13.6, Symbiq <3.13 - Plaintext Wireless Key Exposure
CVSS 7.5
CVE-2015-5537
Siemens RuggedCom ROS <4.2.0 - Info Disclosure
CVE-2014-5433 CRITICAL
Baxter SIGMA Spectrum Infusion System 6.05 - Unauthenticated Cleartext Storage of Wireless Credentials
CVSS 9.8
CVE-2013-2680 HIGH
Cisco Linksys E4200 <1.0.05 - Info Disclosure
CVSS 7.5
CVE-2011-5247 HIGH
Snare for Linux < 1.7.0 - Cleartext Storage of Sensitive Information in RemotePassword Field
CVSS 7.5
CVE-2011-2916 MEDIUM
qtnx 0.9 - Cleartext Storage of Sensitive SSH Keys in Configuration File
CVSS 5.5
CVE-2011-4723 MEDIUM KEV
D-Link DIR-300 - Cleartext Storage of Sensitive Information
CVSS 5.7
CVE-2010-3282 LOW
389 Directory Server <1.2.7.1 - Info Disclosure
CVSS 3.3
CVE-2010-0225
SanDisk Cruzer Enterprise Firmware - Cleartext Storage of Sensitive Information via Fixed Encryption Key
CVE-2009-5068 HIGH
Simple Machines Forum <= 2.0.3 - Unauthenticated Arbitrary File Read via settings.php
CVSS 7.2
CVE-2009-2272 HIGH
Huawei D100 Firmware - Cleartext Storage of Sensitive Information in Cookie
CVSS 7.5
CVE-2009-1466 MEDIUM
Application Access Server 2.0.48 - Cleartext Storage of Sensitive Information in aas.ini
CVSS 5.5
CVE-2009-0152 HIGH
Apple Mac OS X 10.5 <10.5.7 - Info Disclosure
CVSS 7.5
CVE-2009-1603 HIGH
OpenSC 0.11.7 - Cleartext Storage of Sensitive Information via RSA Key Generation
CVSS 7.5
CVE-2009-0964 HIGH
PHPRunner < 4.2 - Cleartext Storage of Sensitive Information in Database
CVSS 7.5
CVE-2008-7272 HIGH
FireGPG < 0.6 - Cleartext Storage of Sensitive Information
CVSS 7.5
CVE-2008-6828 HIGH
Symantec Altiris Deployment Solution < 6.9.355 - Cleartext Storage of Sensitive Information
CVSS 7.8
CVE-2008-6157 HIGH
SepCity Classified Ads - Cleartext Storage of Sensitive Information in data/classifieds.mdb
CVSS 7.5
CVE-2008-1567 MEDIUM
phpMyAdmin <2.11.5.1 - Info Disclosure
CVSS 5.5
CVE-2008-0174 CRITICAL
GE Proficy Real-Time Information Portal < 2.6 - Cleartext Storage of Sensitive Information via HTTP Basic Authentication
CVSS 9.8
CVE-2007-5778 HIGH
Mobile Spy - Cleartext Storage of Sensitive Information in Registry and HTTP Traffic
CVSS 7.5
CVE-2005-2209 MEDIUM
Capturix ScanShare 1.06 build 50 - Cleartext Storage of Sensitive Information in Configuration File
CVSS 5.5
CVE-2005-2160 HIGH
Ipswitch IMail - Cleartext Storage of Sensitive Information in Cookie
CVSS 7.5
CVE-2005-1828 HIGH
D-Link DSL-504T Firmware - Cleartext Storage of Sensitive Information in Router Configuration File
CVSS 7.5
CVE-2004-2397 HIGH
Blue Coat Security Gateway OS <3.2.1 - Info Disclosure
CVSS 7.5
Details
Vulnerabilities 805