CWE-312

Cleartext Storage of Sensitive Information

Parent: CWE-311 - Missing Encryption of Sensitive Data

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

804 vulnerabilities with CWE-312
CVE-2024-20448 MEDIUM
Cisco Nexus Dashboard Fabric Controller - Info Disclosure
CVSS 6.3
CVE-2024-25661 HIGH
Nokia Transcend Network Management System - Cleartext Storage
CVSS 7.7
CVE-2024-25658 MEDIUM
Nokia Transcend Network Management System - Cleartext Storage
CVSS 6.5
CVE-2024-28807 MEDIUM
Nokia hiT 7300 Firmware 5.60.50 - Cleartext Storage of Sensitive Information in Memory
CVSS 6.5
CVE-2024-28810 MEDIUM
Infinera hiT 7300 5.60.50 - Cleartext Storage of Sensitive Information in Diagnostic Files
CVSS 6.6
CVE-2024-28809 HIGH
Infinera hiT 7300 5.60.50 - Cleartext Storage of Sensitive Password in Firmware Update Packages
CVSS 8.8
CVE-2024-8459 HIGH
PLANET Technology - Info Disclosure
CVSS 7.2
CVE-2024-45744 LOW
TopQuadrant TopBraid EDG <7.1.3 - Info Disclosure
CVSS 3.0
CVE-2024-8644 HIGH
Oceanic Software ValeApp <2.0.0 - JSON Hijacking
CVSS 7.5
CVE-2024-7259 MEDIUM
oVirt Engine < 4.5.7 - Authenticated Cleartext Storage of Sensitive Information in Provider Passwords
CVSS 4.9
CVE-2024-6785 MEDIUM
Configuration File - Info Disclosure
CVSS 5.5
CVE-2024-9040 LOW
Blood Bank Management System 1.0 - Info Disclosure
CVSS 2.3
CVE-2024-45862 HIGH
Kastle Access Control System Firmware < 2024-05-01 - Cleartext Storage of Sensitive Information
CVSS 7.5
CVE-2024-31415 MEDIUM
Eaton Foreseer Electrical Power Monitoring System < 7.8.600 - Insufficiently Protected Credentials
CVSS 6.3
CVE-2024-41629 MEDIUM
Texas Instruments Fusion Digital Power Designer 7.10.1 - Sensitive Information Exposure via Plaintext Credential Storage
CVSS 5.5
CVE-2024-40457 CRITICAL
No-IP Dynamic Update Client 3.x - Cleartext Storage of Sensitive Information
CVSS 9.1
CVE-2024-8689 MEDIUM
Cortex XSOAR/XSIAM - Info Disclosure
CVE-2024-35282 MEDIUM
FortiClient VPN iOS <7.2, <7.0, <6.4, <6.2, <6.0 - Info Disclosure
CVSS 4.2
CVE-2024-45175 HIGH
za-internet C-MOR Video Surveillance 5.2401 - Info Disclosure
CVSS 8.8
CVE-2024-45004 MEDIUM
Linux Kernel 6.10-6.10.7 - Cleartext Storage of Sensitive Information in Trusted Key Blob Export
CVSS 5.5
CVE-2024-41716 HIGH
WindLDR < 9.2.0 and WindO/I-NV4 < 3.1.0 - Cleartext Storage of Sensitive Information
CVSS 8.1
CVE-2024-45391 HIGH
Tina CMS < 1.6.2 - Search Token Exposure via Lock File
CVSS 7.5
CVE-2024-6921 HIGH
NACPremium < 2024-08-01 - Cleartext Storage of Sensitive Information
CVSS 7.5
CVE-2024-32939 MEDIUM
Mattermost 9.5.0-9.5.7 9.8.0-9.8.2 9.9.0-9.9.1 9.10.0 - Improper Access Control in Shared Channels
CVSS 4.3
CVE-2024-25024 MEDIUM
IBM QRadar Suite Software <1.10.23.0 & Cloud Pak for Security <1.10...
CVSS 5.5
Details
Vulnerabilities 804