Kastle Systems firmware prior to May 1, 2024, stored machine credentials in cleartext, which may allow an attacker to ac
Cleartext Storage of Sensitive Information in a Cookie vulnerability in Oceanic Software ValeApp allows Protocol Manipul
Cleartext Storage of Sensitive Information, Exposure of Sensitive Information Through Data Queries vulnerability in Finr
mintplex-labs/anything-llm version latest contains a vulnerability where sensitive information, specifically a password,
Pentaminds CuroVMS v2.0.1 was discovered to contain exposed sensitive information.
An issue in H3C switch h3c-S1526 allows a remote attacker to obtain sensitive information via the S1526.cfg component.
Insufficiently Protected Credentials in the Mail Server Configuration in GoPhish v0.12.1 allows an attacker to access cl
Sentry is an error tracking and performance monitoring platform. Prior to 24.4.1, when authenticating as a superuser to
An issue in the Sensor Settings of AVTECH Room Alert 4E v4.4.0 allows attackers to gain access to SMTP credentials in pl
Certain switch models from PLANET Technology store SNMPv3 users' passwords in plaintext within the configuration files,
Navidrome is an open source web-based music collection server and streamer. Navidrome stores the JWT secret in plaintext
Insufficiently protected credentials in DAV server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrator
The NMAP Importer service may expose data store credentials to authorized users of the Windows Registry.
An issue was discovered in Infinera hiT 7300 5.60.50. Sensitive information inside diagnostic files (exported by the @CT
Since version 5.2.0, when using deferrable mode with the path of a Kubernetes configuration file for authentication, the
A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints the Brocade SANnav password in clear text in supports
SecuSTATION Camera V2.5.5.3116-S50-SMA-B20160811A and lower allows an unauthenticated attacker to download device config
An issue was discovered in Italtel Embrace 1.6.4. The web application inserts cleartext passwords in the HTML source cod
An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive information in the memory of the @C
Cleartext storage of passwords in Infinera TNMS (Transcend Network Management System) Server 19.10.3 allows attackers (w
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems.
A cleartext storage of sensitive information vulnerability in Palo Alto Networks Expedition allows an authenticated atta
A vulnerability in Veeam Backup & Replication allows low-privileged users to leak all saved credentials in plaintext. Th
The Eaton Foreseer software provides the feasibility for the user to configure external servers for multiple purposes su
A vulnerability in the Cisco Nexus Dashboard Fabric Controller (NDFC) software, formerly Cisco Data Center Network Manag
Plaintext vulnerability in the Gallery search module. Impact: Successful exploitation of this vulnerability will affect
In Unify CP IP Phone firmware 1.10.4.3, files are not encrypted and contain sensitive information such as the root passw
A vulnerability in a password management API in Brocade Fabric OS versions before v9.2.1, v9.2.0b, v9.1.1d, and v8.2.3e
User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved
NETGEAR RAX30 Device Configuration Cleartext Storage Information Disclosure Vulnerability. This vulnerability allows net
SnapCenter versions prior to 5.0p1 are susceptible to a vulnerability which could allow an authenticated attacker to di
Oxide before 6 has unencrypted Control Plane datastores.
An issue in Shenzen Tenda Technology CP3V2.0 V11.10.00.2311090948 allows a local attacker to obtain sensitive informatio
A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a could allow an authenticated user to print the Auth, Priv, a
An flaw was found in the OpenStack Platform (RHOSP) director, a toolset for installing and managing a complete RHOSP env
IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 through 1.10.22.0 stores p
IBM QRadar Suite Software 1.10.12.0 through 1.10.23.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores u
In the Linux kernel, the following vulnerability has been resolved: KEYS: trusted: dcp: fix leak of blob encryption key
An issue in Texas Instruments Fusion Digital Power Designer v.7.10.1 allows a local attacker to obtain sensitive informa
The configuration file stores credentials in cleartext. An attacker with local access rights can read or modify the conf
An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. When a backup file is created through the web interfa
A vulnerability has been identified in OPUPI0 AMQP/MQTT (All versions < V5.30). The affected devices stores MQTT client
Linksys Velop Pro 6E 1.0.8 MX6200_1.0.8.215731 and 7 1.0.10.215314 devices send cleartext Wi-Fi passwords over the publi
The conformance validation endpoint is public so everybody can verify the conformance of onboarded services. The respons
A flaw was found in moodle. Some hidden user profile fields are visible in gradebook reports, which could result in user
IBM Security Access Manager Container 10.0.0.0 through 10.0.6.1 temporarily stores sensitive information in files that c
A Cleartext Storage of Sensitive Information vulnerability [CWE-312] in FortiClientWindows 7.4.0 through 7.4.1, 7.2.0 th
An issue in the SMTP Email Settings of AVTECH Room Alert 4E v4.4.0 allows attackers to gain access to credentials in pla
A flaw was found in oVirt. A user with administrator privileges, including users with the ReadOnlyAdmin permission, may
An unauthorized user is able to gain access to sensitive data, including credentials, by physically retrieving the hard
Frequently Asked Questions
What is CWE-312?
CWE-312 (CWE-312) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-312?
There are 978 CVE records associated with CWE-312 in our database. Of these, 40 are critical severity, 260 are high severity, and 445 are medium severity.
How can I protect against CWE-312 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-312 using AI-powered security agents.
Detect CWE-312 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-312 vulnerabilities across your infrastructure.
Get Started