This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due lack of encryption in storing of usernames and passw
This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to unencrypted storing of WPA/ WPS credentials withi
This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to storing of default username and password credenti
This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to storing of FTP credentials in plaintext within th
This vulnerability exists in TP-Link IoT Smart Hub due to storage of Wi-Fi credentials in plain text within the device f
A vulnerability in the logging component of Cisco Duo Authentication for Windows Logon and RDP could allow an authentica
An information exposure vulnerability in Palo Alto Networks PAN-OS software enables a local system administrator to unin
IBM OpenPages with Watson 9.0 may write sensitive information, under specific configurations, in clear text to the syste
An issue in Annonshop.app DecentralizeJustice/anonymousLocker commit 2b2b4 to ba9fd and DecentralizeJustice/anonBackend
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2, when shared channels are enabled,
Using remote content in OpenPGP encrypted messages can lead to the disclosure of plaintext. This vulnerability affects T
A cleartext storage of sensitive information in memory vulnerability [CWE-316] affecting FortiClient VPN iOS 7.2 all ver
A vulnerability exists in the FOXMAN-UN/UNEM in which sensitive information is stored in cleartext within a resource th
IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 temporarily stores data from different environments that cou
The W3 Total Cache plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including
NewPass before 1.2.0 stores passwords (rather than password hashes) directly, which makes it easier to obtain unauthoriz
An issue was discovered in Teledyne FLIR M300 2.00-19. User account passwords are encrypted locally, and can be decrypte
Combodo iTop is a web based IT Service Management tool. An attacker accessing a backup file or the database can read som
TopQuadrant TopBraid EDG stores external credentials insecurely. An authenticated attacker with file system access can r
A vulnerability classified as problematic was found in Netgear DG834Gv5 1.6.01.34. This vulnerability affects unknown co
Hathway Skyworth Router CM5100-511 v4.1.1.24 was discovered to store sensitive information about USB and Wifi connected
The OpenAI ChatGPT app before 2024-07-05 for macOS opts out of the sandbox, and stores conversations in cleartext in a l
A vulnerability, which was classified as problematic, was found in code-projects Blood Bank Management System 1.0. This
Statamic is a, Laravel + Git powered CMS designed for building websites. In affected versions users registering via the
Nextcloud Server is a self hosted personal cloud system. Under certain conditions the password of a user was stored unen
A problem with the ActiveMQ integration for both Cortex XSOAR and Cortex XSIAM can result in the cleartext exposure of t
This vulnerability exists in Philips lighting devices due to storage of Wi-Fi credentials in plain text within the devic
This vulnerability exists in the Tinxy mobile app due to storage of logged-in user information in plaintext on the devic
This vulnerability exists in the TP-Link Archer C50 due to presence of terminal access on a serial interface without pro
A Cleartext Storage of Sensitive Information vulnerability in SUSE Rancher allows users on managed clusters to gain acce
Connected IO v2.1.0 and prior keeps passwords and credentials in clear-text format, allowing attackers to exfiltrate the
An issue was discovered in TSplus Remote Access through 16.0.2.14. Credentials are stored as cleartext within the HTML s
Atlas Copco Power Focus 6000 web server does not sanitize the login information stored by the authenticated user’s brows
The firmwaredownload command on Brocade Fabric OS v9.2.0 could log the FTP/SFTP/SCP server password in clear text in t
Plaintext storage of a password exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. Because account informatio
CENTUM series provided by Yokogawa Electric Corporation are vulnerable to cleartext storage of sensitive information. If
Plaintext credential usage vulnerability in Sage 200 Spain 2023.38.001 version, the exploitation of which could allow a
Gradle Build Action allows users to execute a Gradle Build in their GitHub Actions workflow. A vulnerability impacts Git
An issue was discovered in WeCube Platform 3.2.2. Cleartext passwords are displayed in the configuration for terminal pl
In DPA 2022.4 and older releases, generated heap memory dumps contain sensitive information in cleartext.
Phicomm K2 v22.6.534.263 was discovered to store the root and admin passwords in plaintext.
Phicomm K2G v22.6.3.20 was discovered to store the root and admin passwords in plaintext.
Sme.UP ERP TOKYO V6R1M220406 was discovered to contain an information disclosure vulnerability via the /debug endpoint.
EnterpriseDB EDB Postgres Advanced Server (EPAS) before 14.6.0 logs unredacted passwords in situations where optional pa
Ribose RNP before 0.16.3 sometimes lets secret keys remain unlocked after use.
The Danfoss AK-EM100 stores login credentials in cleartext.
An access control issue in Makves DCAP v3.0.0.122 allows unauthenticated attackers to obtain cleartext credentials via a
An issue found in ALBIS Co. ALBIS v.13.6.1 allows a remote attacker to gain access to sensitive information via the chan
Multi-Remote Next Generation Connection Manager (mRemoteNG) is free software that enables users to store and manage mult
TeleAdapt RoomCast TA-2400 1.0 through 3.1 suffers from Cleartext Storage of Sensitive Information: RSA private key in U
Frequently Asked Questions
What is CWE-312?
CWE-312 (CWE-312) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-312?
There are 978 CVE records associated with CWE-312 in our database. Of these, 40 are critical severity, 260 are high severity, and 445 are medium severity.
How can I protect against CWE-312 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-312 using AI-powered security agents.
Detect CWE-312 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-312 vulnerabilities across your infrastructure.
Get Started