Vulnerabilities > Cleartext Storage of Sensitive Information

DATE CVE VULNERABILITY TITLE RISK
2021-06-24 CVE-2021-29956 Cleartext Storage of Sensitive Information vulnerability in Mozilla Thunderbird
OpenPGP secret keys that were imported using Thunderbird version 78.8.1 up to version 78.10.1 were stored unencrypted on the user's local disk.
network
low complexity
mozilla CWE-312
4.3
2021-06-15 CVE-2021-28858 Cleartext Storage of Sensitive Information vulnerability in Tp-Link Tl-Wpa4220 Firmware 4.0.2
TP-Link's TL-WPA4220 4.0.2 Build 20180308 Rel.37064 does not use SSL by default.
local
low complexity
tp-link CWE-312
5.5
2021-06-11 CVE-2021-23182 Cleartext Storage of Sensitive Information vulnerability in Gallagher Command Centre
Cleartext Storage of Sensitive Information in Memory vulnerability in Gallagher Command Centre Server allows OSDP reader master keys to be discoverable in server memory dumps.
local
low complexity
gallagher CWE-312
4.4
2021-06-11 CVE-2021-23211 Cleartext Storage of Sensitive Information vulnerability in Gallagher Command Centre
Cleartext Storage of Sensitive Information in Memory vulnerability in Gallagher Command Centre Server allows Cloud end-to-end encryption key to be discoverable in server memory dumps.
local
low complexity
gallagher CWE-312
4.4
2021-06-09 CVE-2021-32942 Cleartext Storage of Sensitive Information vulnerability in Aveva Intouch 2017 and Intouch 2020
The vulnerability could expose cleartext credentials from AVEVA InTouch Runtime 2020 R2 and all prior versions (WindowViewer) if an authorized, privileged user creates a diagnostic memory dump of the process and saves it to a non-protected location.
local
low complexity
aveva CWE-312
5.5
2021-06-09 CVE-2020-15384 Cleartext Storage of Sensitive Information vulnerability in Broadcom Sannav 2.1.0
Brocade SANNav before version 2.1.1 contains an information disclosure vulnerability.
network
low complexity
broadcom CWE-312
5.3
2021-06-04 CVE-2020-29324 Cleartext Storage of Sensitive Information vulnerability in Dlink Dir-895L MFC Firmware 1.21B05
The DLink Router DIR-895L MFC v1.21b05 is vulnerable to credentials disclosure in telnet service through decompilation of firmware, that allows an unauthenticated attacker to gain access to the firmware and to extract sensitive data.
network
low complexity
dlink CWE-312
7.5
2021-06-02 CVE-2021-31855 Cleartext Storage of Sensitive Information vulnerability in KDE Messagelib 5.5.1
KDE Messagelib through 5.17.0 reveals cleartext of encrypted messages in some situations.
network
low complexity
kde CWE-312
6.5
2021-05-28 CVE-2021-21734 Cleartext Storage of Sensitive Information vulnerability in ZTE products
Some PON MDU devices of ZTE stored sensitive information in plaintext, and users with login authority can obtain it by inputing command.
network
low complexity
zte CWE-312
6.5
2021-05-26 CVE-2018-16498 Cleartext Storage of Sensitive Information vulnerability in Versa-Networks Versa Director
In Versa Director, the unencrypted backup files stored on the Versa deployment contain credentials stored within configuration files.
local
low complexity
versa-networks CWE-312
5.5