Vulnerabilities > Cleartext Storage of Sensitive Information

DATE CVE VULNERABILITY TITLE RISK
2020-07-10 CVE-2020-15105 Cleartext Storage of Sensitive Information vulnerability in Django Two-Factor Authentication Project Django Two-Factor Authentication
Django Two-Factor Authentication before 1.12, stores the user's password in clear text in the user session (base64-encoded).
3.6
2020-07-01 CVE-2019-4676 Cleartext Storage of Sensitive Information vulnerability in IBM Security Identity Manager Virtual Appliance 7.0.2
IBM Security Identity Manager Virtual Appliance 7.0.2 stores user credentials in plain in clear text which can be read by a local user.
2.1
2020-06-30 CVE-2020-15085 Cleartext Storage of Sensitive Information vulnerability in Mirumee Saleor
In Saleor Storefront before version 2.10.3, request data used to authenticate customers was inadvertently cached in the browser's local storage mechanism, including credentials.
local
low complexity
mirumee CWE-312
2.1
2020-06-29 CVE-2020-12032 Cleartext Storage of Sensitive Information vulnerability in Baxter Em1200 Firmware and Em2400 Firmware
Baxter ExactaMix EM 2400 Versions 1.10, 1.11 and ExactaMix EM1200 Versions 1.1, 1.2 systems store device data with sensitive information in an unencrypted database.
network
low complexity
baxter CWE-312
6.4
2020-06-29 CVE-2019-18254 Cleartext Storage of Sensitive Information vulnerability in Biotronik products
BIOTRONIK CardioMessenger II, The affected products do not encrypt sensitive information while at rest.
local
low complexity
biotronik CWE-312
2.1
2020-06-24 CVE-2020-14017 Cleartext Storage of Sensitive Information vulnerability in Naviwebs Navigate CMS 2.9
An issue was discovered in Navigate CMS 2.9 r1433.
network
low complexity
naviwebs CWE-312
5.0
2020-06-24 CVE-2020-10273 Cleartext Storage of Sensitive Information vulnerability in multiple products
MiR controllers across firmware versions 2.8.1.1 and before do not encrypt or protect in any way the intellectual property artifacts installed in the robots.
5.0
2020-06-17 CVE-2020-13637 Cleartext Storage of Sensitive Information vulnerability in Heinekingmedia Stashcat
An issue was discovered in the stashcat app through 3.9.2 for macOS, Windows, Android, iOS, and possibly other platforms.
network
low complexity
heinekingmedia CWE-312
5.0
2020-06-16 CVE-2019-17655 Cleartext Storage of Sensitive Information vulnerability in Fortinet Fortios
A cleartext storage in a file or on disk (CWE-313) vulnerability in FortiOS SSL VPN 6.2.0 through 6.2.2, 6.0.9 and earlier and FortiProxy 2.0.0, 1.2.9 and earlier may allow an attacker to retrieve a logged-in SSL VPN user's credentials should that attacker be able to read the session file stored on the targeted device's system.
network
low complexity
fortinet CWE-312
5.0
2020-06-16 CVE-2020-7513 Cleartext Storage of Sensitive Information vulnerability in Schneider-Electric Easergy T300 Firmware 1.5.2
A CWE-312: Cleartext Storage of Sensitive Information vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to intercept traffic and read configuration data.
network
low complexity
schneider-electric CWE-312
5.0