Vulnerabilities > Insecure Storage of Sensitive Information

DATE CVE VULNERABILITY TITLE RISK
2024-02-06 CVE-2024-22773 Insecure Storage of Sensitive Information vulnerability in Intelbras Action RF 1200 Firmware 1.2.2
Intelbras Action RF 1200 routers 1.2.2 and earlier and Action RG 1200 routers 2.1.7 and earlier expose the Password in Cookie resulting in Login Bypass.
network
high complexity
intelbras CWE-922
8.1
2024-01-03 CVE-2023-5879 Insecure Storage of Sensitive Information vulnerability in Geniecompany Aladdin Connect 5.65
Users’ product account authentication data was stored in clear text in The Genie Company Aladdin Connect Mobile Application Version 5.65 Build 2075 (and below) on Android Devices.
low complexity
geniecompany CWE-922
6.8
2023-12-14 CVE-2023-45184 Insecure Storage of Sensitive Information vulnerability in IBM I Access Client Solutions
IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 could allow an attacker to obtain a decryption key due to improper authority checks.
network
low complexity
ibm CWE-922
7.5
2023-11-22 CVE-2023-6253 Insecure Storage of Sensitive Information vulnerability in Fortra Digital Guardian Agent
A saved encryption key in the Uninstaller in Digital Guardian's Agent before version 7.9.4 allows a local attacker to retrieve the uninstall key and remove the software by extracting the uninstaller key from the memory of the uninstaller file.
local
low complexity
fortra CWE-922
6.0
2023-09-18 CVE-2023-41965 Insecure Storage of Sensitive Information vulnerability in Socomec Modulys GP Firmware 01.12.10
Sending some requests in the web application of the vulnerable device allows information to be obtained due to the lack of security in the authentication process.
network
low complexity
socomec CWE-922
7.5
2023-09-12 CVE-2023-37879 Insecure Storage of Sensitive Information vulnerability in Wftpserver Wing FTP Server
Insecure storage of sensitive information in Wing FTP Server (User Web Client) allows information elicitation.This issue affects Wing FTP Server: <= 7.2.0.
network
low complexity
wftpserver CWE-922
7.5
2023-09-05 CVE-2023-29261 Insecure Storage of Sensitive Information vulnerability in IBM Sterling External Authentication Server 6.0.3.0/6.1.0
IBM Sterling Secure Proxy 6.0.3 and 6.1.0 could allow a local user with specific information about the system to obtain privileged information due to inadequate memory clearing during operations.
local
low complexity
ibm CWE-922
5.5
2023-08-02 CVE-2022-46484 Insecure Storage of Sensitive Information vulnerability in Ngsurvey 2.4.28
Information disclosure in password protected surveys in Data Illusion Survey Software Solutions NGSurvey v2.4.28 and below allows attackers to view the password to access and arbitrarily submit surveys.
network
low complexity
ngsurvey CWE-922
7.5
2023-07-17 CVE-2023-28864 Insecure Storage of Sensitive Information vulnerability in Progress Chef Infra Server
Progress Chef Infra Server before 15.7 allows a local attacker to exploit a /var/opt/opscode/local-mode-cache/backup world-readable temporary backup path to access sensitive information, resulting in the disclosure of all indexed node data, because OpenSearch credentials are exposed.
local
low complexity
progress CWE-922
5.5
2023-06-05 CVE-2023-3064 Insecure Storage of Sensitive Information vulnerability in Mobatime Amxgt 100 1.3.20
Anonymous user may get the list of existing users managed by the application, that could ease further attacks (see CVE-2023-3065 and 3066)This issue affects Mobatime mobile application AMXGT100 through 1.3.20.
network
low complexity
mobatime CWE-922
5.3