CWE:
 

Topic
Date
Author
High
Brickcom 100ap Series Authentication Bypass / CSRF
13.06.2013
Eliezer Varade Lopez


CVEMAP Search Results

CVE
Details
Description
2020-11-17
Medium
CVE-2020-26551

Vendor: Aviatrix
Software: Controller
 

 
An issue was discovered in Aviatrix Controller before R5.3.1151. Encrypted key values are stored in a readable file.

 
2020-10-21
Low
CVE-2020-6648

Vendor: Fortinet
Software: Fortios
 

 
A cleartext storage of sensitive information vulnerability in FortiOS command line interface in versions 6.2.4 and below may allow an authenticated attacker to obtain sensitive information such as users passwords by connecting to FortiGate CLI and executing the "diag sys ha checksum show" command.

 
2020-09-22
Low
CVE-2020-4619

Vendor: IBM
Software: Data risk ma...
 

 
IBM Data Risk Manager (iDNA) 2.0.6 stores user credentials in plain in clear text which can be read by an authenticated user. IBM X-Force ID: 184976.

 
2020-09-16
Low
CVE-2020-2274

Vendor: Jenkins
Software: Elastest
 

 
Jenkins ElasTest Plugin 1.2.1 and earlier stores its server password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

 
2020-09-09
Medium
CVE-2020-15784

Vendor: Siemens
Software: Spectrum power 4
 

 
A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP8). Insecure storage of sensitive information in the configuration files could allow the retrieval of user names.

 
2020-08-26
Low
CVE-2020-15485

Updating...
 

 
An issue was discovered on Nescomed Multipara Monitor M1000 devices. The onboard Flash memory stores data in cleartext, without integrity protection against tampering.

 
Medium
CVE-2020-15484

Updating...
 

 
An issue was discovered on Nescomed Multipara Monitor M1000 devices. The internal storage of the underlying Linux system stores data in cleartext, without integrity protection against tampering.

 
2020-08-11
Medium
CVE-2020-17495

Vendor: Django-celery-results project
Software: Django-celer...
 

 
django-celery-results through 1.2.1 stores task results in the database. Among the data it stores are the variables passed into the tasks. The variables may contain sensitive cleartext information that does not belong unencrypted in the database.

 
2020-07-23
Low
CVE-2020-7517

Vendor: Schneider-electric
Software: Easergy builder
 

 
A CWE-312: Cleartext Storage of Sensitive Information vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could allow an attacker to read user credentials.

 
Low
CVE-2020-7516

Vendor: Schneider-electric
Software: Easergy builder
 

 
A CWE-316: Cleartext Storage of Sensitive Information in Memory vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could allow an attacker access to login credentials.

 

 


Copyright 2020, cxsecurity.com

 

Back to Top