Cyber Posture

CWE · MITRE source

CWE-312Cleartext Storage of Sensitive Information

Abstraction: Base · CVEs in our corpus: 790

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Last updated: 09 May 2026 03:25 UTC

NIST 800-53 r5 controls that address this weakness (7)AI

Control Title Family Why it addresses this CWE
SC-12Cryptographic Key Establishment and ManagementSCKey-management policy requires protected storage of key material, preventing cleartext storage of sensitive cryptographic keys.
SC-28Protection of Information at RestSCRequiring confidentiality protection for information at rest eliminates cleartext storage of sensitive data on persistent media.
SC-38Operations SecuritySCReduces cleartext storage of sensitive data when OPSEC identifies and mandates protection of key information artifacts.
CM-13Data Action MappingCMData action mapping can detect storage actions that leave sensitive information in cleartext.
CM-6Configuration SettingsCMConfiguration policies can mandate secure storage methods to avoid cleartext storage of sensitive information.
AT-3Role-based TrainingATTraining on secure data handling discourages cleartext storage of sensitive information.
MP-1Policy and ProceduresMPPolicy requires protection measures such as encryption for sensitive data stored on media, preventing cleartext exposure.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2022-261487.29.80.87222022-03-21
CVE-2020-279867.17.50.92572020-10-28
CVE-2021-367826.89.90.79612022-09-07
CVE-2020-57235.19.80.51792020-03-30
CVE-2023-507194.67.50.51122023-12-15
CVE-2011-4723 KEV4.05.70.14052011-12-20
CVE-2025-228963.78.60.33242025-02-13
CVE-2023-240553.65.50.41442023-01-22
CVE-2021-289373.57.50.33832021-03-29
CVE-2018-89472.57.50.16172018-03-25
CVE-2020-245772.57.50.16762021-01-08
CVE-2024-94662.56.50.20122024-10-09
CVE-2019-02852.49.80.07282019-04-10
CVE-2013-26802.47.50.15672020-02-05
CVE-2001-14812.19.80.01702001-12-31
CVE-2008-01742.19.80.02672008-01-29
CVE-2021-315812.17.90.09242021-07-22
CVE-2024-37422.17.50.09422024-04-18
CVE-2017-52492.09.80.00182018-02-22
CVE-2017-52502.09.80.00152018-02-22
CVE-2018-183942.09.80.00152018-10-19
CVE-2018-186412.09.80.00062018-12-04
CVE-2014-54332.09.80.00192019-03-26
CVE-2019-113842.09.80.00162019-04-22
CVE-2019-98232.09.80.00002019-07-03