Threadlinqs IntelligenceStart free

Weakness · BaseCWE-312

CWE-312: Cleartext Storage of Sensitive Information

KEV-linkedBase

As of 2026-10-10, CWE-312 (Cleartext Storage of Sensitive Information) underlies 4 CVEs tracked by Threadlinqs, 1 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 18 tracked threats.

CVEs
4Mapped to CWE-312
CISA KEV
1Exploited in the wild
Critical
0CVSS v3 critical CVEs
Threats
18Tracked campaigns citing it
Likelihood
—MITRE likelihood of exploit

Last updated:

What is CWE-312?

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

CWE-312 is a base-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: Not Language-Specific; Technology: Cloud Computing; Technology: ICS/OT; Technology: Mobile.

Source: MITRE CWE (CWE-312 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.

Consequences

  • Confidentiality — Read Application Data. An attacker with access to the system could read sensitive information stored in cleartext (i.e., unencrypted). Even if the information is encoded in a way that is not human-readable, certain techniques could determine which encoding is being used, then decode the information.

Source: MITRE CWE, common consequences.

How CWE-312 is exploited in the wild

Threadlinqs maps 4 CVEs to CWE-312, published between 2023-04-19 and 2026-08-05. 1 is listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild. By CVSS v3 severity the set splits into 2 high, 1 medium. The highest EPSS score in the set is 3.4% (CVE-2023-22894), the modelled probability of exploitation in the next 30 days. 18 tracked threats reference CWE-312 directly or through a CVE it covers; the most recent is “Chinese Government-linked Actors Enabled by Integrity Technology Group Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data (CISA AA26-281A)” (2026-10-08). Affected products concentrate in Cisco (1), Microsoft (1), StrongDM (1).

Vulnerabilities (CVEs)

All 4 CVEs mapped to CWE-312, CISA KEV first, then by CVSS score.

Affected vendors

Threat activity

18 tracked threats cite CWE-312:

Mitigations

  • Implementation, System Configuration, Operation: When storing data in the cloud (e.g., S3 buckets, Azure blobs, Google Cloud Storage, etc.), use the provider's controls to encrypt the data at rest. [REF-1297] [REF-1299] [REF-1301]
  • Implementation, System Configuration, Operation: In some systems/environments such as cloud, the use of "double encryption" (at both the software and hardware layer) might be required, and the developer might be solely responsible for both layers, instead of shared responsibility with the administrator of the broader system/environment.

Source: MITRE CWE, potential mitigations.

Detection methods (MITRE CWE)

  • Automated Static Analysis (effectiveness: High): Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)

Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher.