CWE-922Class

Insecure Storage of Sensitive Information

Incomplete in the CWE catalog · 119 CVEs mapped

119
CVEs mapped
6.0
Median CVSS
What it is

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

Recent examples
7.9cvss
CVE-2026-44629

CVE-2026-44629 - HIGH Severity Vulnerability

Improper access control to the Synergis Softwire installation folder. This vulnerability affects Streamvault all-in-one appliances (SV-100E and SV-300E series) and Synergis Softwire installed on Windows servers.

HIGHno explanation yet
0%
epss
4.6cvss
CVE-2025-59320

CVE-2025-59320 - MEDIUM Severity Vulnerability

CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 stores TPM2.0 secrets in a serialized format within unused disk sectors. An unauthenticated attacker with physical access to the system disk can recover this information and craft an environment to unseal the TPM.

MEDIUMno explanation yet
0%
epss
5.3cvss
CVE-2026-20705

CVE-2026-20705 - MEDIUM Severity Vulnerability

Insecure storage of sensitive information in the Intel(R) TDX module for some Intel(R) platform within Ring 0: Trust Domain may allow information disclosure. System software adversary with a privileged user combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (none) and availability (none) impacts.

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-922
Abstraction
Class
Structure
Simple
Status
Incomplete
References (1)