← Back
CWE-521

259 CVEs • Abstraction: Base

Weak Password Requirements

The product does not require that users should have strong passwords, which makes it easier for attackers to compromise user accounts.

JSON object

Loading...

CVEs (259)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Opto22
1Snap Pac S1 Firmware
Jun 17, 2026
Aug 24, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
There are no requirements for setting a complex password in the built-in web server of the SNAP PAC S1 Firmware version R10.3b, which could allow for a successful brute force attack if users don't set up complex credenti...Show more
There are no requirements for setting a complex password in the built-in web server of the SNAP PAC S1 Firmware version R10.3b, which could allow for a successful brute force attack if users don't set up complex credentials.Show less
1Answer
1Answer
Jun 17, 2026
Aug 3, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Weak Password Requirements in GitHub repository answerdev/answer prior to v1.1.0.
1Piigab
1M Bus 900s Firmware
Jun 17, 2026
Jul 7, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
There are no requirements for setting a complex password for PiiGAB M-Bus, which could contribute to a successful brute force attack if the password is inline with recommended password guidelines.
1Redhat
5Openshift Container Platform
Openshift Container Platform For Arm64Openshift Container Platform For Linuxone+2 more
Jun 17, 2026
Jul 5, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
A compliance problem was found in the Red Hat OpenShift Container Platform. Red Hat discovered that, when FIPS mode was enabled, not all of the cryptographic modules in use were FIPS-validated.
1Fit2cloud
1Cloudexplorer Lite
Jun 17, 2026
Jun 27, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Cloudexplorer-lite is an open source cloud software stack. Weak passwords can be easily guessed and are an easy target for brute force attacks. This can lead to an authentication system failure and compromise system secu...Show more
Cloudexplorer-lite is an open source cloud software stack. Weak passwords can be easily guessed and are an easy target for brute force attacks. This can lead to an authentication system failure and compromise system security. Versions of cloudexplorer-lite prior to 1.2.0 did not enforce strong passwords. This vulnerability has been fixed in version 1.2.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.Show less
1Fit2cloud
1Cloudexplorer Lite
Jun 17, 2026
Jun 27, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Weak Password Requirements in GitHub repository cloudexplorer-dev/cloudexplorer-lite prior to v 1.2.0.
1Mitsubishielectric
4Fx5 Enet/ip Firmware
Rj71eip91 FirmwareSw1dnn Eipct Bd Firmware+1 more
Jun 17, 2026
Jun 2, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Weak Password Requirements vulnerability in FTP function on Mitsubishi Electric Corporation MELSEC iQ-R Series EtherNet/IP module RJ71EIP91 and MELSEC iQ-F Series EtherNet/IP module FX5-ENET/IP allows a remote unauthenti...Show more
Weak Password Requirements vulnerability in FTP function on Mitsubishi Electric Corporation MELSEC iQ-R Series EtherNet/IP module RJ71EIP91 and MELSEC iQ-F Series EtherNet/IP module FX5-ENET/IP allows a remote unauthenticated attacker to access to the module via FTP by dictionary attack or password sniffing.Show less
1Apache
1Inlong
Jun 17, 2026
May 22, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Weak Password Requirements vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.6.0.  When users change their password to a simple password (with any character...Show more
Weak Password Requirements vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.6.0.  When users change their password to a simple password (with any character or symbol), attackers can easily guess the user's password and access the account. Users are advised to upgrade to Apache InLong's 1.7.0 or cherry-pick https://github.com/apache/inlong/pull/7805 https://github.com/apache/inlong/pull/7805 to solve it. Show less
1Seiko Sol
3Skybridge Basic Mb A130 Firmware
Skybridge Mb A200 FirmwareSkyspider Mb R210 Firmware
Jun 17, 2026
May 10, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Use of weak credentials exists in Seiko Solutions SkyBridge and SkySpider series, which may allow a remote unauthenticated attacker to decrypt password for the WebUI of the product. Affected products and versions are as...Show more
Use of weak credentials exists in Seiko Solutions SkyBridge and SkySpider series, which may allow a remote unauthenticated attacker to decrypt password for the WebUI of the product. Affected products and versions are as follows: SkyBridge MB-A200 firmware Ver. 01.00.05 and earlier, SkyBridge BASIC MB-A130 firmware Ver. 1.4.1 and earlier, and SkySpider MB-R210 firmware Ver. 1.01.00 and earlier.Show less
1Seiko Sol
2Skybridge Mb A100 Firmware
Skybridge Mb A110 Firmware
Jun 17, 2026
May 10, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Use of weak credentials exists in SkyBridge MB-A100/110 firmware Ver. 4.2.0 and earlier, which may allow a remote unauthenticated attacker to decrypt password for the WebUI of the product.
1Enterprisedb
1Postgres Advanced Server
Jun 17, 2026
Apr 23, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
EnterpriseDB EDB Postgres Advanced Server (EPAS) before 14.6.0 logs unredacted passwords in situations where optional parameters are used with CREATE/ALTER USER/GROUP/ROLE, and redacting was configured with edb_filter_lo...Show more
EnterpriseDB EDB Postgres Advanced Server (EPAS) before 14.6.0 logs unredacted passwords in situations where optional parameters are used with CREATE/ALTER USER/GROUP/ROLE, and redacting was configured with edb_filter_log.redact_password_commands. The fixed versions are 10.23.33, 11.18.29, 12.13.17, 13.9.13, and 14.6.0.Show less
1Modoboa
1Modoboa
Jun 17, 2026
Apr 18, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Weak Password Requirements in GitHub repository modoboa/modoboa prior to 2.1.0.
1Electra Air
1Central Ac Unit Firmware
Jun 17, 2026
Apr 17, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Electra Central AC unit – The unit opens an AP with an easily calculated password.
1Janeczku
1Calibre Web
Jun 17, 2026
Apr 15, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Weak Password Requirements in GitHub repository janeczku/calibre-web prior to 0.6.20.
1Ibm
1Sterling Order Management
Jun 17, 2026
Apr 7, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
IBM Sterling Order Management 10.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 229698.
1Phpmyfaq
1Phpmyfaq
Jun 17, 2026
Mar 31, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.12.
1Megafeis
1Bofei Dbd+
Jun 17, 2026
Mar 21, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 allows attacker to gain access to sensitive account information via insecure password policy.
1Samourai Wallet Android Project
1Samourai Wallet Android
Jun 17, 2026
Mar 4, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An issue discovered in com.samourai.wallet.PinEntryActivity.java in Streetside Samourai Wallet 0.99.96i allows attackers to view sensitive information and decrypt data via a brute force attack that uses a recovered samou...Show more
An issue discovered in com.samourai.wallet.PinEntryActivity.java in Streetside Samourai Wallet 0.99.96i allows attackers to view sensitive information and decrypt data via a brute force attack that uses a recovered samourai.dat file. The PIN is 5 to 8 digits, which may be insufficient in this situation.Show less
1Phpmyfaq
1Phpmyfaq
Jun 17, 2026
Feb 12, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.11.
1Employee Leaves Management System Project
1Employee Leaves Management System
Jun 17, 2026
Feb 2, 2023
N/A· v4
9.1 CRITICAL· v3
2.6 LOW· v2
A vulnerability was found in PHPGurukul Employee Leaves Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file changepassword.php. The manipulat...Show more
A vulnerability was found in PHPGurukul Employee Leaves Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file changepassword.php. The manipulation of the argument newpassword/confirmpassword leads to weak password requirements. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The identifier VDB-220021 was assigned to this vulnerability.Show less