← Back
CWE-521

259 CVEs • Abstraction: Base

Weak Password Requirements

The product does not require that users should have strong passwords, which makes it easier for attackers to compromise user accounts.

JSON object

Loading...

CVEs (259)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Ibm
Netapp
2Cognos Analytics
Oncommand Insight
Jun 17, 2026
Dec 3, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM Cognos Analytics 11.1.7 and 11.2.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 196339.
1Hitachienergy
2Fox615 Firmware
Xcm20 Firmware
Jun 17, 2026
Dec 2, 2021
N/A· v4
7.1 HIGH· v3
5.5 MEDIUM· v2
Weak Password Requirements vulnerability in Hitachi Energy FOX61x, XCM20 allows an attacker to gain unauthorized access to the Data Communication Network (DCN) routing configuration. This issue affects: Hitachi Energy FO...Show more
Weak Password Requirements vulnerability in Hitachi Energy FOX61x, XCM20 allows an attacker to gain unauthorized access to the Data Communication Network (DCN) routing configuration. This issue affects: Hitachi Energy FOX61x versions prior to R15A. Hitachi Energy XCM20 versions prior to R15A.Show less
1Airangel
5Hsmx App 1000 Firmware
Hsmx App 100 FirmwareHsmx App 20000 Firmware+2 more
Jun 17, 2026
Nov 10, 2021
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Airangel HSMX Gateway devices through 5.2.04 have Weak SSH Credentials.
1Inhandnetworks
1Ir615 Firmware
Jun 17, 2026
Oct 19, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 does not enforce an efficient password policy. This may allow an attacker with obtained user credentials to enumerate passwords and impersonate other ap...Show more
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 does not enforce an efficient password policy. This may allow an attacker with obtained user credentials to enumerate passwords and impersonate other application users and perform operations on their behalf.Show less
1Tibco
2Ebx
Product And Service Catalog Powered By Tibco Ebx
Jun 17, 2026
Oct 13, 2021
N/A· v4
9.8 CRITICAL· v3
9.3 HIGH· v2
The TIBCO EBX Web Server component of TIBCO Software Inc.'s TIBCO EBX, TIBCO EBX, TIBCO EBX, and TIBCO Product and Service Catalog powered by TIBCO EBX contains a vulnerability that under certain specific conditions allo...Show more
The TIBCO EBX Web Server component of TIBCO Software Inc.'s TIBCO EBX, TIBCO EBX, TIBCO EBX, and TIBCO Product and Service Catalog powered by TIBCO EBX contains a vulnerability that under certain specific conditions allows an attacker to enter a password other than the legitimate password and it will be accepted as valid. Affected releases are TIBCO Software Inc.'s TIBCO EBX: versions 5.8.123 and below, TIBCO EBX: versions 5.9.3, 5.9.4, 5.9.5, 5.9.6, 5.9.7, 5.9.8, 5.9.9, 5.9.10, 5.9.11, 5.9.12, 5.9.13, and 5.9.14, TIBCO EBX: versions 6.0.0 and 6.0.1, and TIBCO Product and Service Catalog powered by TIBCO EBX: version 1.0.0.Show less
1Ecoa
3Ecs Router Controller Ecs Firmware
Riskbuster FirmwareRiskterminator
Jun 17, 2026
Sep 30, 2021
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
ECOA BAS controller uses weak set of default administrative credentials that can be easily guessed in remote password attacks and gain full control of the system.
1Bab Technologie
1Eibport Firmware
Jun 17, 2026
Sep 9, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 allow the user to set a weak password because the strength is shown in configuration tool, but finally not enforced. This is usable and part of an attack chain to gain...Show more
BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 allow the user to set a weak password because the strength is shown in configuration tool, but finally not enforced. This is usable and part of an attack chain to gain SSH root access.Show less
1Bab Technologie
1Eibport Firmware
Jun 17, 2026
Sep 9, 2021
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
BAB TECHNOLOGIE GmbH eibPort V3. Each device has its own unique hard coded and weak root SSH key passphrase known as 'eibPort string'. This is usable and the final part of an attack chain to gain SSH root access.
1Ibm
1Security Guardium
Jun 17, 2026
Aug 11, 2021
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
IBM Security Guardium 11.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 196279.
1Cisco
1Connected Mobile Experiences
Jun 17, 2026
Aug 4, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability in the change password API of Cisco Connected Mobile Experiences (CMX) could allow an authenticated, remote attacker to alter their own password to a value that does not comply with the strong authenticat...Show more
A vulnerability in the change password API of Cisco Connected Mobile Experiences (CMX) could allow an authenticated, remote attacker to alter their own password to a value that does not comply with the strong authentication requirements that are configured on an affected device. This vulnerability exists because a password policy check is incomplete at the time a password is changed at server side using the API. An attacker could exploit this vulnerability by sending a specially crafted API request to the affected device. A successful exploit could allow the attacker to change their own password to a value that does not comply with the configured strong authentication requirements.Show less
1Edgexfoundry
1Edgex Foundry
Jun 17, 2026
Jul 9, 2021
N/A· v4
6.5 MEDIUM· v3
5.8 MEDIUM· v2
EdgeX Foundry is an open source project for building a common open framework for internet-of-things edge computing. A vulnerability exists in the Edinburgh, Fuji, Geneva, and Hanoi versions of the software. When the Edge...Show more
EdgeX Foundry is an open source project for building a common open framework for internet-of-things edge computing. A vulnerability exists in the Edinburgh, Fuji, Geneva, and Hanoi versions of the software. When the EdgeX API gateway is configured for OAuth2 authentication and a proxy user is created, the client_id and client_secret required to obtain an OAuth2 authentication token are set to the username of the proxy user. A remote network attacker can then perform a dictionary-based password attack on the OAuth2 token endpoint of the API gateway to obtain an OAuth2 authentication token and use that token to make authenticated calls to EdgeX microservices from an untrusted network. OAuth2 is the default authentication method in EdgeX Edinburgh release. The default authentication method was changed to JWT in Fuji and later releases. Users should upgrade to the EdgeX Ireland release to obtain the fix. The OAuth2 authentication method is disabled in Ireland release. If unable to upgrade and OAuth2 authentication is required, users should create OAuth2 users directly using the Kong admin API and forgo the use of the `security-proxy-setup` tool to create OAuth2 users.Show less
1Open Emr
1Openemr
Jun 17, 2026
Jun 24, 2021
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
In OpenEMR, versions 5.0.0 to 6.0.0.1 are vulnerable to weak password requirements as it does not enforce a maximum password length limit. If a malicious user is aware of the first 72 characters of the victim user’s pass...Show more
In OpenEMR, versions 5.0.0 to 6.0.0.1 are vulnerable to weak password requirements as it does not enforce a maximum password length limit. If a malicious user is aware of the first 72 characters of the victim user’s password, he can leverage it to an account takeover.Show less
1Minthcm
1Minthcm
Jun 17, 2026
Apr 26, 2021
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
A weak password requirement vulnerability exists in the Create New User function of MintHCM RELEASE 3.0.8, which could lead an attacker to easier password brute-forcing.
1Hametech
1Hame Sd1 Wi Fi Firmware
Jun 17, 2026
Apr 26, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An access control vulnerability in Hame SD1 Wi-Fi firmware <=V.20140224154640 allows an attacker to get system administrator through an open Telnet service.
1Luvion
1Grand Elite 3 Connect Firmware
Jun 17, 2026
Apr 2, 2021
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
An issue was discovered in Luvion Grand Elite 3 Connect through 2020-02-25. Authentication to the device is based on a username and password. The root credentials are the same across all devices of this model.
2Fedoraproject
Nextcloud
2Fedora
Nextcloud Server
Jun 17, 2026
Mar 3, 2021
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
Nextcloud Server prior to 20.0.0 stores passwords in a recoverable format even when external storage is not configured.
1Gigaset
1Dx600a Firmware
Jun 17, 2026
Mar 2, 2021
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
The telnet administrator service running on port 650 on Gigaset DX600A v41.00-175 devices does not implement any lockout or throttling functionality. This situation (together with the weak password policy that forces a 4...Show more
The telnet administrator service running on port 650 on Gigaset DX600A v41.00-175 devices does not implement any lockout or throttling functionality. This situation (together with the weak password policy that forces a 4-digit password) allows remote attackers to easily obtain administrative access via brute-force attacks.Show less
1Moxa
1Nport Iaw5000a I/o Firmware
Jun 17, 2026
Dec 23, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The built-in web service for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower does not require users to have strong passwords.
1Docker
1Registry
Jun 17, 2026
Dec 11, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Versions of the Official registry Docker images through 2.7.0 contain a blank password for the root user. Systems deployed using affected versions of the registry container may allow a remote attacker to achieve root acc...Show more
Versions of the Official registry Docker images through 2.7.0 contain a blank password for the root user. Systems deployed using affected versions of the registry container may allow a remote attacker to achieve root access with a blank password.Show less
1Askey
1Ap5100w Firmware
Jun 17, 2026
Dec 10, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Askey AP5100W_Dual_SIG_1.01.097 and all prior versions use a weak password at the Operating System (rlx-linux) level. This allows an attacker to gain unauthorized access as an admin or root user to the device Operating S...Show more
Askey AP5100W_Dual_SIG_1.01.097 and all prior versions use a weak password at the Operating System (rlx-linux) level. This allows an attacker to gain unauthorized access as an admin or root user to the device Operating System via Telnet or SSH.Show less