← Back
CWE-521

259 CVEs • Abstraction: Base

Weak Password Requirements

The product does not require that users should have strong passwords, which makes it easier for attackers to compromise user accounts.

JSON object

Loading...

CVEs (259)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Quickheal
1Total Security
Jun 17, 2026
Nov 30, 2020
N/A· v4
6.7 MEDIUM· v3
2.1 LOW· v2
Quick Heal Total Security before 19.0 allows attackers with local admin rights to obtain access to files in the File Vault via a brute-force attack on the password.
1Quickheal
1Total Security
Jun 17, 2026
Nov 30, 2020
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
Quick Heal Total Security before 19.0 allows attackers with local admin rights to modify sensitive anti virus settings via a brute-attack on the settings password.
1Pulsesecure
1Pulse Secure Desktop
Jun 17, 2026
Oct 27, 2020
N/A· v4
3.3 LOW· v3
1.9 LOW· v2
Pulse Secure Desktop Client 9.0Rx before 9.0R5 and 9.1Rx before 9.1R4 on Windows reveals users' passwords if Save Settings is enabled.
1Jfrog
1Artifactory
Jun 17, 2026
Oct 12, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Jfrog Artifactory uses default passwords (such as "password") for administrative accounts and does not require users to change them. This may allow unauthorized network-based attackers to completely compromise of Jfrog A...Show more
Jfrog Artifactory uses default passwords (such as "password") for administrative accounts and does not require users to change them. This may allow unauthorized network-based attackers to completely compromise of Jfrog Artifactory. This issue affects Jfrog Artifactory versions prior to 6.17.0.Show less
1Broadcom
1Fabric Operating System
Jun 17, 2026
Sep 25, 2020
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Supportlink CLI in Brocade Fabric OS Versions v8.2.1 through v8.2.1d, and 8.2.2 versions before v8.2.2c does not obfuscate the password field, which could expose users’ credentials of the remote server. An authenticated...Show more
Supportlink CLI in Brocade Fabric OS Versions v8.2.1 through v8.2.1d, and 8.2.2 versions before v8.2.2c does not obfuscate the password field, which could expose users’ credentials of the remote server. An authenticated user could obtain the exposed password credentials to gain access to the remote host.Show less
1Cpanel
1Cpanel
Jun 17, 2026
Sep 25, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In cPanel before 88.0.3, an insecure site password is used for Mailman on a templated VM (SEC-551).
1Ibm
2Guardium Data Encryption
Guardium For Cloud Key Management
Jun 17, 2026
Aug 26, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 171929.
1Textpattern
1Textpattern
Nov 21, 2024
Aug 14, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In Textpattern 4.5.7, the password-reset feature does not securely tether a hash to a user account.
2Fedoraproject
Redhat
2Etcd
Fedora
Jun 17, 2026
Aug 6, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
etcd before versions 3.3.23 and 3.4.10 does not perform any password length validation, which allows for very short passwords, such as those with a length of one. This may allow an attacker to guess or brute-force users'...Show more
etcd before versions 3.3.23 and 3.4.10 does not perform any password length validation, which allows for very short passwords, such as those with a length of one. This may allow an attacker to guess or brute-force users' passwords with little computational effort.Show less
1Ibm
1Security Key Lifecycle Manager
Jun 17, 2026
Jul 29, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM Tivoli Key Lifecycle Manager does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 184181.
1Schneider Electric
1Easergy Builder
Jun 17, 2026
Jul 23, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A CWE-521: Weak Password Requirements vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could allow an attacker to compromise a user account.
1Avertx
2Hd438 Firmware
Hd838 Firmware
Jun 17, 2026
Jul 23, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in AvertX Auto focus Night Vision HD Indoor/Outdoor IP Dome Camera HD838 and Night Vision HD Indoor/Outdoor Mini IP Bullet Camera HD438. They do not require users to change the default password fo...Show more
An issue was discovered in AvertX Auto focus Night Vision HD Indoor/Outdoor IP Dome Camera HD838 and Night Vision HD Indoor/Outdoor Mini IP Bullet Camera HD438. They do not require users to change the default password for the admin account. They only show a pop-up window suggesting a change but there's no enforcement. An administrator can click Cancel and proceed to use the device without changing the password. Additionally, they disclose the default username within the login.js script. Since many attacks for IoT devices, including malware and exploits, are based on the usage of default credentials, it makes these cameras an easy target for malicious actors.Show less
1Mattermost
1Mattermost Server
Nov 21, 2024
Jun 19, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Mattermost Server before 3.2.0. It mishandles brute-force attempts at password change.
1Schneider Electric
1Gp Pro Ex Firmware
Jun 17, 2026
Jun 16, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A CWE-521: Weak Password Requirements vulnerability exists in the GP-Pro EX V1.00 to V4.09.100 which could cause the discovery of the password when the user is entering the password because it is not masqueraded.
1Ibm
1Qradar Network Packet Capture
Jun 17, 2026
Jun 10, 2020
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
IBM QRadar Network Packet Capture 7.3.0 - 7.3.3 Patch 1 and 7.4.0 GA does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 1...Show more
IBM QRadar Network Packet Capture 7.3.0 - 7.3.3 Patch 1 and 7.4.0 GA does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 166803.Show less
1Ibm
1Security Identity Governance And Intelligence
Jun 17, 2026
May 28, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM Security Identity Governance and Intelligence 5.2.6 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 175423.
1Blaauwproducts
1Remote Kiln Control
Jun 17, 2026
May 7, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Weak password requirements in Blaauw Remote Kiln Control through v3.00r4 allow a user to set short or guessable passwords (e.g., 1 or 1234).
1Oklok Project
1Oklok
Jun 17, 2026
May 4, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) has weak password requirements combined with improper restriction of excessive authentication attempts, which could allow a remote attac...Show more
The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) has weak password requirements combined with improper restriction of excessive authentication attempts, which could allow a remote attacker to discover user credentials and obtain access via a brute force attack.Show less
1Netgear
1Insight
Nov 21, 2024
Apr 28, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The NETGEAR Insight application before 2.42 for Android and iOS is affected by password mismanagement.
1Evenroute
1Iqrouter Firmware
Jun 17, 2026
Apr 21, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In IQrouter through 3.3.1, the Lua function reset_password in the web-panel allows remote attackers to change the root password arbitrarily. Note: The vendor claims that this vulnerability can only occur on a brand-new n...Show more
In IQrouter through 3.3.1, the Lua function reset_password in the web-panel allows remote attackers to change the root password arbitrarily. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after initiating the forced initial configuration (which has a required step for setting a secure password on the system), makes this CVE invalid. This vulnerability is “true for any unconfigured release of OpenWRT, and true of many other new Linux distros prior to being configured for the first time”Show less