← Back
CWE-521

259 CVEs • Abstraction: Base

Weak Password Requirements

The product does not require that users should have strong passwords, which makes it easier for attackers to compromise user accounts.

JSON object

Loading...

CVEs (259)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hitachienergy
1Esoms
Jun 17, 2026
Apr 2, 2020
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
eSOMS versions 4.0 to 6.0.3 do not enforce password complexity settings, potentially resulting in lower access security due to insecure user passwords.
1Moxa
2Eds 510e Firmware
Eds G516e Firmware
Jun 17, 2026
Mar 24, 2020
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
In Moxa EDS-G516E Series firmware, Version 5.2 or lower, weak password requirements may allow an attacker to gain access using brute force.
1Moxa
55Pt 7528 12msc 12tx 4gsfp Hv Hv Firmware
Pt 7528 12msc 12tx 4gsfp Hv FirmwarePt 7528 12msc 12tx 4gsfp Wv Wv Firmware+52 more
Jun 17, 2026
Mar 24, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or lower, the application utilizes weak password requirements, which may allow an attacker to gain unauthorized access.
1Auto Maskin
3Dcu 210e Firmware
Marine Pro ObserverRp 210e Firmware
Jun 17, 2026
Mar 23, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Auto-Maskin RP210E Versions 3.7 and prior, DCU210E Versions 3.7 and prior and Marine Observer Pro (Android App), the software contains a mechanism for users to recover or change their passwords without knowing the ori...Show more
In Auto-Maskin RP210E Versions 3.7 and prior, DCU210E Versions 3.7 and prior and Marine Observer Pro (Android App), the software contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.Show less
1Moxa
6Mb3170 Firmware
Mb3180 FirmwareMb3270 Firmware+3 more
Jun 17, 2026
Mar 11, 2020
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. Insufficient password requirements for the MGate...Show more
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. Insufficient password requirements for the MGate web application may allow an attacker to gain access by brute-forcing account passwords.Show less
1Iteris
1Vantage Velocity Firmware
Jun 17, 2026
Feb 17, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Iteris Vantage Velocity Field Unit 2.3.1 and 2.4.2 devices have two users that are not documented and are configured with weak passwords (User bluetooth, password bluetooth; User eclipse, password eclipse). Also, bluetoo...Show more
Iteris Vantage Velocity Field Unit 2.3.1 and 2.4.2 devices have two users that are not documented and are configured with weak passwords (User bluetooth, password bluetooth; User eclipse, password eclipse). Also, bluetooth is the root password.Show less
1Voatz
1Voatz
Jun 17, 2026
Feb 13, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The Voatz application 2020-01-01 for Android allows only 100 million different PINs, which makes it easier for attackers (after using root access to make a copy of the local database) to discover login credentials and vo...Show more
The Voatz application 2020-01-01 for Android allows only 100 million different PINs, which makes it easier for attackers (after using root access to make a copy of the local database) to discover login credentials and voting history via an offline brute-force approach.Show less
1Teamviewer
1Teamviewer
Jun 17, 2026
Feb 7, 2020
N/A· v4
7.0 HIGH· v3
4.4 MEDIUM· v2
TeamViewer Desktop through 14.7.1965 allows a bypass of remote-login access control because the same key is used for different customers' installations. It used a shared AES key for all installations since at least as fa...Show more
TeamViewer Desktop through 14.7.1965 allows a bypass of remote-login access control because the same key is used for different customers' installations. It used a shared AES key for all installations since at least as far back as v7.0.43148, and used it for at least OptionsPasswordAES in the current version of the product. If an attacker were to know this key, they could decrypt protect information stored in the registry or configuration files of TeamViewer. With versions before v9.x , this allowed for attackers to decrypt the Unattended Access password to the system (which allows for remote login to the system as well as headless file browsing). The latest version still uses the same key for OptionPasswordAES but appears to have changed how the Unattended Access password is stored. While in most cases an attacker requires an existing session on a system, if the registry/configuration keys were stored off of the machine (such as in a file share or online), an attacker could then decrypt the required password to login to the system.Show less
3Canonical
DebianOpensuse
3Cloud Init
Debian LinuxLeap
Jun 17, 2026
Feb 5, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
In cloud-init through 19.4, rand_user_password in cloudinit/config/cc_set_passwords.py has a small default pwlen value, which makes it easier for attackers to guess passwords.
1Plone
1Plone
Jun 17, 2026
Jan 23, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Missing password strength checks on some forms in Plone 4.3 through 5.2.0 allow users to set weak passwords, leading to easier cracking.
1Sonicwall
1Email Security Appliance
Jun 17, 2026
Dec 23, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Weak default password cause vulnerability in SonicWall Email Security appliance which leads to attacker gain access to appliance database. This vulnerability affected Email Security Appliance version 10.0.2 and earlier.
1Neuvector
1Neuvector
Jun 17, 2026
Dec 20, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
NeuVector 3.1 when configured to allow authentication via Active Directory, does not enforce non-empty passwords which allows an attacker with access to the Neuvector portal to authenticate as any valid LDAP user by prov...Show more
NeuVector 3.1 when configured to allow authentication via Active Directory, does not enforce non-empty passwords which allows an attacker with access to the Neuvector portal to authenticate as any valid LDAP user by providing a valid username and an empty password (provided that the active directory server has not been configured to reject empty passwords).Show less
1Trendmicro
1Mobile Security
Jun 17, 2026
Dec 18, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Trend Micro Mobile Security for Android (Consumer) versions 10.3.1 and below on Android 8.0+ has an issue in which an attacker could bypass the product's App Password Protection feature.
1Barco
3Clickshare Cs 100 Firmware
Clickshare Cse 200 FirmwareClickshare Cse 800 Firmware
Jun 17, 2026
Dec 16, 2019
N/A· v4
6.8 MEDIUM· v3
7.2 HIGH· v2
Barco ClickShare Button R9861500D01 devices before 1.9.0 have Insufficiently Protected Credentials. The root account (present for access via debug interfaces, which are by default not enabled on production devices) of th...Show more
Barco ClickShare Button R9861500D01 devices before 1.9.0 have Insufficiently Protected Credentials. The root account (present for access via debug interfaces, which are by default not enabled on production devices) of the embedded Linux on the ClickShare Button is using a weak password.Show less
3Fedoraproject
OpensuseSamba
3Fedora
LeapSamba
Jun 17, 2026
Nov 6, 2019
N/A· v4
5.4 MEDIUM· v3
4.9 MEDIUM· v2
A flaw was found in Samba, all versions starting samba 4.5.0 before samba 4.9.15, samba 4.10.10, samba 4.11.2, in the way it handles a user password change or a new password for a samba user. The Samba Active Directory D...Show more
A flaw was found in Samba, all versions starting samba 4.5.0 before samba 4.9.15, samba 4.10.10, samba 4.11.2, in the way it handles a user password change or a new password for a samba user. The Samba Active Directory Domain Controller can be configured to use a custom script to check for password complexity. This configuration can fail to verify password complexity when non-ASCII characters are used in the password, which could lead to weak passwords being set for samba users, making it vulnerable to dictionary attacks.Show less
2Debian
Gpw Project
2Debian Linux
Gpw
Nov 21, 2024
Oct 29, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
gpw generates shorter passwords than required
1Ibm
1Security Key Lifecycle Manager
Jun 17, 2026
Sep 20, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM Security Key Lifecycle Manager 3.0 and 3.0.1 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 166626.
1Rsa
1Archer
Jun 17, 2026
Sep 18, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
RSA Archer, versions prior to 6.6 P2 (6.6.0.2), contain an improper authentication vulnerability. The vulnerability allows sysadmins to create user accounts with insufficient credentials. Unauthenticated attackers could...Show more
RSA Archer, versions prior to 6.6 P2 (6.6.0.2), contain an improper authentication vulnerability. The vulnerability allows sysadmins to create user accounts with insufficient credentials. Unauthenticated attackers could gain unauthorized access to the system using those accounts.Show less
1Siemens
1Sinema Remote Connect Server
Jun 17, 2026
Sep 13, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). The web interface has no means to prevent password guessing attacks. The vulnerability could be exploited by an attacker with...Show more
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). The web interface has no means to prevent password guessing attacks. The vulnerability could be exploited by an attacker with network access to the vulnerable software, requiring no privileges and no user interaction. The vulnerability could allow full access to the web interface. At the time of advisory publication no public exploitation of this security vulnerability was known.Show less
1Ibm
3Intelligent Operations Center
Intelligent Operations Center For Emergency ManagementWater Operations For Waternamics
Jun 17, 2026
Sep 5, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM Intelligent Operations Center V5.1.0 - V5.2.0, IBM Intelligent Operations Center for Emergency Management V5.1.0 - V5.1.0.6, and IBM Water Operations for Waternamics V5.1.0 - V5.2.1.1 does not require that users shou...Show more
IBM Intelligent Operations Center V5.1.0 - V5.2.0, IBM Intelligent Operations Center for Emergency Management V5.1.0 - V5.1.0.6, and IBM Water Operations for Waternamics V5.1.0 - V5.2.1.1 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 161201.Show less