← Back
CWE-521

259 CVEs • Abstraction: Base

Weak Password Requirements

The product does not require that users should have strong passwords, which makes it easier for attackers to compromise user accounts.

JSON object

Loading...

CVEs (259)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Pureapplication System
Jun 17, 2026
Jun 26, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM PureApplication System 2.2.3.0 through 2.2.5.3 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 159417.
1Ibm
3Intelligent Operations Center
Intelligent Operations Center For Emergency ManagementWater Operations For Waternamics
Jun 17, 2026
Jun 7, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM Intelligent Operations Center (IOC) 5.1.0 through 5.2.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 157012.
1Westerndigital
9My Cloud Dl2100 Firmware
My Cloud Dl4100 FirmwareMy Cloud Ex2100 Firmware+6 more
Jun 17, 2026
Apr 24, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Western Digital My Cloud, My Cloud Mirror Gen2, My Cloud EX2 Ultra, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100, My Cloud DL4100, My Cloud PR2100 and My Cloud PR4100 firmware before 2.31.174 is affected by an authe...Show more
Western Digital My Cloud, My Cloud Mirror Gen2, My Cloud EX2 Ultra, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100, My Cloud DL4100, My Cloud PR2100 and My Cloud PR4100 firmware before 2.31.174 is affected by an authentication bypass vulnerability. The login_mgr.cgi file checks credentials against /etc/shadow. However, the "nobody" account (which can be used to access the control panel API as a low-privilege logged-in user) has a default empty password, allowing an attacker to modify the My Cloud EX2 Ultra web page source code and obtain access to the My Cloud as a non-Admin My Cloud device user.Show less
1Ibm
1Security Privileged Identity Manager
Nov 21, 2024
Apr 2, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 14523...Show more
IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 145236.Show less
1Dlink
1Dir 825 Rev.b Firmware
Jun 17, 2026
Feb 25, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. The "user" account has a blank password.
1Enphase
1Envoy
Jun 17, 2026
Feb 9, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A weak password vulnerability was discovered in Enphase Envoy R3.*.*. One can login via TCP port 8888 with the admin password for the admin account.
1Mobotix
1S14 Firmware
Jun 17, 2026
Feb 9, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
An issue was discovered on MOBOTIX S14 MX-V4.2.1.61 devices. /admin/access accepts a request to set the "aaaaa" password, considered insecure for some use cases, from a user.
1Ibm
1Security Identity Manager
Nov 21, 2024
Jan 14, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM Security Identity Manager 6.0.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 153628.
1Ibm
1Security Guardium
Nov 21, 2024
Dec 17, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM Security Guardium 10.0, 10.0.1, 10.1, 10.1.2, 10.1.3, 10.1.4, and 10.5 Database Activity Monitor does not require that users should have strong passwords by default, which makes it easier for attackers to compromise...Show more
IBM Security Guardium 10.0, 10.0.1, 10.1, 10.1.2, 10.1.3, 10.1.4, and 10.5 Database Activity Monitor does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 132610.Show less
1Opendental
1Opendental
Nov 21, 2024
Dec 12, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Open Dental before version 18.4 installs a mysql database and uses the default credentials of "root" with a blank password. This allows anyone on the network with access to the server to access all database information.
1Roche
4Accu Chek Inform Ii Firmware
Base Unit Hub FirmwareCoaguchek Firmware+1 more
Nov 21, 2024
Nov 20, 2018
N/A· v4
8.8 HIGH· v3
3.3 LOW· v2
An issue was discovered in Roche Accu-Chek Inform II Base Unit / Base Unit Hub before 03.01.04 and CoaguChek / cobas h232 Handheld Base Unit before 03.01.04. Weak access credentials may enable attackers in the adjacent n...Show more
An issue was discovered in Roche Accu-Chek Inform II Base Unit / Base Unit Hub before 03.01.04 and CoaguChek / cobas h232 Handheld Base Unit before 03.01.04. Weak access credentials may enable attackers in the adjacent network to gain unauthorized service access via a service interface.Show less
1Philips
2Intellispace Pacs
Isite Pacs
Nov 21, 2024
Nov 19, 2018
N/A· v4
8.8 HIGH· v3
3.3 LOW· v2
Philips iSite and IntelliSpace PACS, iSite PACS, all versions, and IntelliSpace PACS, all versions. Default credentials and no authentication within third party software may allow an attacker to compromise a component of...Show more
Philips iSite and IntelliSpace PACS, iSite PACS, all versions, and IntelliSpace PACS, all versions. Default credentials and no authentication within third party software may allow an attacker to compromise a component of the system.Show less
2Foscam
Opticam
4C2 Application Firmware
C2 System FirmwareI5 Application Firmware+1 more
Nov 21, 2024
Nov 7, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The ftpuser1 accoun...Show more
An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The ftpuser1 account has a blank password, which cannot be changed.Show less
1Dell
2Encryption
Endpoint Security Suite Enterprise
Nov 21, 2024
Oct 11, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
On install, Dell Encryption versions prior 10.0.1 and Dell Endpoint Security Suite Enterprise versions prior 2.0.1 will overwrite and manually set the "Minimum Password Length" group policy object to a value of 1 on that...Show more
On install, Dell Encryption versions prior 10.0.1 and Dell Endpoint Security Suite Enterprise versions prior 2.0.1 will overwrite and manually set the "Minimum Password Length" group policy object to a value of 1 on that device. This allows for users to bypass any existing policy for password length and potentially create insecure password on their device. This value is defined during the installation of the "Encryption Management Agent" or "EMAgent" application. There are no other known values modified.Show less
1Gleeztech
1Gleez Cms
Nov 21, 2024
Sep 7, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability in the Gleez CMS 1.2.0 login page could allow an unauthenticated, remote attacker to perform multiple user enumerations, which can further help an attacker to perform login attempts in excess of the confi...Show more
A vulnerability in the Gleez CMS 1.2.0 login page could allow an unauthenticated, remote attacker to perform multiple user enumerations, which can further help an attacker to perform login attempts in excess of the configured login attempt limit. The vulnerability is due to insufficient server-side access control and login attempt limit enforcement. An attacker could exploit this vulnerability by sending modified login attempts to the Portal login page. An exploit could allow the attacker to identify existing users and perform brute-force password attacks on the Portal, as demonstrated by navigating to the user/4 URI.Show less
1Ietf
1Internet Key Exchange
Jun 17, 2026
Sep 6, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The Internet Key Exchange v1 main mode is vulnerable to offline dictionary or brute force attacks. Reusing a key pair across different versions and modes of IKE could lead to cross-protocol authentication bypasses. It is...Show more
The Internet Key Exchange v1 main mode is vulnerable to offline dictionary or brute force attacks. Reusing a key pair across different versions and modes of IKE could lead to cross-protocol authentication bypasses. It is well known, that the aggressive mode of IKEv1 PSK is vulnerable to offline dictionary or brute force attacks. For the main mode, however, only an online attack against PSK authentication was thought to be feasible. This vulnerability could allow an attacker to recover a weak Pre-Shared Key or enable the impersonation of a victim host or network.Show less
1Npci
1Bharat Interface For Money (bhim)
Nov 21, 2024
Aug 24, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The National Payments Corporation of India BHIM application 1.3 for Android relies on a four-digit passcode, which makes it easier for attackers to obtain access.
1Dell
32335dn Engine Firmware
2335dn Network Firmware2335dn Printer Firmware
Nov 21, 2024
Aug 23, 2018
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
On Dell 2335dn printers with Printer Firmware Version 2.70.05.02, Engine Firmware Version 1.10.65, and Network Firmware Version V4.02.15(2335dn MFP) 11-22-2010, the admin interface allows an authenticated attacker to ret...Show more
On Dell 2335dn printers with Printer Firmware Version 2.70.05.02, Engine Firmware Version 1.10.65, and Network Firmware Version V4.02.15(2335dn MFP) 11-22-2010, the admin interface allows an authenticated attacker to retrieve the configured SMTP or LDAP password by viewing the HTML source code of the Email Settings webpage. In some cases, authentication can be achieved with the blank default password for the admin account. NOTE: the vendor indicates that this is an "End Of Support Life" product.Show less
1Lantronix
1Mss Firmware
Nov 21, 2024
Jun 28, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Baseon Lantronix MSS devices do not require a password for TELNET access.
1Redhat
2Ansible Tower
Cloudforms
Nov 21, 2024
May 2, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Ansible Tower before version 3.2.4 has a flaw in the management of system and organization administrators that allows for privilege escalation. System administrators that are members of organizations can have their passw...Show more
Ansible Tower before version 3.2.4 has a flaw in the management of system and organization administrators that allows for privilege escalation. System administrators that are members of organizations can have their passwords reset by organization administrators, allowing organization administrators access to the entire system.Show less