← Back
CWE-521

259 CVEs • Abstraction: Base

Weak Password Requirements

The product does not require that users should have strong passwords, which makes it easier for attackers to compromise user accounts.

JSON object

Loading...

CVEs (259)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Jun 17, 2026
Jul 10, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Weak Password Requirements vulnerability in Mitsubishi Electric Corporation photovoltaic system monitor “EcoGuideTAB” PV-DR004J all versions and PV-DR004JA all versions allows an attacker within the Wi-Fi communication r...Show more
Weak Password Requirements vulnerability in Mitsubishi Electric Corporation photovoltaic system monitor “EcoGuideTAB” PV-DR004J all versions and PV-DR004JA all versions allows an attacker within the Wi-Fi communication range between the units of the product (measurement unit and display unit) to derive the password from the SSID. In addition, if the product is configured to enable the individual air conditioner control function, an attacker who has access to the Wi-Fi communication between the units by exploiting this vulnerability may be able to execute ECHONET Lite commands to perform operations such as turning the air conditioner on or off and changing the set temperature. The individual air conditioner control function is available only in display unit version 02.00.01 or later and measurement unit version 02.03.01 or later. The affected products discontinued in 2015, support ended in 2020.Show less
-
-
Jun 17, 2026
Jul 1, 2025
8.7 HIGH· v4
N/A· v3
N/A· v2
Hikvision Streaming Media Management Server v2.3.5 uses default credentials that allow remote attackers to authenticate and access restricted functionality. After authenticating with these credentials, an attacker can ex...Show more
Hikvision Streaming Media Management Server v2.3.5 uses default credentials that allow remote attackers to authenticate and access restricted functionality. After authenticating with these credentials, an attacker can exploit an arbitrary file read vulnerability in the /systemLog/downFile.php endpoint via directory traversal in the fileName parameter. This exploit chain can enable unauthorized access to sensitive system files.Show less
1Filebrowser
1Filebrowser
Jun 17, 2026
Jun 30, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to version 2.34.1, a missing password policy and brute-force protec...Show more
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to version 2.34.1, a missing password policy and brute-force protection makes the authentication process insecure. Attackers could mount a brute-force attack to retrieve the passwords of all accounts in a given instance. This issue has been patched in version 2.34.1.Show less
1Openc3
1Cosmos
Jun 17, 2026
Jun 13, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Weak password requirements in OpenC3 COSMOS v6.0.0 allow attackers to bypass authentication via a brute force attack.
1Ibm
1Security Verify Governance
Jun 17, 2026
Jun 6, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
IBM Security Verify Governance 10.0.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
1Schule111
1Schule School Management System
Jun 17, 2026
May 22, 2025
6.6 MEDIUM· v4
7.3 HIGH· v3
N/A· v2
Schule is open-source school management system software. The generateOTP() function generates a 4-digit numeric One-Time Password (OTP). Prior to version 1.0.1, even if a secure random number generator is used, the short...Show more
Schule is open-source school management system software. The generateOTP() function generates a 4-digit numeric One-Time Password (OTP). Prior to version 1.0.1, even if a secure random number generator is used, the short length and limited range (1000–9999) results in only 9000 possible combinations. This small keyspace makes the OTP highly vulnerable to brute-force attacks, especially in the absence of strong rate-limiting or lockout mechanisms. Version 1.0.1 fixes the issue.Show less
-
-
Jun 17, 2026
May 12, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Users who were required to change their password could still access system information before changing their password
-
-
Jun 17, 2026
May 11, 2025
6.3 MEDIUM· v4
3.7 LOW· v3
2.6 LOW· v2
A vulnerability, which was classified as problematic, has been found in SunGrow Logger1000 01_A. This issue affects some unknown processing. The manipulation leads to weak password requirements. The attack may be initiat...Show more
A vulnerability, which was classified as problematic, has been found in SunGrow Logger1000 01_A. This issue affects some unknown processing. The manipulation leads to weak password requirements. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Ibm
2App Connect Enterprise Certified Containers Operands
App Connect Operator
Jun 17, 2026
May 9, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
IBM App Connect Enterprise Certified Container 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, 12.3, 12.4, 12.5, 12.6, 12.7, 12.8, 12.9, and 12.10 DesignerAuthoring instan...Show more
IBM App Connect Enterprise Certified Container 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, 12.3, 12.4, 12.5, 12.6, 12.7, 12.8, 12.9, and 12.10 DesignerAuthoring instances store their flows in a database that is protected by weaker than expected cryptographic algorithms that could be decrypted by a local user.Show less
1Govicture
1Rx1800 Firmware
Jul 5, 2026
May 9, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Victure RX1800 EN_V1.0.0_r12_110933 was discovered to utilize a weak default password which includes the last 8 digits of the Mac address.
1Znuny
1Znuny
Jun 17, 2026
May 8, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in Znuny before 7.1.5. When generating a support bundle, not all passwords are masked.
1Ibm
1Aspera Console
Jun 17, 2026
Apr 14, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
IBM Aspera Console 3.4.0 through 3.4.4 allows passwords to be reused when a new user logs into the system.
-
-
Jun 17, 2026
Mar 31, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Weak password requirements issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If this issue is exploited, a brute-force attack may allow an attacker unauthorized access and login.
1Lfprojects
1Mlflow
Jun 17, 2026
Mar 20, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In mlflow/mlflow version 2.18, an admin is able to create a new user account without setting a password. This vulnerability could lead to security risks, as accounts without passwords may be susceptible to unauthorized a...Show more
In mlflow/mlflow version 2.18, an admin is able to create a new user account without setting a password. This vulnerability could lead to security risks, as accounts without passwords may be susceptible to unauthorized access. Additionally, this issue violates best practices for secure user account management. The issue is fixed in version 2.19.0.Show less
1Digitaldruid
1Hoteldruid
Jun 17, 2026
Mar 11, 2025
N/A· v4
7.1 HIGH· v3
N/A· v2
An issue in HotelDruid version 3.0.7 and earlier allows users to set weak passwords due to the lack of enforcement of password strength policies.
1Printerlogic
2Vasion Print
Virtual Appliance
Jun 17, 2026
Mar 5, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Weak Password Encryption / Encoding OVE-20230524-0007.
1Ibm
1Controller
Jun 17, 2026
Mar 1, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
IBM Controller 11.0.0 through 11.0.1 and 11.1.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
1Pmweb
1Pmweb
Jun 17, 2026
Feb 16, 2025
6.3 MEDIUM· v4
8.1 HIGH· v3
2.6 LOW· v2
A vulnerability, which was classified as problematic, was found in PMWeb 7.2.0. This affects an unknown part of the component Setting Handler. The manipulation leads to weak password requirements. It is possible to initi...Show more
A vulnerability, which was classified as problematic, was found in PMWeb 7.2.0. This affects an unknown part of the component Setting Handler. The manipulation leads to weak password requirements. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to change the configuration settings. The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Ibm
1Aspera Faspex
Jun 17, 2026
Jan 29, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
IBM Aspera Faspex 5.0.0 through 5.0.10 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
1Ibm
1Aspera Faspex
Jun 17, 2026
Jan 29, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
IBM Aspera Faspex 5.0.0 through 5.0.10 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.