CWE-522
1,396 CVEs • Abstraction: Class
Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
CVEs (1,396)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Jenkins Fortify Plugin 19.1.29 and earlier stores proxy server passwords unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master...Show more |
backup.php in HandsomeWeb SOS Webpages before 1.1.12 does not require knowledge of the cleartext password, which allows remote attackers to bypass authentication by leveraging knowledge of the administrator password hash...Show more |
2Fedoraproject Smb4k Project2Fedora Smb4kNov 21, 2024 Jan 28, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Smb4K before 1.1.1 allows remote attackers to obtain credentials via vectors related to the cuid option in the "Additional options" line edit. |
1Hp 3Web Viewpoint T0320 Web Viewpoint T0952Web Viewpoint T0986Jun 17, 2026 Jan 27, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An issue was discovered in Idelji Web ViewPoint H01ABO-H01BY and L01ABP-L01ABZ, Web ViewPoint Plus H01AAG-H01AAQ and L01AAH-L01AAR, and Web ViewPoint Enterprise H01-H01AAE and L01-L01AAF. By reading ADB or AADB file cont...Show more |
11Ciktel CoshipFg Products+8 more18A3002ru Firmware A702r FirmwareEmta Ap Firmwre+15 moreJun 17, 2026 Jan 27, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) stores cleartext administrative passwords in flash memory and in a file. This affects TOTOLINK A3002RU through 2.0.0, A702...Show more |
1Gehealthcare 6Apexpro Telemetry Server Firmware Carescape Central Station Mai700 FirmwareCarescape Central Station Mas700 Firmware+3 moreJun 17, 2026 Jan 24, 2020 N/A· v4 10.0 CRITICAL· v3 7.5 HIGH· v2 In ApexPro Telemetry Server, Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Telemetry Server Version 4.3, CARESCAPE Central Station (CSC...Show more |
1Ge 2D200 Firmware D20me FirmwareNov 21, 2024 Jan 23, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 General Electric D20ME devices are not properly configured and reveal plaintext passwords. |
In IXP EasyInstall 6.2.13723, there are cleartext credentials in network communication on TCP port 20050 when using the Administrator console remotely. |
1Ruckuswireless 2Unleashed Zonedirector 1200 FirmwareJun 17, 2026 Jan 22, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Incorrect access control in the web interface in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote credential fetch via an unauthenticated HTTP request involving a symlink with /tmp and web/user/wps_tool_ca...Show more |
1Kmccontrols 1Bac A1616bc Firmware Jun 17, 2026 Jan 19, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 KMS Controls BAC-A1616BC BACnet devices have a cleartext password of snowman in the BACKDOOR_NAME variable in the BC_Logon.swf file. |
A RootCA vulnerability found in Trend Micro Password Manager for Windows and macOS exists where the localhost.key of RootCA.crt might be improperly accessed by an unauthorized party and could be used to create malicious...Show more |
2Apache Oracle8Commerce Guided Search Communications Diameter Signaling RouterCommunications Element Manager+5 moreJun 17, 2026 Jan 16, 2020 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 Apache CXF ships with a OpenId Connect JWK Keys service, which allows a client to obtain the public keys in JWK format, which can then be used to verify the signature of tokens issued by the service. Typically, the servi...Show more |
1Jenkins 1Redgate Sql Change Automation Jun 17, 2026 Jan 15, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Jenkins Redgate SQL Change Automation Plugin 2.0.4 and earlier stored an API key unencrypted in job config.xml files on the Jenkins master where they could be viewed by users with Extended Read permission, or access to t...Show more |
1Zohocorp 1Manageengine Eventlog Analyzer Nov 21, 2024 Jan 13, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ManageEngine EventLog Analyzer version 7 through 9.9 build 9002 has a Credentials Disclosure Vulnerability. Fixed version 10 Build 10000. |
1Granding 1Grand Ma300 Firmware Nov 21, 2024 Jan 13, 2020 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Grand MA 300 allows a brute-force attack on the PIN. |
1Arialsoftware 1Campaign Enterprise Nov 21, 2024 Jan 10, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Arial Campaign Enterprise before 11.0.551 stores passwords in clear text and these may be retrieved. |
1Ibm 1Qradar Security Information And Event Manager Jun 17, 2026 Jan 10, 2020 N/A· v4 7.8 HIGH· v3 2.1 LOW· v2 IBM QRadar SIEM 7.3.0 through 7.3.3 uses weak credential storage in some instances which could be decrypted by a local attacker. IBM X-Force ID: 164429. |
Status2k does not remove the install directory allowing credential reset. |
An information exposure vulnerability in the external authentication profile form of FortiSIEM 5.2.2 and earlier may allow an authenticated attacker to retrieve the external authentication password via the HTML source co...Show more |
Access analysis CGI An-Analyzer released in 2019 June 24 and earlier allow remote attackers to obtain a login password via HTTP referer. |