← Back
CWE-522

1,396 CVEs • Abstraction: Class

Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

JSON object

Loading...

CVEs (1,396)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jenkins
1Fortify
Jun 17, 2026
Jan 29, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins Fortify Plugin 19.1.29 and earlier stores proxy server passwords unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master...Show more
Jenkins Fortify Plugin 19.1.29 and earlier stores proxy server passwords unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.Show less
1Handsomeweb
1Sos Webpages
Nov 21, 2024
Jan 28, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
backup.php in HandsomeWeb SOS Webpages before 1.1.12 does not require knowledge of the cleartext password, which allows remote attackers to bypass authentication by leveraging knowledge of the administrator password hash...Show more
backup.php in HandsomeWeb SOS Webpages before 1.1.12 does not require knowledge of the cleartext password, which allows remote attackers to bypass authentication by leveraging knowledge of the administrator password hash.Show less
2Fedoraproject
Smb4k Project
2Fedora
Smb4k
Nov 21, 2024
Jan 28, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Smb4K before 1.1.1 allows remote attackers to obtain credentials via vectors related to the cuid option in the "Additional options" line edit.
1Hp
3Web Viewpoint T0320
Web Viewpoint T0952Web Viewpoint T0986
Jun 17, 2026
Jan 27, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An issue was discovered in Idelji Web ViewPoint H01ABO-H01BY and L01ABP-L01ABZ, Web ViewPoint Plus H01AAG-H01AAQ and L01AAH-L01AAR, and Web ViewPoint Enterprise H01-H01AAE and L01-L01AAF. By reading ADB or AADB file cont...Show more
An issue was discovered in Idelji Web ViewPoint H01ABO-H01BY and L01ABP-L01ABZ, Web ViewPoint Plus H01AAG-H01AAQ and L01AAH-L01AAR, and Web ViewPoint Enterprise H01-H01AAE and L01-L01AAF. By reading ADB or AADB file content within the Installation subvolume, a Guardian user can discover the password of the group.user or alias who acknowledges events from the WVP Events screen.Show less
11Ciktel
CoshipFg Products+8 more
18A3002ru Firmware
A702r FirmwareEmta Ap Firmwre+15 more
Jun 17, 2026
Jan 27, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) stores cleartext administrative passwords in flash memory and in a file. This affects TOTOLINK A3002RU through 2.0.0, A702...Show more
A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) stores cleartext administrative passwords in flash memory and in a file. This affects TOTOLINK A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through 4.0.0, N150RT through 3.4.0, and N100RE through 3.4.0; Rutek RTK 11N AP through 2019-12-12; Sapido GR297n through 2019-12-12; CIK TELECOM MESH ROUTER through 2019-12-12; KCTVJEJU Wireless AP through 2019-12-12; Fibergate FGN-R2 through 2019-12-12; Hi-Wifi MAX-C300N through 2019-12-12; HCN MAX-C300N through 2019-12-12; T-broad GN-866ac through 2019-12-12; Coship EMTA AP through 2019-12-12; and IO-Data WN-AC1167R through 2019-12-12.Show less
1Gehealthcare
6Apexpro Telemetry Server Firmware
Carescape Central Station Mai700 FirmwareCarescape Central Station Mas700 Firmware+3 more
Jun 17, 2026
Jan 24, 2020
N/A· v4
10.0 CRITICAL· v3
7.5 HIGH· v2
In ApexPro Telemetry Server, Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Telemetry Server Version 4.3, CARESCAPE Central Station (CSC...Show more
In ApexPro Telemetry Server, Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Telemetry Server Version 4.3, CARESCAPE Central Station (CSCS) Versions 1.X, a vulnerability exists in the affected products that could allow an attacker to obtain access to the SSH private key in configuration files.Show less
1Ge
2D200 Firmware
D20me Firmware
Nov 21, 2024
Jan 23, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
General Electric D20ME devices are not properly configured and reveal plaintext passwords.
1Ixpdata
1Easyinstall
Jun 17, 2026
Jan 23, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In IXP EasyInstall 6.2.13723, there are cleartext credentials in network communication on TCP port 20050 when using the Administrator console remotely.
1Ruckuswireless
2Unleashed
Zonedirector 1200 Firmware
Jun 17, 2026
Jan 22, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Incorrect access control in the web interface in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote credential fetch via an unauthenticated HTTP request involving a symlink with /tmp and web/user/wps_tool_ca...Show more
Incorrect access control in the web interface in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote credential fetch via an unauthenticated HTTP request involving a symlink with /tmp and web/user/wps_tool_cache.Show less
1Kmccontrols
1Bac A1616bc Firmware
Jun 17, 2026
Jan 19, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
KMS Controls BAC-A1616BC BACnet devices have a cleartext password of snowman in the BACKDOOR_NAME variable in the BC_Logon.swf file.
1Trendmicro
1Password Manager
Jun 17, 2026
Jan 18, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A RootCA vulnerability found in Trend Micro Password Manager for Windows and macOS exists where the localhost.key of RootCA.crt might be improperly accessed by an unauthorized party and could be used to create malicious...Show more
A RootCA vulnerability found in Trend Micro Password Manager for Windows and macOS exists where the localhost.key of RootCA.crt might be improperly accessed by an unauthorized party and could be used to create malicious self-signed SSL certificates, allowing an attacker to misdirect a user to phishing sites.Show less
2Apache
Oracle
8Commerce Guided Search
Communications Diameter Signaling RouterCommunications Element Manager+5 more
Jun 17, 2026
Jan 16, 2020
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
Apache CXF ships with a OpenId Connect JWK Keys service, which allows a client to obtain the public keys in JWK format, which can then be used to verify the signature of tokens issued by the service. Typically, the servi...Show more
Apache CXF ships with a OpenId Connect JWK Keys service, which allows a client to obtain the public keys in JWK format, which can then be used to verify the signature of tokens issued by the service. Typically, the service obtains the public key from a local keystore (JKS/PKCS12) by specifing the path of the keystore and the alias of the keystore entry. This case is not vulnerable. However it is also possible to obtain the keys from a JWK keystore file, by setting the configuration parameter "rs.security.keystore.type" to "jwk". For this case all keys are returned in this file "as is", including all private key and secret key credentials. This is an obvious security risk if the user has configured the signature keystore file with private or secret key credentials. From CXF 3.3.5 and 3.2.12, it is mandatory to specify an alias corresponding to the id of the key in the JWK file, and only this key is returned. In addition, any private key information is omitted by default. "oct" keys, which contain secret keys, are not returned at all.Show less
1Jenkins
1Redgate Sql Change Automation
Jun 17, 2026
Jan 15, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins Redgate SQL Change Automation Plugin 2.0.4 and earlier stored an API key unencrypted in job config.xml files on the Jenkins master where they could be viewed by users with Extended Read permission, or access to t...Show more
Jenkins Redgate SQL Change Automation Plugin 2.0.4 and earlier stored an API key unencrypted in job config.xml files on the Jenkins master where they could be viewed by users with Extended Read permission, or access to the master file system.Show less
1Zohocorp
1Manageengine Eventlog Analyzer
Nov 21, 2024
Jan 13, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
ManageEngine EventLog Analyzer version 7 through 9.9 build 9002 has a Credentials Disclosure Vulnerability. Fixed version 10 Build 10000.
1Granding
1Grand Ma300 Firmware
Nov 21, 2024
Jan 13, 2020
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Grand MA 300 allows a brute-force attack on the PIN.
1Arialsoftware
1Campaign Enterprise
Nov 21, 2024
Jan 10, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Arial Campaign Enterprise before 11.0.551 stores passwords in clear text and these may be retrieved.
1Ibm
1Qradar Security Information And Event Manager
Jun 17, 2026
Jan 10, 2020
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
IBM QRadar SIEM 7.3.0 through 7.3.3 uses weak credential storage in some instances which could be decrypted by a local attacker. IBM X-Force ID: 164429.
1Status2k
1Status2k
Nov 21, 2024
Jan 10, 2020
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Status2k does not remove the install directory allowing credential reset.
1Fortinet
1Fortisiem
Jun 17, 2026
Jan 7, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An information exposure vulnerability in the external authentication profile form of FortiSIEM 5.2.2 and earlier may allow an authenticated attacker to retrieve the external authentication password via the HTML source co...Show more
An information exposure vulnerability in the external authentication profile form of FortiSIEM 5.2.2 and earlier may allow an authenticated attacker to retrieve the external authentication password via the HTML source code.Show less
1Anglers Net
1Cgi An Anlyzer
Jun 17, 2026
Jan 6, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Access analysis CGI An-Analyzer released in 2019 June 24 and earlier allow remote attackers to obtain a login password via HTTP referer.