← Back
CWE-522

1,467 CVEs • Abstraction: Class

Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

JSON object

Loading...

CVEs (1,467)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Auth0
1Auth0.js
Jun 17, 2026
Apr 9, 2020
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
auth0.js (NPM package auth0-js) greater than version 8.0.0 and before version 9.12.3 has a vulnerability. In the case of an (authentication) error, the error object returned by the library contains the original request o...Show more
auth0.js (NPM package auth0-js) greater than version 8.0.0 and before version 9.12.3 has a vulnerability. In the case of an (authentication) error, the error object returned by the library contains the original request of the user, which may include the plaintext password the user entered. If the error object is exposed or logged without modification, the application risks password exposure. This is fixed in version 9.12.3Show less
1Castlerock
1Snmpc Online
Jun 17, 2026
Apr 9, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. It includes the username and password values in cleartext within each request's cookie value.
1Castlerock
1Snmpc Online
Jun 17, 2026
Apr 9, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. It allows remote attackers to obtain sensitive credential information from backup files.
1Paloaltonetworks
2Pan Os
Vm Series
Jun 17, 2026
Apr 8, 2020
N/A· v4
4.4 MEDIUM· v3
1.9 LOW· v2
TechSupport files generated on Palo Alto Networks VM Series firewalls for Microsoft Azure platform configured with high availability (HA) inadvertently collect Azure dashboard service account credentials. These credentia...Show more
TechSupport files generated on Palo Alto Networks VM Series firewalls for Microsoft Azure platform configured with high availability (HA) inadvertently collect Azure dashboard service account credentials. These credentials are equivalent to the credentials associated with the Contributor role in Azure. A user with the credentials will be able to manage all the Azure resources in the subscription except for granting access to other resources. These credentials do not allow login access to the VMs themselves. This issue affects VM Series Plugin versions before 1.0.9 for PAN-OS 9.0. This issue does not affect VM Series in non-HA configurations or on other cloud platforms. It does not affect hardware firewall appliances. Since becoming aware of the issue, Palo Alto Networks has safely deleted all the tech support files with the credentials. We now filter and remove these credentials from all TechSupport files sent to us. The TechSupport files uploaded to Palo Alto Networks systems were only accessible by authorized personnel with valid Palo Alto Networks credentials. We do not have any evidence of malicious access or use of these credentials.Show less
1Primekey
1Ejbca
Jun 17, 2026
Apr 8, 2020
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. The External Command Certificate Validator, which allows administrators to upload external linters to validate certificates, is supposed to save up...Show more
An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. The External Command Certificate Validator, which allows administrators to upload external linters to validate certificates, is supposed to save uploaded test certificates to the server. An attacker who has gained access to the CA UI could exploit this to upload malicious scripts to the server. (Risks associated with this issue alone are negligible unless a malicious user already has gained access to the CA UI through other means, as a trusted user is already trusted to upload scripts by virtue of having access to the validator.)Show less
1Nchsoftware
1Express Invoice
Jun 17, 2026
Apr 7, 2020
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
NCH Express Invoice 7.25 allows local users to discover the cleartext password by reading the configuration file.
1Google
1Android
Nov 21, 2024
Apr 7, 2020
N/A· v4
6.5 MEDIUM· v3
3.5 LOW· v2
An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.0) software. Attackers (who control a certain subdomain) can discover a user's credentials, during an email account login, via a...Show more
An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.0) software. Attackers (who control a certain subdomain) can discover a user's credentials, during an email account login, via an EAS autodiscover packet. The Samsung ID is SVE-2016-7654 (January 2017).Show less
1Google
1Android
Nov 21, 2024
Apr 7, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered on Samsung mobile devices with L(5.0/5.1), M(6.0), and N(7.0) software. Attackers can read the password of the Mobile Hotspot in the log because of an unprotected intent. The Samsung ID is SVE-201...Show more
An issue was discovered on Samsung mobile devices with L(5.0/5.1), M(6.0), and N(7.0) software. Attackers can read the password of the Mobile Hotspot in the log because of an unprotected intent. The Samsung ID is SVE-2016-7301 (December 2016).Show less
1Hitachienergy
1Esoms
Jun 17, 2026
Apr 2, 2020
N/A· v4
6.1 MEDIUM· v3
3.6 LOW· v2
The Redis data structure component used in ABB eSOMS versions 6.0 to 6.0.2 stores credentials in clear text. If an attacker has file system access, this can potentially compromise the credentials' confidentiality.
1Advantech
1Webaccess
Jun 17, 2026
Apr 1, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Advantech WebAccess 8.3.4 does not properly restrict an RPC call that allows unauthenticated, remote users to read files. An attacker can use this vulnerability to recover the administrator password.
1Technicolor
1Tc7337 Firmware
Jun 17, 2026
Apr 1, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered on Technicolor TC7337 8.89.17 devices. An attacker can discover admin credentials in the backup file, aka backupsettings.conf.
1Jfrog
1Artifactory
Jun 17, 2026
Mar 25, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Jenkins Artifactory Plugin 3.6.0 and earlier transmits configured passwords in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.
1Jfrog
1Artifactory
Jun 17, 2026
Mar 25, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins Artifactory Plugin 3.5.0 and earlier stores its Artifactory server password unencrypted in its global configuration file on the Jenkins master where it can be viewed by users with access to the master file system...Show more
Jenkins Artifactory Plugin 3.5.0 and earlier stores its Artifactory server password unencrypted in its global configuration file on the Jenkins master where it can be viewed by users with access to the master file system.Show less
1Suitecrm
1Suitecrm
Jun 17, 2026
Mar 20, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
SuiteCRM 7.10.x prior to 7.10.21 and 7.11.x prior to 7.11.9 mishandles API access tokens and credentials.
1Netsas
1Enigma Network Management Solution
Jun 17, 2026
Mar 19, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
NETSAS Enigma NMS 65.0.0 and prior utilises basic authentication over HTTP for enforcing access control to the web application. The use of weak authentication transmitted over cleartext protocols can allow an attacker to...Show more
NETSAS Enigma NMS 65.0.0 and prior utilises basic authentication over HTTP for enforcing access control to the web application. The use of weak authentication transmitted over cleartext protocols can allow an attacker to steal username and password combinations by intercepting authentication traffic in transit.Show less
1Dlink
2Dsl 2875al Firmware
Dsl 2877al Firmware
Jun 17, 2026
Mar 19, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
D-Link DSL-2875AL and DSL-2877AL devices through 1.00.05 are prone to information disclosure via a simple crafted request to index.asp on the web management server because of username_v and password_v variables.
1Dlink
1Dsl 2875al Firmware
Jun 17, 2026
Mar 19, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
D-Link DSL-2875AL devices through 1.00.05 are prone to password disclosure via a simple crafted /romfile.cfg request to the web management server. This request doesn't require any authentication and will lead to saving t...Show more
D-Link DSL-2875AL devices through 1.00.05 are prone to password disclosure via a simple crafted /romfile.cfg request to the web management server. This request doesn't require any authentication and will lead to saving the configuration file. The password is stored in cleartext.Show less
1Comba
1Ap2600 I A02 0202n00pd2 Firmware
Jun 17, 2026
Mar 19, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Comba AP2600-I devices through A02,0202N00PD2 are prone to password disclosure via an insecure authentication mechanism. The HTML source code of the login page contains values that allow obtaining the username and passwo...Show more
Comba AP2600-I devices through A02,0202N00PD2 are prone to password disclosure via an insecure authentication mechanism. The HTML source code of the login page contains values that allow obtaining the username and password. The username are password values are a double md5 of the plaintext real value, i.e., md5(md5(value)).Show less
1Aquaforest
1Tiff Server
Jun 17, 2026
Mar 18, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Aquaforest TIFF Server 4.0 allows Unauthenticated SMB Hash Capture via UNC.
1Netgear
1Cg3700b Firmware
Jun 17, 2026
Mar 13, 2020
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
The Voo branded NETGEAR CG3700b custom firmware V2.02.03 uses HTTP Basic Authentication over cleartext HTTP.