← Back
CWE-522

1,396 CVEs • Abstraction: Class

Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

JSON object

Loading...

CVEs (1,396)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jenkins
1Data Theorem Mobile App Security
Jun 17, 2026
Sep 25, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins Data Theorem: CI/CD Plugin 1.3 and earlier stored credentials unencrypted in job config.xml files on the Jenkins master where they could be viewed by users with Extended Read permission, or access to the master f...Show more
Jenkins Data Theorem: CI/CD Plugin 1.3 and earlier stored credentials unencrypted in job config.xml files on the Jenkins master where they could be viewed by users with Extended Read permission, or access to the master file system.Show less
1Netapp
1Ontap Select Deploy Administration Utility
Jun 17, 2026
Sep 24, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
ONTAP Select Deploy administration utility versions 2.2 through 2.12.1 transmit credentials in plaintext.
1Grafana
1Grafana
Jun 17, 2026
Sep 23, 2019
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in Grafana 5.4.0. Passwords for data sources used by Grafana (e.g., MySQL) are not encrypted. An admin user can reveal passwords for any data source by pressing the "Save and test" button within a...Show more
An issue was discovered in Grafana 5.4.0. Passwords for data sources used by Grafana (e.g., MySQL) are not encrypted. An admin user can reveal passwords for any data source by pressing the "Save and test" button within a data source's settings menu. When watching the transaction with Burp Proxy, the password for the data source is revealed and sent to the server. From a browser, a prompt to save the credentials is generated, and the password can be revealed by simply checking the "Show password" box.Show less
1Supermicro
321A1sa2 2750f Firmware
A1sai 2550f FirmwareA1sai 2750f Firmware+318 more
Jun 17, 2026
Sep 21, 2019
N/A· v4
10.0 CRITICAL· v3
5.0 MEDIUM· v2
On Supermicro H11, H12, M11, X9, X10, and X11 products, a combination of encryption and authentication problems in the virtual media service allows capture of BMC credentials and data transferred over virtual media devic...Show more
On Supermicro H11, H12, M11, X9, X10, and X11 products, a combination of encryption and authentication problems in the virtual media service allows capture of BMC credentials and data transferred over virtual media devices. Attackers can use captured credentials to connect virtual USB devices to the server managed by the BMC.Show less
1Microfocus
1Service Manager
Jun 17, 2026
Sep 18, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Clear text password in browser in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could be exploited to allow sensitive d...Show more
Clear text password in browser in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could be exploited to allow sensitive data exposure.Show less
1Microfocus
1Service Manager
Jun 17, 2026
Sep 18, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Clear text credentials are used to access managers app in Tomcat in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could...Show more
Clear text credentials are used to access managers app in Tomcat in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could be exploited to allow sensitive data exposure.Show less
1Vmware
1Vcenter Server
Jun 17, 2026
Sep 18, 2019
N/A· v4
7.7 HIGH· v3
4.0 MEDIUM· v2
VMware vCenter Server (6.7.x prior to 6.7 U3, 6.5 prior to 6.5 U3 and 6.0 prior to 6.0 U3j) contains an information disclosure vulnerability where Virtual Machines deployed from an OVF could expose login information via...Show more
VMware vCenter Server (6.7.x prior to 6.7 U3, 6.5 prior to 6.5 U3 and 6.0 prior to 6.0 U3j) contains an information disclosure vulnerability where Virtual Machines deployed from an OVF could expose login information via the virtual machine's vAppConfig properties. A malicious actor with access to query the vAppConfig properties of a virtual machine deployed from an OVF may be able to view the credentials used to deploy the OVF (typically the root account of the virtual machine).Show less
1Schneider Electric
4Ap9630 Firmware
Ap9631 FirmwareAp9635 Firmware+1 more
Jun 17, 2026
Sep 17, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
A Credentials Management CWE-255 vulnerability exists in the APC UPS Network Management Card 2 AOS v6.5.6, which could cause Remote Monitoring Credentials to be viewed in plaintext when Remote Monitoring is enabled, and...Show more
A Credentials Management CWE-255 vulnerability exists in the APC UPS Network Management Card 2 AOS v6.5.6, which could cause Remote Monitoring Credentials to be viewed in plaintext when Remote Monitoring is enabled, and then disabled.Show less
1Jenkins
1Beaker Builder
Jun 17, 2026
Sep 12, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Jenkins Beaker Builder Plugin 1.9 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system.
1Teamviewer
1Teamviewer
Jun 17, 2026
Sep 11, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
An issue was discovered in TeamViewer 14.2.2558. Updating the product as a non-administrative user requires entering administrative credentials into the GUI. Subsequently, these credentials are processed in Teamviewer.ex...Show more
An issue was discovered in TeamViewer 14.2.2558. Updating the product as a non-administrative user requires entering administrative credentials into the GUI. Subsequently, these credentials are processed in Teamviewer.exe, which allows any application running in the same non-administrative user context to intercept them in cleartext within process memory. By using this technique, a local attacker is able to obtain administrative credentials in order to elevate privileges. This vulnerability can be exploited by injecting code into Teamviewer.exe which intercepts calls to GetWindowTextW and logs the processed credentials.Show less
1Knowage Suite
1Knowage
Jun 17, 2026
Sep 5, 2019
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
In Knowage through 6.1.1, an authenticated user that accesses the users page will obtain all user password hashes.
1Eng
1Knowage
Jun 17, 2026
Aug 28, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
In Knowage through 6.1.1, an authenticated user who accesses the datasources page will gain access to any data source credentials in cleartext, which includes databases.
1Search Guard
1Search Guard
Jun 17, 2026
Aug 23, 2019
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Search Guard versions before 23.1 had an issue that an administrative user is able to retrieve bcrypt password hashes of other users configured in the internal user database.
1Zebra
8220xi4 Firmware
Zt220 FirmwareZt230 Firmware+5 more
Jun 17, 2026
Aug 20, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Zebra Industrial Printers All Versions, Zebra printers are shipped with unrestricted end-user access to front panel options. If the option to use a passcode to limit the functionality of the front panel is applied, speci...Show more
Zebra Industrial Printers All Versions, Zebra printers are shipped with unrestricted end-user access to front panel options. If the option to use a passcode to limit the functionality of the front panel is applied, specially crafted packets could be sent over the same network to a port on the printer and the printer will respond with an array of information that includes the front panel passcode for the printer. Once the passcode is retrieved, an attacker must have physical access to the front panel of the printer to enter the passcode to access the full functionality of the front panel.Show less
1Dell
6Emc Powerconnect 7000 Firmware
Emc Powerconnect 8024 FirmwareEmc Powerconnect M6220 Firmware+3 more
Jun 17, 2026
Aug 20, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Dell EMC PowerConnect 8024, 7000, M6348, M6220, M8024 and M8024-K running firmware versions prior to 5.1.15.2 contain a plain-text password storage vulnerability. TACACS\Radius credentials are stored in plain text in the...Show more
Dell EMC PowerConnect 8024, 7000, M6348, M6220, M8024 and M8024-K running firmware versions prior to 5.1.15.2 contain a plain-text password storage vulnerability. TACACS\Radius credentials are stored in plain text in the system settings menu. An authenticated malicious user with access to the system settings menu may obtain the exposed password to use it in further attacks.Show less
1Gradle
1Gradle
Jun 17, 2026
Aug 14, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
The HTTP client in Gradle before 5.6 sends authentication credentials originally destined for the configured host. If that host returns a 30x redirect, Gradle also sends those credentials to all subsequent hosts that the...Show more
The HTTP client in Gradle before 5.6 sends authentication credentials originally destined for the configured host. If that host returns a 30x redirect, Gradle also sends those credentials to all subsequent hosts that the request redirects to. This is similar to CVE-2018-1000007.Show less
1Jenkins
1Eggplant
Jun 17, 2026
Aug 7, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins eggPlant Plugin 2.2 and earlier stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
1Google
1Cloud Messaging Notification
Jun 17, 2026
Aug 7, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins Google Cloud Messaging Notification Plugin 1.0 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file sy...Show more
Jenkins Google Cloud Messaging Notification Plugin 1.0 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.Show less
1Jenkins
1Testlink
Jun 17, 2026
Aug 7, 2019
N/A· v4
5.3 MEDIUM· v3
2.1 LOW· v2
Jenkins TestLink Plugin 3.16 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
1Microdigital
3Mdc N2190v Firmware
Mdc N4090 FirmwareMdc N4090w Firmware
Jun 17, 2026
Aug 6, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
A cleartext password storage issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. The file in question is /usr/local/ipsca/mipsca.db. If a camera is compromised, the attacker can gain a...Show more
A cleartext password storage issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. The file in question is /usr/local/ipsca/mipsca.db. If a camera is compromised, the attacker can gain access to passwords and abuse them to compromise further systems.Show less