← Back
CWE-522

1,396 CVEs • Abstraction: Class

Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

JSON object

Loading...

CVEs (1,396)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Spectrum Control
Jun 17, 2026
May 29, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
IBM Tivoli Storage Productivity Center 5.2.13 through 5.3.0.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could expl...Show more
IBM Tivoli Storage Productivity Center 5.2.13 through 5.3.0.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. X-Force ID: 158334.Show less
1Bluecats
1Bc Reveal
Jun 17, 2026
May 22, 2019
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
The iOS mobile application BlueCats Reveal before 5.14 stores the username and password in the app cache as base64 encoded strings, i.e. clear text. These persist in the cache even if the user logs out. This can allow an...Show more
The iOS mobile application BlueCats Reveal before 5.14 stores the username and password in the app cache as base64 encoded strings, i.e. clear text. These persist in the cache even if the user logs out. This can allow an attacker to compromise the affected BlueCats network implementation. The attacker would first need to gain physical control of the iOS device or compromise it with a malicious app.Show less
1Bluecats
1Bluecats Reveal
Jun 17, 2026
May 22, 2019
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
The Android mobile application BlueCats Reveal before 3.0.19 stores the username and password in a clear text file. This file persists until the user logs out or the session times out from non-usage (30 days of no user a...Show more
The Android mobile application BlueCats Reveal before 3.0.19 stores the username and password in a clear text file. This file persists until the user logs out or the session times out from non-usage (30 days of no user activity). This can allow an attacker to compromise the affected BlueCats network implementation. The attacker would first need to gain physical control of the Android device or compromise it with a malicious app.Show less
1Eaton
1Halo Home
Jun 17, 2026
May 22, 2019
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
The Android mobile application Halo Home before 1.11.0 stores OAuth authentication and refresh access tokens in a clear text file. This file persists until the user logs out of the application and reboots the device. Thi...Show more
The Android mobile application Halo Home before 1.11.0 stores OAuth authentication and refresh access tokens in a clear text file. This file persists until the user logs out of the application and reboots the device. This vulnerability can allow an attacker to impersonate the legitimate user by reusing the stored OAuth token, thus allowing them to view and change the user's personal information stored in the backend cloud service. The attacker would first need to gain physical control of the Android device or compromise it with a malicious app.Show less
2Debian
Lemonldap Ng
2Debian Linux
Lemonldap\
Jun 17, 2026
May 22, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
LemonLDAP::NG -2.0.3 has Incorrect Access Control.
1Ovirt
1Cockpit Ovirt
Jun 17, 2026
May 17, 2019
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
During HE deployment via cockpit-ovirt, cockpit-ovirt generates an ansible variable file `/var/lib/ovirt-hosted-engine-setup/cockpit/ansibleVarFileXXXXXX.var` which contains the admin and the appliance passwords as plain...Show more
During HE deployment via cockpit-ovirt, cockpit-ovirt generates an ansible variable file `/var/lib/ovirt-hosted-engine-setup/cockpit/ansibleVarFileXXXXXX.var` which contains the admin and the appliance passwords as plain-text. At the of the deployment procedure, these files are deleted.Show less
1Intel
28Atom 230 Firmware
Atom 330 FirmwareAtom X5 E3930 Firmware+25 more
Jun 17, 2026
May 17, 2019
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
Insufficient key protection vulnerability in silicon reference firmware for Intel(R) Pentium(R) Processor J Series, Intel(R) Pentium(R) Processor N Series, Intel(R) Celeron(R) J Series, Intel(R) Celeron(R) N Series, Inte...Show more
Insufficient key protection vulnerability in silicon reference firmware for Intel(R) Pentium(R) Processor J Series, Intel(R) Pentium(R) Processor N Series, Intel(R) Celeron(R) J Series, Intel(R) Celeron(R) N Series, Intel(R) Atom(R) Processor A Series, Intel(R) Atom(R) Processor E3900 Series, Intel(R) Pentium(R) Processor Silver Series may allow a privileged user to potentially enable denial of service via local access.Show less
1Microsoft
8Windows 10
Windows 7Windows 8.1+5 more
Jun 17, 2026
May 16, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
An elevation of privilege vulnerability exists when the Windows Kernel improperly handles key enumeration, aka 'Windows Kernel Elevation of Privilege Vulnerability'.
1Siemens
1Logo!8 Bm Firmware
Jun 17, 2026
May 14, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). Unencrypted storage of passwords in the project could allow an attacker with access to port 10005/tcp to obtain passwords o...Show more
A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). Unencrypted storage of passwords in the project could allow an attacker with access to port 10005/tcp to obtain passwords of the device. The security vulnerability could be exploited by an unauthenticated attacker with network access to port 10005/tcp. No user interaction is required to exploit this security vulnerability. The vulnerability impacts confidentiality of the device. At the time of advisory publication no public exploitation of this security vulnerability was knownShow less
1Simple
1Better Banking
Jun 17, 2026
May 13, 2019
N/A· v4
6.8 MEDIUM· v3
2.1 LOW· v2
The Simple - Better Banking application 2.45.0 through 2.45.3 (fixed in 2.46.0) for Android was affected by an information disclosure vulnerability that leaked the user's password to the keyboard autocomplete functionali...Show more
The Simple - Better Banking application 2.45.0 through 2.45.3 (fixed in 2.46.0) for Android was affected by an information disclosure vulnerability that leaked the user's password to the keyboard autocomplete functionality. Third-party Android keyboards that capture the password may store this password in cleartext, or transmit the password to third-party services for keyboard customization purposes. A compromise of any datastore that contains keyboard autocompletion caches would result in the disclosure of the user's Simple Bank password.Show less
1Eye Disk
1Eyedisk
Jun 17, 2026
May 12, 2019
N/A· v4
6.8 MEDIUM· v3
2.1 LOW· v2
eyeDisk implements the unlock feature by sending a cleartext password. The password can be discovered by sniffing USB traffic or by sending a 06 05 52 41 01 b0 00 00 00 00 00 00 SCSI command.
1Synology
1Calendar
Jun 17, 2026
May 9, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Information exposure through process environment vulnerability in Synology Calendar before 2.3.3-0620 allows local users to obtain credentials via cmdline.
1Crestron
2Am 100 Firmware
Am 101 Firmware
Jun 17, 2026
Apr 30, 2019
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 stores usernames, passwords, and other configuration options in the file generated via the "export configuration" feature. The configuration file is...Show more
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 stores usernames, passwords, and other configuration options in the file generated via the "export configuration" feature. The configuration file is encrypted using the awenc binary. The same binary can be used to decrypt any configuration file since all the encryption logic is hard coded. A local attacker can use this vulnerability to gain access to devices username and passwords.Show less
1Jenkins
1Azure Ad
Jun 17, 2026
Apr 30, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Jenkins Azure AD Plugin 0.3.3 and earlier stored the client secret unencrypted in the global config.xml configuration file on the Jenkins master where it could be viewed by users with access to the master file system.
1Jenkins
1Aqua Microscanner
Jun 17, 2026
Apr 30, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Jenkins Aqua MicroScanner Plugin 1.0.5 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system.
1Jenkins
1Twitter
Jun 17, 2026
Apr 30, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Jenkins Twitter Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
1Robotronic
1Runasspc
Jun 17, 2026
Apr 24, 2019
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
Robotronic RunAsSpc 3.7.0.0 protects stored credentials insufficiently, which allows locally authenticated attackers (under the same user context) to obtain cleartext credentials of the stored account.
1Gradle
1Enterprise
Jun 17, 2026
Apr 22, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
In Gradle Enterprise before 2018.5.3, Build Cache Nodes did not store the credentials at rest in an encrypted format.
1Cloudbees
1Jenkins Operations Center
Jun 17, 2026
Apr 19, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
CloudBees Jenkins Operations Center 2.150.2.3, when an expired trial license exists, allows Cleartext Password Storage and Retrieval via the proxy configuration page.
1Jenkins
1Azure Publishersettings Credentials
Jun 17, 2026
Apr 18, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Jenkins Azure PublisherSettings Credentials Plugin 1.2 and earlier stored credentials unencrypted in the credentials.xml file on the Jenkins master where they could be viewed by users with access to the master file syste...Show more
Jenkins Azure PublisherSettings Credentials Plugin 1.2 and earlier stored credentials unencrypted in the credentials.xml file on the Jenkins master where they could be viewed by users with access to the master file system.Show less